Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-ip.c
Line
Count
Source
1
/* packet-ip.c
2
 * Routines for IP and miscellaneous IP protocol packet disassembly
3
 *
4
 * Wireshark - Network traffic analyzer
5
 * By Gerald Combs <gerald@wireshark.org>
6
 * Copyright 1998 Gerald Combs
7
 *
8
 * Wednesday, January 17, 2006
9
 * Support for the CIPSO IPv4 option
10
 * (http://sourceforge.net/docman/display_doc.php?docid=34650&group_id=174379)
11
 * by   Paul Moore <paul.moore@hp.com>
12
 *
13
 * SPDX-License-Identifier: GPL-2.0-or-later
14
 */
15
16
#include "config.h"
17
18
#include <epan/packet.h>
19
#include <epan/capture_dissectors.h>
20
#include <epan/addr_resolv.h>
21
#include <epan/maxmind_db.h>
22
#include <epan/expert.h>
23
#include <epan/ip_opts.h>
24
#include <epan/prefs.h>
25
#include <epan/conversation_table.h>
26
#include <epan/conversation_filter.h>
27
#include <epan/reassemble.h>
28
#include <epan/etypes.h>
29
#include <epan/aftypes.h>
30
#include <epan/in_cksum.h>
31
#include <epan/decode_as.h>
32
#include <epan/proto_data.h>
33
#include <epan/exported_pdu.h>
34
#include <epan/tfs.h>
35
#include <epan/iana-info.h>
36
#include <wsutil/array.h>
37
#include <wiretap/erf_record.h>
38
#include <wsutil/str_util.h>
39
40
#include "packet-ip.h"
41
#include "packet-juniper.h"
42
#include "packet-sflow.h"
43
#include "packet-gre.h"
44
#include "packet-l2tp.h"
45
#include "packet-vxlan.h"
46
#include "packet-mpls.h"
47
#include "packet-nsh.h"
48
#include "packet-eth.h"
49
#include "packet-osi.h"
50
#include "packet-ppp.h"
51
#include "packet-llc.h"
52
#include "packet-arcnet.h"
53
#include "packet-ax25.h"
54
55
56
void proto_register_ip(void);
57
void proto_reg_handoff_ip(void);
58
59
static int ip_tap;
60
61
static int exported_pdu_tap;
62
63
/* Decode the old IPv4 TOS field as the DiffServ DS Field (RFC2474/2475) */
64
static bool g_ip_dscp_actif = true;
65
66
/* Defragment fragmented IP datagrams */
67
static bool ip_defragment = true;
68
69
/* Place IP summary in proto tree */
70
static bool ip_summary_in_tree = true;
71
72
/* Perform IP checksum */
73
static bool ip_check_checksum;
74
75
/* Assume TSO and correct zero-length IP packets */
76
static bool ip_tso_supported = true;
77
78
/* Use heuristics to determine subdissector */
79
static bool try_heuristic_first;
80
81
/* Interpret the reserved flag as security flag (RFC 3514) */
82
static bool ip_security_flag;
83
84
/* Assign unique stream numbers to each IP conversation. This increases
85
 * resource use (CPU and memory) because of having to lookup and create
86
 * conversations.
87
 */
88
static bool ip_track_conv_id = true;
89
90
/* Aggregate subnets in Statistics Endpoints/Conversations Dialogs
91
 * defaults to false to not impact resources
92
 */
93
static bool ip_conv_agg_flag = false;
94
95
static int proto_ip;
96
97
static int proto_ip_option_eol;
98
static int proto_ip_option_nop;
99
static int proto_ip_option_security;
100
static int proto_ip_option_route;
101
static int proto_ip_option_timestamp;
102
static int proto_ip_option_ext_security;
103
static int proto_ip_option_cipso;
104
static int proto_ip_option_record_route;
105
static int proto_ip_option_sid;
106
static int proto_ip_option_source_route;
107
static int proto_ip_option_mtu_probe;
108
static int proto_ip_option_mtu_reply;
109
static int proto_ip_option_traceroute;
110
static int proto_ip_option_routeralert;
111
static int proto_ip_option_sdb;
112
static int proto_ip_option_qs;
113
static int proto_ip_option_dsr;
114
static int hf_ip_version;
115
static int hf_ip_hdr_len;
116
static int hf_ip_dsfield;
117
static int hf_ip_dsfield_dscp;
118
static int hf_ip_dsfield_ecn;
119
static int hf_ip_tos;
120
static int hf_ip_tos_precedence;
121
static int hf_ip_tos_delay;
122
static int hf_ip_tos_throughput;
123
static int hf_ip_tos_reliability;
124
static int hf_ip_tos_cost;
125
static int hf_ip_len;
126
static int hf_ip_id;
127
static int hf_ip_dst;
128
static int hf_ip_dst_host;
129
static int hf_ip_src;
130
static int hf_ip_src_host;
131
static int hf_ip_addr;
132
static int hf_ip_host;
133
static int hf_ip_flags;
134
static int hf_ip_flags_sf;
135
static int hf_ip_flags_rf;
136
static int hf_ip_flags_df;
137
static int hf_ip_flags_mf;
138
static int hf_ip_frag_offset;
139
static int hf_ip_ttl;
140
static int hf_ip_proto;
141
static int hf_ip_checksum;
142
static int hf_ip_checksum_calculated;
143
static int hf_ip_checksum_status;
144
static int hf_ip_stream;
145
146
/* IP option fields */
147
static int hf_ip_opt_type;
148
static int hf_ip_opt_type_copy;
149
static int hf_ip_opt_type_class;
150
static int hf_ip_opt_type_number;
151
static int hf_ip_opt_len;
152
static int hf_ip_opt_data;
153
static int hf_ip_opt_ptr;
154
static int hf_ip_opt_sid;
155
static int hf_ip_opt_mtu;
156
static int hf_ip_opt_id_number;
157
static int hf_ip_opt_ohc;
158
static int hf_ip_opt_rhc;
159
static int hf_ip_opt_originator;
160
static int hf_ip_opt_ra;
161
static int hf_ip_opt_addr;
162
static int hf_ip_opt_padding;
163
static int hf_ip_opt_qs_func;
164
static int hf_ip_opt_qs_rate;
165
static int hf_ip_opt_qs_ttl;
166
static int hf_ip_opt_qs_ttl_diff;
167
static int hf_ip_opt_qs_unused;
168
static int hf_ip_opt_qs_nonce;
169
static int hf_ip_opt_qs_reserved;
170
static int hf_ip_opt_sec_rfc791_sec;
171
static int hf_ip_opt_sec_rfc791_comp;
172
static int hf_ip_opt_sec_rfc791_hr;
173
static int hf_ip_opt_sec_rfc791_tcc;
174
static int hf_ip_opt_sec_cl;
175
static int hf_ip_opt_sec_prot_auth_flags;
176
static int hf_ip_opt_sec_prot_auth_genser;
177
static int hf_ip_opt_sec_prot_auth_siop_esi;
178
static int hf_ip_opt_sec_prot_auth_sci;
179
static int hf_ip_opt_sec_prot_auth_nsa;
180
static int hf_ip_opt_sec_prot_auth_doe;
181
static int hf_ip_opt_sec_prot_auth_unassigned;
182
static int hf_ip_opt_sec_prot_auth_unassigned2;
183
static int hf_ip_opt_sec_prot_auth_fti;
184
static int hf_ip_opt_ext_sec_add_sec_info_format_code;
185
static int hf_ip_opt_ext_sec_add_sec_info;
186
static int hf_ip_opt_dsr_cilium_service_port;
187
static int hf_ip_opt_dsr_cilium_service_ip;
188
static int hf_ip_rec_rt;
189
static int hf_ip_rec_rt_host;
190
static int hf_ip_cur_rt;
191
static int hf_ip_cur_rt_host;
192
static int hf_ip_src_rt;
193
static int hf_ip_src_rt_host;
194
static int hf_ip_empty_rt;
195
static int hf_ip_empty_rt_host;
196
static int hf_ip_cipso_tag_type;
197
198
static int hf_ip_fragments;
199
static int hf_ip_fragment;
200
static int hf_ip_fragment_overlap;
201
static int hf_ip_fragment_overlap_conflict;
202
static int hf_ip_fragment_multiple_tails;
203
static int hf_ip_fragment_too_long_fragment;
204
static int hf_ip_fragment_error;
205
static int hf_ip_fragment_count;
206
static int hf_ip_reassembled_in;
207
static int hf_ip_reassembled_length;
208
static int hf_ip_reassembled_data;
209
210
/* Generated from convert_proto_tree_add_text.pl */
211
static int hf_ip_opt_flag;
212
static int hf_ip_opt_overflow;
213
static int hf_ip_cipso_tag_data;
214
static int hf_ip_cipso_sensitivity_level;
215
static int hf_ip_cipso_categories;
216
static int hf_ip_cipso_doi;
217
static int hf_ip_opt_time_stamp;
218
static int hf_ip_opt_time_stamp_addr;
219
220
static int hf_geoip_country;
221
static int hf_geoip_country_iso;
222
static int hf_geoip_city;
223
static int hf_geoip_as_number;
224
static int hf_geoip_as_org;
225
static int hf_geoip_latitude;
226
static int hf_geoip_longitude;
227
static int hf_geoip_src_summary;
228
static int hf_geoip_src_country;
229
static int hf_geoip_src_country_iso;
230
static int hf_geoip_src_city;
231
static int hf_geoip_src_as_number;
232
static int hf_geoip_src_as_org;
233
static int hf_geoip_src_latitude;
234
static int hf_geoip_src_longitude;
235
static int hf_geoip_dst_summary;
236
static int hf_geoip_dst_country;
237
static int hf_geoip_dst_country_iso;
238
static int hf_geoip_dst_city;
239
static int hf_geoip_dst_as_number;
240
static int hf_geoip_dst_as_org;
241
static int hf_geoip_dst_latitude;
242
static int hf_geoip_dst_longitude;
243
244
static int ett_ip;
245
static int ett_ip_dsfield;
246
static int ett_ip_tos;
247
static int ett_ip_flags;
248
static int ett_ip_options;
249
static int ett_ip_option_eool;
250
static int ett_ip_option_nop;
251
static int ett_ip_option_sec;
252
static int ett_ip_option_route;
253
static int ett_ip_option_timestamp;
254
static int ett_ip_option_ext_security;
255
static int ett_ip_option_cipso;
256
static int ett_ip_option_sid;
257
static int ett_ip_option_mtu;
258
static int ett_ip_option_tr;
259
static int ett_ip_option_ra;
260
static int ett_ip_option_sdb;
261
static int ett_ip_option_qs;
262
static int ett_ip_option_dsr;
263
static int ett_ip_option_other;
264
static int ett_ip_fragments;
265
static int ett_ip_fragment;
266
static int ett_ip_opt_type;
267
static int ett_ip_opt_sec_prot_auth_flags;
268
static int ett_ip_unknown_opt;
269
270
static expert_field ei_ip_opt_len_invalid;
271
static expert_field ei_ip_opt_deprecated;
272
static expert_field ei_ip_opt_sec_prot_auth_fti;
273
static expert_field ei_ip_extraneous_data;
274
static expert_field ei_ip_opt_ptr_before_address;
275
static expert_field ei_ip_opt_ptr_middle_address;
276
static expert_field ei_ip_subopt_too_long;
277
static expert_field ei_ip_nop;
278
static expert_field ei_ip_bogus_ip_length;
279
static expert_field ei_ip_zero_data_length;
280
static expert_field ei_ip_evil_packet;
281
static expert_field ei_ip_checksum_bad;
282
static expert_field ei_ip_ttl_lncb;
283
static expert_field ei_ip_ttl_too_small;
284
static expert_field ei_ip_cipso_tag;
285
static expert_field ei_ip_bogus_ip_version;
286
static expert_field ei_ip_bogus_header_length;
287
static expert_field ei_ip_reserved_bit_set;
288
289
static dissector_handle_t ip_handle;
290
static dissector_handle_t ipv4_handle;
291
static dissector_table_t ip_option_table;
292
293
static int ett_geoip_info;
294
295
static uint32_t ip_stream_count;
296
297
static const fragment_items ip_frag_items = {
298
  &ett_ip_fragment,
299
  &ett_ip_fragments,
300
  &hf_ip_fragments,
301
  &hf_ip_fragment,
302
  &hf_ip_fragment_overlap,
303
  &hf_ip_fragment_overlap_conflict,
304
  &hf_ip_fragment_multiple_tails,
305
  &hf_ip_fragment_too_long_fragment,
306
  &hf_ip_fragment_error,
307
  &hf_ip_fragment_count,
308
  &hf_ip_reassembled_in,
309
  &hf_ip_reassembled_length,
310
  &hf_ip_reassembled_data,
311
  "IPv4 fragments"
312
};
313
314
static heur_dissector_list_t heur_subdissector_list;
315
316
static dissector_table_t ip_dissector_table;
317
318
static dissector_handle_t ipv6_handle;
319
static capture_dissector_handle_t ip_cap_handle;
320
321
322
/* IP structs and definitions */
323
324
const value_string ip_version_vals[] = {
325
  { IP_VERSION_NUM_RESERVED,       "Reserved" },
326
  { IP_VERSION_NUM_INET,           "IPv4" },
327
  { IP_VERSION_NUM_ST,             "ST Datagram" },
328
  { IP_VERSION_NUM_INET6,          "IPv6" },
329
  { IP_VERSION_NUM_TPIX,           "TP/IX" },
330
  { IP_VERSION_NUM_PIP,            "PIP" },
331
  { IP_VERSION_NUM_TUBA,           "TUBA" },
332
  { 0, NULL },
333
};
334
335
/* Offsets of fields within an IP header. */
336
#define IPH_V_HL                0
337
#define IPH_TOS                 1
338
#define IPH_LEN                 2
339
#define IPH_ID                  4
340
#define IPH_TTL                 6
341
#define IPH_OFF                 8
342
#define IPH_P                   9
343
#define IPH_SUM                 10
344
131k
#define IPH_SRC                 12
345
131k
#define IPH_DST                 16
346
347
/* Minimum IP header length. */
348
308k
#define IPH_MIN_LEN             20
349
350
/* IP flags. */
351
65.6k
#define IP_RF                   0x8000      /* Flag: "Reserved bit"     */
352
#define IP_DF                   0x4000      /* Flag: "Don't Fragment"   */
353
65.2k
#define IP_MF                   0x2000      /* Flag: "More Fragments"   */
354
131k
#define IP_OFFSET               0x1FFF      /* "Fragment Offset" part   */
355
356
/* Differentiated Services Field. See RFCs 2474, 2597, 2598 and 3168. */
357
#define IPDSFIELD_DSCP_DEFAULT  0x00
358
#define IPDSFIELD_DSCP_LE       0x01
359
#define IPDSFIELD_DSCP_CS1      0x08
360
#define IPDSFIELD_DSCP_AF11     0x0A
361
#define IPDSFIELD_DSCP_AF12     0x0C
362
#define IPDSFIELD_DSCP_AF13     0x0E
363
#define IPDSFIELD_DSCP_CS2      0x10
364
#define IPDSFIELD_DSCP_AF21     0x12
365
#define IPDSFIELD_DSCP_AF22     0x14
366
#define IPDSFIELD_DSCP_AF23     0x16
367
#define IPDSFIELD_DSCP_CS3      0x18
368
#define IPDSFIELD_DSCP_AF31     0x1A
369
#define IPDSFIELD_DSCP_AF32     0x1C
370
#define IPDSFIELD_DSCP_AF33     0x1E
371
#define IPDSFIELD_DSCP_CS4      0x20
372
#define IPDSFIELD_DSCP_AF41     0x22
373
#define IPDSFIELD_DSCP_AF42     0x24
374
#define IPDSFIELD_DSCP_AF43     0x26
375
#define IPDSFIELD_DSCP_CS5      0x28
376
#define IPDSFIELD_VOICE_ADMIT   0x2C
377
#define IPDSFIELD_DSCP_EF       0x2E
378
#define IPDSFIELD_DSCP_CS6      0x30
379
#define IPDSFIELD_DSCP_CS7      0x38
380
381
#define IPDSFIELD_ECT_NOT       0x00
382
#define IPDSFIELD_ECT_1         0x01
383
#define IPDSFIELD_ECT_0         0x02
384
#define IPDSFIELD_CE            0x03
385
386
/* IP TOS, superseded by the DS Field, RFC 2474. */
387
0
#define IPTOS_TOS_MASK          0x1E
388
0
#define IPTOS_TOS(tos)          ((tos) & IPTOS_TOS_MASK)
389
#define IPTOS_NONE              0x00
390
16
#define IPTOS_LOWCOST           0x02
391
16
#define IPTOS_RELIABILITY       0x04
392
16
#define IPTOS_THROUGHPUT        0x08
393
16
#define IPTOS_LOWDELAY          0x10
394
#define IPTOS_SECURITY          0x1E
395
396
16
#define IPTOS_PREC_MASK             0xE0
397
#define IPTOS_PREC_SHIFT            5
398
#define IPTOS_PREC(tos)             (((tos)&IPTOS_PREC_MASK)>>IPTOS_PREC_SHIFT)
399
#define IPTOS_PREC_NETCONTROL       7
400
#define IPTOS_PREC_INTERNETCONTROL  6
401
#define IPTOS_PREC_CRITIC_ECP       5
402
#define IPTOS_PREC_FLASHOVERRIDE    4
403
#define IPTOS_PREC_FLASH            3
404
#define IPTOS_PREC_IMMEDIATE        2
405
#define IPTOS_PREC_PRIORITY         1
406
#define IPTOS_PREC_ROUTINE          0
407
408
/* IP options */
409
8.40k
#define IPOPT_COPY              0x80
410
411
279k
#define IPOPT_CONTROL           0x00
412
#define IPOPT_RESERVED1         0x20
413
32
#define IPOPT_MEASUREMENT       0x40
414
#define IPOPT_RESERVED2         0x60
415
416
/* REF: http://www.iana.org/assignments/ip-parameters */
417
/* TODO: Not all of these are implemented, especially those
418
 * deprecated by RFC 6814. */
419
174k
#define IPOPT_EOOL      (0 |IPOPT_CONTROL)
420
96.9k
#define IPOPT_NOP       (1 |IPOPT_CONTROL)
421
16
#define IPOPT_SEC       (2 |IPOPT_COPY|IPOPT_CONTROL)       /* RFC 791/1108 */
422
4.13k
#define IPOPT_LSR       (3 |IPOPT_COPY|IPOPT_CONTROL)
423
16
#define IPOPT_TS        (4 |IPOPT_MEASUREMENT)
424
16
#define IPOPT_ESEC      (5 |IPOPT_COPY|IPOPT_CONTROL)       /* RFC 1108 */
425
16
#define IPOPT_CIPSO     (6 |IPOPT_COPY|IPOPT_CONTROL)       /* draft-ietf-cipso-ipsecurity-01 */
426
16
#define IPOPT_RR        (7 |IPOPT_CONTROL)
427
16
#define IPOPT_SID       (8 |IPOPT_COPY|IPOPT_CONTROL)       /* Deprecated */
428
8.29k
#define IPOPT_SSR       (9 |IPOPT_COPY|IPOPT_CONTROL)
429
#define IPOPT_ZSU       (10|IPOPT_CONTROL)                  /* Zsu */
430
16
#define IPOPT_MTUP      (11|IPOPT_CONTROL)                  /* RFC 1063 */
431
16
#define IPOPT_MTUR      (12|IPOPT_CONTROL)                  /* RFC 1063 */
432
#define IPOPT_FINN      (13|IPOPT_COPY|IPOPT_MEASUREMENT)   /* Finn */
433
#define IPOPT_VISA      (14|IPOPT_COPY|IPOPT_CONTROL)       /* Estrin; Deprecated */
434
#define IPOPT_ENCODE    (15|IPOPT_CONTROL)                  /* VerSteeg; Deprecated */
435
#define IPOPT_IMITD     (16|IPOPT_COPY|IPOPT_CONTROL)       /* Lee */
436
#define IPOPT_EIP       (17|IPOPT_COPY|IPOPT_CONTROL)       /* RFC 1385; Deprecated */
437
16
#define IPOPT_TR        (18|IPOPT_MEASUREMENT)              /* RFC 1393; Deprecated */
438
#define IPOPT_ADDEXT    (19|IPOPT_COPY|IPOPT_CONTROL)       /* Ullmann IPv7; Deprecated */
439
16
#define IPOPT_RTRALT    (20|IPOPT_COPY|IPOPT_CONTROL)       /* RFC 2113 */
440
16
#define IPOPT_SDB       (21|IPOPT_COPY|IPOPT_CONTROL)       /* RFC 1770 Graff; Deprecated */
441
#define IPOPT_UN        (22|IPOPT_COPY|IPOPT_CONTROL)       /* Released 18-Oct-2005 */
442
#define IPOPT_DPS       (23|IPOPT_COPY|IPOPT_CONTROL)       /* Malis; Deprecated */
443
#define IPOPT_UMP       (24|IPOPT_COPY|IPOPT_CONTROL)       /* Farinacci; Deprecated */
444
16
#define IPOPT_QS        (25|IPOPT_CONTROL)                  /* RFC 4782 */
445
16
#define IPOPT_DSR       (26|IPOPT_COPY)                     /* From Cilium for DSR https://github.com/cilium/cilium/blob/9acb306ce3003304c73394e2f9fe133253934213/bpf/lib/common.h#L612 */
446
#define IPOPT_EXP       (30|IPOPT_CONTROL)                  /* RFC 4727 */
447
448
449
/* IP option lengths */
450
#define IPOLEN_SEC_MIN          3
451
29
#define IPOLEN_LSR_MIN          3
452
#define IPOLEN_TS_MIN           4
453
#define IPOLEN_ESEC_MIN         3
454
#define IPOLEN_CIPSO_MIN        10
455
272
#define IPOLEN_RR_MIN           3
456
1
#define IPOLEN_SID              4
457
4
#define IPOLEN_SSR_MIN          3
458
30
#define IPOLEN_MTU              4
459
1
#define IPOLEN_TR               12
460
2
#define IPOLEN_RA               4
461
#define IPOLEN_SDB_MIN          6
462
5
#define IPOLEN_QS               8
463
1
#define IPOLEN_DSR              8
464
190
#define IPOLEN_MAX              40
465
466
#define IPSEC_RFC791_UNCLASSIFIED 0x0000
467
#define IPSEC_RFC791_CONFIDENTIAL 0xF135
468
#define IPSEC_RFC791_EFTO         0x789A
469
#define IPSEC_RFC791_MMMM         0xBC4D
470
#define IPSEC_RFC791_PROG         0x5E26
471
#define IPSEC_RFC791_RESTRICTED   0xAF13
472
#define IPSEC_RFC791_SECRET       0xD788
473
#define IPSEC_RFC791_TOPSECRET    0x6BC5
474
#define IPSEC_RFC791_RESERVED1    0x35E2
475
#define IPSEC_RFC791_RESERVED2    0x9AF1
476
#define IPSEC_RFC791_RESERVED3    0x4D78
477
#define IPSEC_RFC791_RESERVED4    0x24BD
478
#define IPSEC_RFC791_RESERVED5    0x135E
479
#define IPSEC_RFC791_RESERVED6    0x89AF
480
#define IPSEC_RFC791_RESERVED7    0xC4D6
481
#define IPSEC_RFC791_RESERVED8    0xE26B
482
483
#define IPSEC_RESERVED4         0x01
484
#define IPSEC_TOPSECRET         0x3D
485
#define IPSEC_SECRET            0x5A
486
#define IPSEC_CONFIDENTIAL      0x96
487
#define IPSEC_RESERVED3         0x66
488
#define IPSEC_RESERVED2         0xCC
489
#define IPSEC_UNCLASSIFIED      0xAB
490
#define IPSEC_RESERVED1         0xF1
491
492
#define IPOPT_TS_TSONLY         0       /* timestamps only */
493
52
#define IPOPT_TS_TSANDADDR      1       /* timestamps and addresses */
494
25
#define IPOPT_TS_PRESPEC        3       /* specified modules only */
495
496
7
#define IPLOCAL_NETWRK_CTRL_BLK_VRRP_ADDR       0xE0000012
497
0
#define IPLOCAL_NETWRK_CTRL_BLK_VRRP_TTL        0xFF
498
7
#define IPLOCAL_NETWRK_CTRL_BLK_GLPB_ADDR       0xE0000066
499
1
#define IPLOCAL_NETWRK_CTRL_BLK_GLPB_TTL        0XFF
500
6
#define IPLOCAL_NETWRK_CTRL_BLK_MDNS_ADDR       0xE00000FB
501
0
#define IPLOCAL_NETWRK_CTRL_BLK_MDNS_TTL        0XFF
502
6
#define IPLOCAL_NETWRK_CTRL_BLK_LLMNR_ADDR      0xE00000FC
503
504
6
#define IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL         0x1000 /* larger than max ttl */
505
7
#define IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL     0X01
506
507
static void ip_prompt(packet_info *pinfo, char* result)
508
0
{
509
0
    ws_ip4* iph = (ws_ip4*)p_get_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num);
510
0
    snprintf(result, MAX_DECODE_AS_PROMPT_LEN, "IP protocol %u as", iph->ip_proto);
511
0
}
512
513
static void *ip_value(packet_info *pinfo)
514
0
{
515
0
    ws_ip4* iph = (ws_ip4*)p_get_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num);
516
0
    return GUINT_TO_POINTER(iph->ip_proto);
517
0
}
518
519
static const char* ip_conv_get_filter_type(conv_item_t* conv, conv_filter_type_e filter)
520
0
{
521
    /* addr type is AT_STRINGZ for subnets, as it is a very flexible format
522
     * XXX - create a new type when required, at this moment it's only used in
523
     * conversation tables and is not justified. See #19481.
524
     */
525
0
    if ((filter == CONV_FT_SRC_ADDRESS) && ((conv->src_address.type == AT_IPv4) ||
526
0
        (conv->src_address.type == AT_STRINGZ)))
527
0
        return "ip.src";
528
529
0
    if ((filter == CONV_FT_DST_ADDRESS) && ((conv->dst_address.type == AT_IPv4) ||
530
0
        (conv->dst_address.type == AT_STRINGZ)))
531
0
        return "ip.dst";
532
533
0
    if ((filter == CONV_FT_ANY_ADDRESS) && ((conv->src_address.type == AT_IPv4) ||
534
0
        (conv->src_address.type == AT_STRINGZ)))
535
0
        return "ip.addr";
536
537
0
    return CONV_FILTER_INVALID;
538
0
}
539
540
static ct_dissector_info_t ip_ct_dissector_info = {&ip_conv_get_filter_type};
541
542
static tap_packet_status
543
ip_conversation_packet(void *pct, packet_info *pinfo, epan_dissect_t *edt _U_, const void *vip, tap_flags_t flags)
544
0
{
545
0
    conv_hash_t *hash = (conv_hash_t*) pct;
546
0
    hash->flags = flags;
547
0
    const ws_ip4 *iph=(const ws_ip4 *)vip;
548
549
    /* Try aggregating into subnets if asked so,
550
     * if no subnets are found it will still end in calling xxx_with_conv_id()
551
     */
552
0
    if (!ip_track_conv_id) {
553
0
        add_conversation_table_data(hash, &iph->ip_src, &iph->ip_dst, 0, 0, 1, pinfo->fd->pkt_len,
554
0
                                                 &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP);
555
0
    } else if(ip_conv_agg_flag) {
556
0
        add_conversation_table_data_ipv4_subnet(hash, &iph->ip_src, &iph->ip_dst, 0, 0, (conv_id_t)iph->ip_stream, 1, pinfo->fd->pkt_len,
557
0
                                                &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP);
558
0
    } else {
559
0
        add_conversation_table_data_with_conv_id(hash, &iph->ip_src, &iph->ip_dst, 0, 0, (conv_id_t)iph->ip_stream, 1, pinfo->fd->pkt_len,
560
0
                                                 &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP);
561
0
    }
562
563
0
    return TAP_PACKET_REDRAW;
564
0
}
565
566
static const char* ip_endpoint_get_filter_type(endpoint_item_t* endpoint, conv_filter_type_e filter)
567
0
{
568
    /* subnets: handled similarly to ip_conv_get_filter_type() */
569
0
    if ((filter == CONV_FT_ANY_ADDRESS) && ((endpoint->myaddress.type == AT_IPv4) ||
570
0
        (endpoint->myaddress.type == AT_STRINGZ)))
571
0
        return "ip.addr";
572
573
0
    return CONV_FILTER_INVALID;
574
0
}
575
576
static et_dissector_info_t ip_endpoint_dissector_info = {&ip_endpoint_get_filter_type};
577
578
static tap_packet_status
579
ip_endpoint_packet(void *pit, packet_info *pinfo, epan_dissect_t *edt _U_, const void *vip, tap_flags_t flags)
580
0
{
581
0
    conv_hash_t *hash = (conv_hash_t*) pit;
582
0
    hash->flags = flags;
583
0
    const ws_ip4 *iph=(const ws_ip4 *)vip;
584
585
    /* Take two "add" passes per packet, adding for each direction, ensures that all
586
    packets are counted properly (even if address is sending to itself)
587
    XXX - this could probably be done more efficiently inside endpoint_table */
588
0
    if(ip_conv_agg_flag) {
589
0
        add_endpoint_table_data_ipv4_subnet(hash, &iph->ip_src, 0, true, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE);
590
0
        add_endpoint_table_data_ipv4_subnet(hash, &iph->ip_dst, 0, false, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE);
591
0
    }
592
0
    else {
593
0
        add_endpoint_table_data(hash, &iph->ip_src, 0, true, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE);
594
0
        add_endpoint_table_data(hash, &iph->ip_dst, 0, false, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE);
595
0
    }
596
0
    return TAP_PACKET_REDRAW;
597
0
}
598
599
static bool
600
ip_filter_valid(packet_info *pinfo, void *user_data _U_)
601
0
{
602
0
    return proto_is_frame_protocol(pinfo->layers, "ip");
603
0
}
604
605
static char*
606
ip_build_filter(packet_info *pinfo, void *user_data _U_)
607
0
{
608
0
    return ws_strdup_printf("ip.addr eq %s and ip.addr eq %s",
609
0
                address_to_str(pinfo->pool, &pinfo->net_src),
610
0
                address_to_str(pinfo->pool, &pinfo->net_dst));
611
0
}
612
613
/*
614
 * defragmentation of IPv4
615
 */
616
static reassembly_table ip_reassembly_table;
617
618
static bool
619
0
capture_ip(const unsigned char *pd, int offset, int len, capture_packet_info_t *cpinfo, const union wtap_pseudo_header *pseudo_header _U_) {
620
0
  if (!BYTES_ARE_IN_FRAME(offset, len, IPH_MIN_LEN))
621
0
    return false;
622
623
0
  capture_dissector_increment_count(cpinfo, proto_ip);
624
0
  return try_capture_dissector("ip.proto", pd[offset + 9], pd, offset+IPH_MIN_LEN, len, cpinfo, pseudo_header);
625
0
}
626
627
static void
628
add_geoip_info_entry(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, ws_in4_addr ip, bool isdst)
629
110k
{
630
110k
  const mmdb_lookup_t *lookup = maxmind_db_lookup_ipv4(&ip);
631
110k
  if (!lookup->found) return;
632
633
0
  wmem_strbuf_t *summary = wmem_strbuf_new(pinfo->pool, "");
634
0
  if (lookup->city) {
635
0
    wmem_strbuf_append(summary, lookup->city);
636
0
  }
637
0
  if (lookup->country_iso) {
638
0
    if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", ");
639
0
    wmem_strbuf_append(summary, lookup->country_iso);
640
0
  } else if (lookup->country) {
641
0
    if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", ");
642
0
    wmem_strbuf_append(summary, lookup->country);
643
0
  }
644
0
  if (lookup->as_number > 0) {
645
0
    if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", ");
646
0
    wmem_strbuf_append_printf(summary, "ASN %u", lookup->as_number);
647
0
  }
648
0
  if (lookup->as_org) {
649
0
    if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", ");
650
0
    wmem_strbuf_append(summary, lookup->as_org);
651
0
  }
652
653
0
  int addr_offset = offset + (isdst ? IPH_DST : IPH_SRC);
654
0
  int dir_hf = isdst ? hf_geoip_dst_summary : hf_geoip_src_summary;
655
0
  proto_item *geoip_info_item = proto_tree_add_string(tree, dir_hf, tvb, addr_offset, 4, wmem_strbuf_finalize(summary));
656
0
  proto_item_set_generated(geoip_info_item);
657
0
  proto_tree *geoip_info_tree = proto_item_add_subtree(geoip_info_item, ett_geoip_info);
658
659
0
  proto_item *item;
660
661
0
  if (lookup->city) {
662
0
    dir_hf = isdst ? hf_geoip_dst_city : hf_geoip_src_city;
663
0
    item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->city);
664
0
    proto_item_set_generated(item);
665
0
    item = proto_tree_add_string(geoip_info_tree, hf_geoip_city, tvb, addr_offset, 4, lookup->city);
666
0
    proto_item_set_generated(item);
667
0
  }
668
669
0
  if (lookup->country) {
670
0
    dir_hf = isdst ? hf_geoip_dst_country : hf_geoip_src_country;
671
0
    item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->country);
672
0
    proto_item_set_generated(item);
673
0
    item = proto_tree_add_string(geoip_info_tree, hf_geoip_country, tvb, addr_offset, 4, lookup->country);
674
0
    proto_item_set_generated(item);
675
0
  }
676
677
0
  if (lookup->country_iso) {
678
0
    dir_hf = isdst ? hf_geoip_dst_country_iso : hf_geoip_src_country_iso;
679
0
    item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->country_iso);
680
0
    proto_item_set_generated(item);
681
0
    item = proto_tree_add_string(geoip_info_tree, hf_geoip_country_iso, tvb, addr_offset, 4, lookup->country_iso);
682
0
    proto_item_set_generated(item);
683
0
  }
684
685
0
  if (lookup->as_number > 0) {
686
0
    dir_hf = isdst ? hf_geoip_dst_as_number : hf_geoip_src_as_number;
687
0
    item = proto_tree_add_uint(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->as_number);
688
0
    proto_item_set_generated(item);
689
0
    item = proto_tree_add_uint(geoip_info_tree, hf_geoip_as_number, tvb, addr_offset, 4, lookup->as_number);
690
0
    proto_item_set_generated(item);
691
0
  }
692
693
0
  if (lookup->as_org) {
694
0
    dir_hf = isdst ? hf_geoip_dst_as_org : hf_geoip_src_as_org;
695
0
    item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->as_org);
696
0
    proto_item_set_generated(item);
697
0
    item = proto_tree_add_string(geoip_info_tree, hf_geoip_as_org, tvb, addr_offset, 4, lookup->as_org);
698
0
    proto_item_set_generated(item);
699
0
  }
700
701
0
  if (lookup->latitude >= -90.0 && lookup->latitude <= 90.0) {
702
0
    dir_hf = isdst ? hf_geoip_dst_latitude : hf_geoip_src_latitude;
703
0
    item = proto_tree_add_double(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->latitude);
704
0
    proto_item_set_generated(item);
705
0
    item = proto_tree_add_double(geoip_info_tree, hf_geoip_latitude, tvb, addr_offset, 4, lookup->latitude);
706
0
    proto_item_set_generated(item);
707
0
  }
708
709
0
  if (lookup->longitude >= -180.0 && lookup->longitude <= 180.0) {
710
0
    dir_hf = isdst ? hf_geoip_dst_longitude : hf_geoip_src_longitude;
711
0
    item = proto_tree_add_double(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->longitude);
712
0
    proto_item_set_generated(item);
713
0
    item = proto_tree_add_double(geoip_info_tree, hf_geoip_longitude, tvb, addr_offset, 4, lookup->longitude);
714
0
    proto_item_set_generated(item);
715
0
  }
716
0
}
717
718
static void
719
add_geoip_info(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, uint32_t src32,
720
               uint32_t dst32)
721
55.1k
{
722
55.1k
  add_geoip_info_entry(tree, pinfo, tvb, offset, g_htonl(src32), false);
723
55.1k
  add_geoip_info_entry(tree, pinfo, tvb, offset, g_htonl(dst32), true);
724
55.1k
}
725
726
const value_string ipopt_type_class_vals[] = {
727
  {(IPOPT_CONTROL & IPOPT_CLASS_MASK) >> 5, "Control"},
728
  {(IPOPT_RESERVED1 & IPOPT_CLASS_MASK) >> 5, "Reserved for future use"},
729
  {(IPOPT_MEASUREMENT & IPOPT_CLASS_MASK) >> 5, "Debugging and measurement"},
730
  {(IPOPT_RESERVED2 & IPOPT_CLASS_MASK) >> 5, "Reserved for future use"},
731
  {0, NULL}
732
};
733
734
const value_string ipopt_type_number_vals[] = {
735
  {IPOPT_EOOL & IPOPT_NUMBER_MASK, "End of Option List (EOL)"},
736
  {IPOPT_NOP & IPOPT_NUMBER_MASK, "No-Operation (NOP)"},
737
  {IPOPT_SEC & IPOPT_NUMBER_MASK, "Security"},
738
  {IPOPT_LSR & IPOPT_NUMBER_MASK, "Loose source route"},
739
  {IPOPT_TS & IPOPT_NUMBER_MASK, "Time stamp"},
740
  {IPOPT_ESEC & IPOPT_NUMBER_MASK, "Extended security"},
741
  {IPOPT_CIPSO & IPOPT_NUMBER_MASK, "Commercial IP security option"},
742
  {IPOPT_RR & IPOPT_NUMBER_MASK, "Record route"},
743
  {IPOPT_SID & IPOPT_NUMBER_MASK, "Stream identifier"},
744
  {IPOPT_SSR & IPOPT_NUMBER_MASK, "Strict source route"},
745
  {IPOPT_ZSU & IPOPT_NUMBER_MASK, "Experimental Measurement"},
746
  {IPOPT_MTUP & IPOPT_NUMBER_MASK, "MTU probe"},
747
  {IPOPT_MTUR & IPOPT_NUMBER_MASK, "MTU Reply"},
748
  {IPOPT_FINN & IPOPT_NUMBER_MASK, "Experimental Flow Control"},
749
  {IPOPT_VISA & IPOPT_NUMBER_MASK, "Experimental Access Control"},
750
  {IPOPT_ENCODE & IPOPT_NUMBER_MASK, "Ask Estrin"},
751
  {IPOPT_IMITD & IPOPT_NUMBER_MASK, "IMI Traffic Descriptor"},
752
  {IPOPT_EIP & IPOPT_NUMBER_MASK, "Extended Internet Protocol"},
753
  {IPOPT_TR & IPOPT_NUMBER_MASK, "Traceroute"},
754
  {IPOPT_ADDEXT & IPOPT_NUMBER_MASK, "Address Extension"},
755
  {IPOPT_RTRALT & IPOPT_NUMBER_MASK, "Router Alert"},
756
  {IPOPT_SDB & IPOPT_NUMBER_MASK, "Selective Directed Broadcast"},
757
  {IPOPT_UN & IPOPT_NUMBER_MASK, "Unassigned"},
758
  {IPOPT_DPS & IPOPT_NUMBER_MASK, "Dynamic Packet State"},
759
  {IPOPT_UMP & IPOPT_NUMBER_MASK, "Upstream Multicast Packet"},
760
  {IPOPT_QS & IPOPT_NUMBER_MASK, "Quick-Start"},
761
  {IPOPT_DSR & IPOPT_NUMBER_MASK, "Cilium DSR"},
762
  {IPOPT_EXP & IPOPT_NUMBER_MASK, "RFC 3692-style experiment"},
763
  {0, NULL}
764
};
765
766
static void
767
dissect_ipopt_type(tvbuff_t *tvb, int offset, proto_tree *tree)
768
18.7k
{
769
18.7k
  proto_tree *type_tree;
770
18.7k
  proto_item *ti;
771
772
18.7k
  ti = proto_tree_add_item(tree, hf_ip_opt_type, tvb, offset, 1, ENC_NA);
773
18.7k
  type_tree = proto_item_add_subtree(ti, ett_ip_opt_type);
774
18.7k
  proto_tree_add_item(type_tree, hf_ip_opt_type_copy, tvb, offset, 1, ENC_NA);
775
18.7k
  proto_tree_add_item(type_tree, hf_ip_opt_type_class, tvb, offset, 1, ENC_NA);
776
18.7k
  proto_tree_add_item(type_tree, hf_ip_opt_type_number, tvb, offset, 1, ENC_NA);
777
18.7k
}
778
779
static proto_tree*
780
ip_fixed_option_header(proto_tree* tree, packet_info *pinfo, tvbuff_t *tvb, int proto, int ett, proto_item** ti, unsigned len, unsigned optlen)
781
40
{
782
40
  proto_tree *field_tree;
783
40
  proto_item *tf;
784
785
40
  *ti = proto_tree_add_item(tree, proto, tvb, 0, optlen, ENC_NA);
786
40
  field_tree = proto_item_add_subtree(*ti, ett);
787
40
  proto_item_append_text(*ti, " (%u bytes)", len);
788
789
40
  dissect_ipopt_type(tvb, 0, field_tree);
790
40
  tf = proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, 1, 1, ENC_NA);
791
792
40
  if (len != optlen) {
793
    /* Bogus - option length isn't what it's supposed to be for this option. */
794
37
    expert_add_info_format(pinfo, tf, &ei_ip_opt_len_invalid,
795
37
                            "%s (with option length = %u byte%s; should be %u)",
796
37
                            proto_get_protocol_short_name(find_protocol_by_id(proto)),
797
37
                            optlen, plurality(optlen, "", "s"), len);
798
37
  }
799
800
40
  return field_tree;
801
40
}
802
803
static proto_tree*
804
ip_var_option_header(proto_tree* tree, packet_info *pinfo, tvbuff_t *tvb, int proto, int ett, proto_item** ti, unsigned optlen)
805
190
{
806
190
  proto_tree *field_tree;
807
190
  proto_item *tf;
808
809
190
  *ti = proto_tree_add_item(tree, proto, tvb, 0, optlen, ENC_NA);
810
190
  field_tree = proto_item_add_subtree(*ti, ett);
811
190
  proto_item_append_text(*ti, " (%u bytes)", optlen);
812
813
190
  dissect_ipopt_type(tvb, 0, field_tree);
814
190
  tf = proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, 1, 1, ENC_NA);
815
190
  if (optlen > IPOLEN_MAX)
816
0
    expert_add_info(pinfo, tf, &ei_ip_opt_len_invalid);
817
818
190
  return field_tree;
819
190
}
820
821
static const value_string secl_rfc791_vals[] = {
822
  {IPSEC_RFC791_UNCLASSIFIED, "Unclassified"},
823
  {IPSEC_RFC791_CONFIDENTIAL, "Confidential"},
824
  {IPSEC_RFC791_EFTO,         "EFTO"        },
825
  {IPSEC_RFC791_MMMM,         "MMMM"        },
826
  {IPSEC_RFC791_PROG,         "PROG"        },
827
  {IPSEC_RFC791_RESTRICTED,   "Restricted"  },
828
  {IPSEC_RFC791_SECRET,       "Secret"      },
829
  {IPSEC_RFC791_TOPSECRET,    "Top secret"  },
830
  {IPSEC_RFC791_RESERVED1,    "Reserved"    },
831
  {IPSEC_RFC791_RESERVED2,    "Reserved"    },
832
  {IPSEC_RFC791_RESERVED3,    "Reserved"    },
833
  {IPSEC_RFC791_RESERVED4,    "Reserved"    },
834
  {IPSEC_RFC791_RESERVED5,    "Reserved"    },
835
  {IPSEC_RFC791_RESERVED6,    "Reserved"    },
836
  {IPSEC_RFC791_RESERVED7,    "Reserved"    },
837
  {IPSEC_RFC791_RESERVED8,    "Reserved"    },
838
  {0,                  NULL          }
839
};
840
841
static const value_string sec_cl_vals[] = {
842
  {IPSEC_RESERVED4,    "Reserved 4"  },
843
  {IPSEC_TOPSECRET,    "Top secret"  },
844
  {IPSEC_SECRET,       "Secret"      },
845
  {IPSEC_CONFIDENTIAL, "Confidential"},
846
  {IPSEC_RESERVED3,    "Reserved 3"  },
847
  {IPSEC_RESERVED2,    "Reserved 2"  },
848
  {IPSEC_UNCLASSIFIED, "Unclassified"},
849
  {IPSEC_RESERVED1,    "Reserved 1"  },
850
  {0,                  NULL          }
851
};
852
853
static const true_false_string ip_opt_sec_prot_auth_flag_tfs = {
854
  "Datagram protected in accordance with its rules",
855
  "Datagram not protected in accordance with its rules"
856
};
857
858
static const true_false_string ip_opt_sec_prot_auth_fti_tfs = {
859
  "Additional octet present",
860
  "Final octet"
861
};
862
863
static int * const ip_opt_sec_prot_auth_fields_byte_1[] = {
864
  &hf_ip_opt_sec_prot_auth_genser,
865
  &hf_ip_opt_sec_prot_auth_siop_esi,
866
  &hf_ip_opt_sec_prot_auth_sci,
867
  &hf_ip_opt_sec_prot_auth_nsa,
868
  &hf_ip_opt_sec_prot_auth_doe,
869
  &hf_ip_opt_sec_prot_auth_unassigned,
870
  &hf_ip_opt_sec_prot_auth_fti,
871
  NULL
872
};
873
874
static int * const ip_opt_sec_prot_auth_fields_byte_n[] = {
875
  &hf_ip_opt_sec_prot_auth_unassigned2,
876
  &hf_ip_opt_sec_prot_auth_fti,
877
  NULL
878
};
879
static int
880
dissect_ipopt_security(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
881
19
{
882
19
  proto_tree *field_tree;
883
19
  proto_item *tf;
884
19
  unsigned   val;
885
19
  unsigned   curr_offset = 2;
886
19
  unsigned   optlen = tvb_reported_length(tvb);
887
888
19
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_security, ett_ip_option_sec, &tf, optlen);
889
890
19
  if (optlen == 11) {
891
  /* Analyze payload start to decide whether it should be dissected
892
     according to RFC 791 or RFC 1108 */
893
0
    val = tvb_get_ntohs(tvb, curr_offset);
894
0
    if (try_val_to_str(val, secl_rfc791_vals)) {
895
      /* Dissect as RFC 791 */
896
0
      proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_sec,
897
0
                          tvb, curr_offset, 2, ENC_BIG_ENDIAN);
898
0
      curr_offset += 2;
899
0
      proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_comp,
900
0
                          tvb, curr_offset, 2, ENC_BIG_ENDIAN);
901
0
      curr_offset += 2;
902
0
      proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_hr,
903
0
                          tvb, curr_offset, 2, ENC_ASCII);
904
0
      curr_offset += 2;
905
0
      proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_tcc,
906
0
                          tvb, curr_offset, 3, ENC_ASCII);
907
0
      return curr_offset;
908
0
    }
909
0
  }
910
911
  /* Dissect as RFC 108 */
912
19
  proto_tree_add_item(field_tree, hf_ip_opt_sec_cl, tvb, curr_offset, 1, ENC_BIG_ENDIAN);
913
19
  curr_offset++;
914
19
  if (curr_offset >= optlen) {
915
7
    return curr_offset;
916
7
  }
917
12
  val = tvb_get_uint8(tvb, curr_offset);
918
12
  proto_tree_add_bitmask(field_tree, tvb, curr_offset, hf_ip_opt_sec_prot_auth_flags,
919
12
                         ett_ip_opt_sec_prot_auth_flags, ip_opt_sec_prot_auth_fields_byte_1,
920
12
                         ENC_BIG_ENDIAN);
921
12
  curr_offset++;
922
27
  while (val & 0x01) {
923
17
    if (curr_offset == optlen) {
924
2
      expert_add_info(pinfo, tf, &ei_ip_opt_sec_prot_auth_fti);
925
2
      break;
926
2
    }
927
15
    val = tvb_get_uint8(tvb, curr_offset);
928
15
    proto_tree_add_bitmask(field_tree, tvb, curr_offset, hf_ip_opt_sec_prot_auth_flags,
929
15
                           ett_ip_opt_sec_prot_auth_flags, ip_opt_sec_prot_auth_fields_byte_n,
930
15
                           ENC_BIG_ENDIAN);
931
15
    curr_offset++;
932
15
  }
933
12
  if (curr_offset < optlen) {
934
3
    expert_add_info(pinfo, tf, &ei_ip_extraneous_data);
935
3
  }
936
937
12
  return curr_offset;
938
19
}
939
940
static int
941
dissect_ipopt_ext_security(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
942
4
{
943
4
  proto_tree *field_tree;
944
4
  proto_item *tf;
945
4
  unsigned   curr_offset = 2;
946
4
  int       remaining;
947
4
  int       optlen = tvb_reported_length(tvb);
948
949
4
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_ext_security, ett_ip_option_ext_security, &tf, optlen);
950
951
4
  proto_tree_add_item(field_tree, hf_ip_opt_ext_sec_add_sec_info_format_code, tvb, curr_offset, 1, ENC_BIG_ENDIAN);
952
4
  curr_offset++;
953
4
  remaining = optlen - curr_offset;
954
4
  if (remaining > 0) {
955
4
    proto_tree_add_item(field_tree, hf_ip_opt_ext_sec_add_sec_info, tvb, curr_offset, remaining, ENC_NA);
956
4
  }
957
958
4
  return tvb_captured_length(tvb);
959
4
}
960
961
/* USHRT_MAX can hold at most 5 (base 10) digits (6 for the NULL byte) */
962
#define USHRT_MAX_STRLEN    6
963
964
/* Maximum CIPSO tag length:
965
 * (IP hdr max)60 - (IPv4 hdr std)20 - (CIPSO base)6 = 34 */
966
19
#define CIPSO_TAG_LEN_MAX   34
967
968
/* The Commercial IP Security Option (CIPSO) is defined in IETF draft
969
 * draft-ietf-cipso-ipsecurity-01.txt and FIPS 188, a copy of both documents
970
 * can be found at the NetLabel project page, http://netlabel.sf.net or at
971
 * https://tools.ietf.org/html/draft-ietf-cipso-ipsecurity-01 */
972
static const value_string cipso_tag_type_vals[] = {
973
   {0,   "Padding"},
974
   {1,   "Restrictive Category Bitmap"},
975
   {2,   "Enumerated Categories"},
976
   {5,   "Ranged Categories"},
977
   {6,   "Permissive Categories"},
978
   {7,   "Free Form"},
979
980
   { 0,                          NULL }
981
};
982
983
static int
984
dissect_ipopt_cipso(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
985
20
{
986
20
  proto_tree *field_tree;
987
20
  proto_item *tf, *tag_item;
988
20
  unsigned   tagtype, taglen;
989
20
  int        offset = 2,
990
20
             optlen = tvb_reported_length(tvb);
991
20
  int        offset_max = optlen;
992
993
20
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_cipso, ett_ip_option_cipso, &tf, optlen);
994
995
20
  proto_tree_add_item(field_tree, hf_ip_cipso_doi, tvb, offset, 4, ENC_BIG_ENDIAN);
996
20
  offset += 4;
997
998
  /* loop through all of the tags in the CIPSO option */
999
70
  while (offset < offset_max) {
1000
66
    tagtype = tvb_get_uint8(tvb, offset);
1001
66
    tag_item = proto_tree_add_item(field_tree, hf_ip_cipso_tag_type, tvb, offset, 1, ENC_NA);
1002
1003
66
    if ((offset + 1) < offset_max)
1004
63
      taglen = tvb_get_uint8(tvb, offset + 1);
1005
3
    else
1006
3
      taglen = 1;
1007
1008
66
    switch (tagtype) {
1009
38
    case 0:
1010
      /* padding - skip this tag */
1011
38
      offset += 1;
1012
38
      continue;
1013
3
    case 1:
1014
      /* restrictive bitmap, see CIPSO draft section 3.4.2 for tag format */
1015
3
      if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) ||
1016
2
         ((offset + (int)taglen - 1) > offset_max)) {
1017
2
        expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag);
1018
2
        return offset;
1019
2
      }
1020
1021
      /* skip past alignment octet */
1022
1
      offset += 3;
1023
1024
1
      proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA);
1025
1
      offset += 1;
1026
1027
1
      if (taglen > 4) {
1028
1
        unsigned bit_spot;
1029
1
        unsigned byte_spot = 0;
1030
1
        unsigned char bitmask;
1031
1
        wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, "");
1032
1
        const uint8_t *val_ptr = tvb_get_ptr(tvb, offset, taglen - 4);
1033
1034
        /* we checked the length above so the highest category value
1035
         * possible here is 240 */
1036
3
        while (byte_spot < (taglen - 4)) {
1037
2
          bitmask = 0x80;
1038
2
          bit_spot = 0;
1039
18
          while (bit_spot < 8) {
1040
16
            if (val_ptr[byte_spot] & bitmask) {
1041
10
              if (wmem_strbuf_get_len(cat_str_buf) > 0)
1042
9
                wmem_strbuf_append_c(cat_str_buf, ',');
1043
1044
10
              wmem_strbuf_append_printf(cat_str_buf, "%u", byte_spot * 8 + bit_spot);
1045
10
            }
1046
16
            bit_spot++;
1047
16
            bitmask >>= 1;
1048
16
          }
1049
2
          byte_spot++;
1050
2
        }
1051
1052
1
        if (wmem_strbuf_get_len(cat_str_buf) > 0)
1053
1
          proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset, taglen - 4, wmem_strbuf_get_str(cat_str_buf));
1054
0
        else
1055
0
          proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset, taglen - 4, "ERROR PARSING CATEGORIES");
1056
1
        offset += taglen - 4;
1057
1
      }
1058
1
      break;
1059
3
    case 2:
1060
      /* enumerated categories, see CIPSO draft section 3.4.3 for tag format */
1061
3
      if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) ||
1062
2
         ((offset + (int)taglen - 1) > offset_max)) {
1063
2
        expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag);
1064
2
        return offset;
1065
2
      }
1066
1067
      /* skip past alignment octet */
1068
1
      offset += 3;
1069
1070
      /* sensitivity level */
1071
1
      proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA);
1072
1
      offset += 1;
1073
1074
1
      if (taglen > 4) {
1075
1
        int offset_max_cat = offset + taglen - 4;
1076
1
        wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, "");
1077
1078
3
        while ((offset + 2) <= offset_max_cat) {
1079
2
          if (wmem_strbuf_get_len(cat_str_buf) > 0)
1080
1
            wmem_strbuf_append_c(cat_str_buf, ',');
1081
1082
2
          wmem_strbuf_append_printf(cat_str_buf, "%u", tvb_get_ntohs(tvb, offset));
1083
2
          offset += 2;
1084
2
        }
1085
1086
1
        proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset - taglen + 4, taglen - 4, wmem_strbuf_get_str(cat_str_buf));
1087
1
      }
1088
1
      break;
1089
5
    case 5:
1090
      /* ranged categories, see CIPSO draft section 3.4.4 for tag format */
1091
5
      if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) ||
1092
4
         ((offset + (int)taglen - 1) > offset_max)) {
1093
2
        expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag);
1094
2
        return offset;
1095
2
      }
1096
1097
      /* skip past alignment octet */
1098
3
      offset += 3;
1099
1100
      /* sensitivity level */
1101
3
      proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA);
1102
3
      offset += 1;
1103
1104
3
      if (taglen > 4) {
1105
3
        uint16_t cat_low, cat_high;
1106
3
        int offset_max_cat = offset + taglen - 4;
1107
3
        wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, "");
1108
1109
7
        while ((offset + 2) <= offset_max_cat) {
1110
4
          cat_high = tvb_get_ntohs(tvb, offset);
1111
4
          if ((offset + 4) <= offset_max_cat) {
1112
1
            cat_low = tvb_get_ntohs(tvb, offset + 2);
1113
1
            offset += 4;
1114
3
          } else {
1115
3
            cat_low = 0;
1116
3
            offset += 2;
1117
3
          }
1118
4
          if (wmem_strbuf_get_len(cat_str_buf) > 0)
1119
1
            wmem_strbuf_append_c(cat_str_buf, ',');
1120
1121
4
          if (cat_low != cat_high)
1122
3
            wmem_strbuf_append_printf(cat_str_buf, "%u-%u", cat_high, cat_low);
1123
1
          else
1124
1
            wmem_strbuf_append_printf(cat_str_buf, "%u", cat_high);
1125
4
        }
1126
1127
3
        proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset - taglen + 4, taglen - 4, wmem_strbuf_get_str(cat_str_buf));
1128
3
      }
1129
3
      break;
1130
6
    case 6:
1131
      /* permissive categories, see FIPS 188 section 6.9 for tag format */
1132
6
      if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) ||
1133
5
         ((offset + (int)taglen - 1) > offset_max)) {
1134
2
        expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag);
1135
2
        return offset;
1136
2
      }
1137
1138
4
      proto_tree_add_item(field_tree, hf_ip_cipso_tag_data, tvb, offset + 2, taglen - 2, ENC_NA);
1139
4
      offset += taglen;
1140
4
      break;
1141
4
    case 7:
1142
      /* free form, see FIPS 188 section 6.10 for tag format */
1143
4
      if ((taglen < 2) || (taglen > CIPSO_TAG_LEN_MAX) ||
1144
4
         ((offset + (int)taglen - 1) > offset_max)) {
1145
0
        expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag);
1146
0
        return offset;
1147
0
      }
1148
1149
4
      proto_tree_add_item(field_tree, hf_ip_cipso_tag_data, tvb, offset + 2, taglen - 2, ENC_NA);
1150
4
      offset += taglen;
1151
4
      break;
1152
7
    default:
1153
      /* unknown tag - stop parsing this IPv4 option */
1154
7
      if ((offset + 1) <= offset_max) {
1155
7
        taglen = tvb_get_uint8(tvb, offset + 1);
1156
7
        proto_item_append_text(tag_item, " (%u bytes)", taglen);
1157
7
        return offset;
1158
7
      }
1159
0
      return offset;
1160
66
    }
1161
66
  }
1162
1163
4
  return offset;
1164
20
}
1165
1166
static void
1167
dissect_option_route(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, int hf,
1168
                     int hf_host, bool next)
1169
18
{
1170
18
  proto_item *ti;
1171
18
  uint32_t route;
1172
1173
18
  route = tvb_get_ipv4(tvb, offset);
1174
18
  if (next)
1175
1
    proto_tree_add_ipv4_format_value(tree, hf, tvb, offset, 4, route,
1176
1
                                     "%s <- (next)",
1177
1
                                     tvb_ip_to_str(pinfo->pool, tvb, offset));
1178
17
  else
1179
17
    proto_tree_add_ipv4(tree, hf, tvb, offset, 4, route);
1180
1181
18
  if (!proto_field_is_referenced(tree, hf_host)) {
1182
15
    return;
1183
15
  }
1184
1185
3
  ti = proto_tree_add_string(tree, hf_host, tvb, offset, 4, get_hostname_wmem(pinfo->pool, route));
1186
3
  proto_item_set_generated(ti);
1187
3
  proto_item_set_hidden(ti);
1188
3
}
1189
1190
static int
1191
dissect_ipopt_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, int proto, int optlen_min)
1192
33
{
1193
33
  proto_tree *field_tree;
1194
33
  proto_item *tf;
1195
33
  uint8_t len, ptr;
1196
33
  int optoffset = 0;
1197
33
  int        offset = 0,
1198
33
             optlen = tvb_reported_length(tvb);
1199
1200
33
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto, ett_ip_option_route, &tf, optlen);
1201
1202
33
  tf = proto_tree_add_item_ret_uint8(field_tree, hf_ip_opt_ptr, tvb, offset + 2, 1, ENC_NA, &ptr);
1203
33
  if ((ptr < (optlen_min + 1)) || (ptr & 3)) {
1204
26
    if (ptr < (optlen_min + 1)) {
1205
21
      expert_add_info(pinfo, tf, &ei_ip_opt_ptr_before_address);
1206
21
    }
1207
5
    else {
1208
5
      expert_add_info(pinfo, tf, &ei_ip_opt_ptr_middle_address);
1209
5
    }
1210
26
    return optlen_min;
1211
26
  }
1212
1213
7
  len = optlen;
1214
7
  optoffset = 3;    /* skip past type, length and pointer */
1215
12
  for (optlen -= 3; optlen > 0; optlen -= 4, optoffset += 4) {
1216
8
    if (optlen < 4) {
1217
3
      expert_add_info(pinfo, tf, &ei_ip_subopt_too_long);
1218
3
      break;
1219
3
    }
1220
1221
5
    if (ptr > len) {
1222
      /* This is a recorded route */
1223
3
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt,
1224
3
                           hf_ip_rec_rt_host, false);
1225
3
    } else if (optoffset == (len - 4)) {
1226
      /* This is the destination */
1227
0
      proto_item *item;
1228
0
      uint32_t addr;
1229
0
      const char *dst_host;
1230
1231
0
      addr = tvb_get_ipv4(tvb, offset + optoffset);
1232
0
      proto_tree_add_ipv4(field_tree, hf_ip_dst, tvb,
1233
0
                          offset + optoffset, 4, addr);
1234
0
      item = proto_tree_add_ipv4(field_tree, hf_ip_addr, tvb,
1235
0
                                 offset + optoffset, 4, addr);
1236
0
      proto_item_set_hidden(item);
1237
0
      if (proto_field_is_referenced(field_tree, hf_ip_dst_host) || proto_field_is_referenced(field_tree, hf_ip_host)) {
1238
0
        dst_host = get_hostname_wmem(pinfo->pool, addr);
1239
0
        item = proto_tree_add_string(field_tree, hf_ip_dst_host, tvb,
1240
0
                                     offset + optoffset, 4, dst_host);
1241
0
        proto_item_set_generated(item);
1242
0
        proto_item_set_hidden(item);
1243
0
        item = proto_tree_add_string(field_tree, hf_ip_host, tvb,
1244
0
                                     offset + optoffset, 4, dst_host);
1245
0
        proto_item_set_generated(item);
1246
0
        proto_item_set_hidden(item);
1247
0
      }
1248
2
    } else if ((optoffset + 1) < ptr) {
1249
      /* This is also a recorded route */
1250
2
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt,
1251
2
                           hf_ip_rec_rt_host, false);
1252
2
    } else if ((optoffset + 1) == ptr) {
1253
      /* This is the next source route.  TODO: Should we use separate hf's
1254
       * for this, such as hf_ip_next_rt and hf_ip_next_rt_host and avoid
1255
       * having to pass true/false to dissect_option_route()? */
1256
0
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_src_rt,
1257
0
                           hf_ip_src_rt_host, true);
1258
0
    } else {
1259
      /* This must be a source route */
1260
0
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_src_rt,
1261
0
                           hf_ip_src_rt_host, false);
1262
0
    }
1263
5
  }
1264
1265
7
  return tvb_captured_length(tvb);
1266
33
}
1267
1268
static int
1269
dissect_ipopt_loose_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1270
29
{
1271
29
  return dissect_ipopt_route(tvb, pinfo, tree, proto_ip_option_route, IPOLEN_LSR_MIN);
1272
29
}
1273
1274
static int
1275
dissect_ipopt_source_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1276
4
{
1277
4
  return dissect_ipopt_route(tvb, pinfo, tree, proto_ip_option_source_route, IPOLEN_SSR_MIN);
1278
1279
4
}
1280
1281
static int
1282
dissect_ipopt_record_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1283
96
{
1284
96
  proto_tree *field_tree;
1285
96
  proto_item *tf;
1286
96
  uint8_t len, ptr;
1287
96
  int optoffset = 0;
1288
96
  int        offset = 0,
1289
96
             optlen = tvb_reported_length(tvb);
1290
1291
96
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_record_route, ett_ip_option_route, &tf, optlen);
1292
1293
96
  tf = proto_tree_add_item_ret_uint8(field_tree, hf_ip_opt_ptr, tvb, offset + 2, 1, ENC_NA, &ptr);
1294
1295
96
  if ((ptr < (IPOLEN_RR_MIN + 1)) || (ptr & 3)) {
1296
88
    if (ptr < (IPOLEN_RR_MIN + 1)) {
1297
46
      expert_add_info(pinfo, tf, &ei_ip_opt_ptr_before_address);
1298
46
    }
1299
42
    else {
1300
42
      expert_add_info(pinfo, tf, &ei_ip_opt_ptr_middle_address);
1301
42
    }
1302
88
    return IPOLEN_RR_MIN;
1303
88
  }
1304
1305
8
  len = optlen;
1306
8
  optoffset = 3;    /* skip past type, length and pointer */
1307
21
  for (optlen -= 3; optlen > 0; optlen -= 4, optoffset += 4) {
1308
15
    if (optlen < 4) {
1309
2
      expert_add_info(pinfo, tf, &ei_ip_subopt_too_long);
1310
2
      break;
1311
2
    }
1312
1313
13
    if (ptr > len) {
1314
      /* The recorded route data area is full. */
1315
10
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt,
1316
10
                           hf_ip_rec_rt_host, false);
1317
10
    } else if ((optoffset + 1) < ptr) {
1318
      /* This is a recorded route */
1319
2
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt,
1320
2
                           hf_ip_rec_rt_host, false);
1321
2
    } else if ((optoffset + 1) == ptr) {
1322
      /* This is the next available slot.  TODO: Should we use separate hf's
1323
       * for this, such as hf_ip_next_rt and hf_ip_next_rt_host and avoid
1324
       * having to pass true/false to dissect_option_route()? */
1325
1
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_empty_rt,
1326
1
                           hf_ip_empty_rt_host, true);
1327
1
    } else {
1328
      /* This must be an available slot too. */
1329
0
      dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_empty_rt,
1330
0
                           hf_ip_empty_rt_host, false);
1331
0
    }
1332
13
  }
1333
1334
8
  return tvb_captured_length(tvb);
1335
96
}
1336
1337
/* Stream Identifier */
1338
static int
1339
dissect_ipopt_sid(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1340
1
{
1341
1
  proto_tree *field_tree;
1342
1
  proto_item *tf;
1343
1344
1
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_sid, ett_ip_option_sid, &tf, IPOLEN_SID, tvb_reported_length(tvb));
1345
1
  expert_add_info(pinfo, tf, &ei_ip_opt_deprecated);
1346
1347
1
  proto_tree_add_item(field_tree, hf_ip_opt_sid, tvb, 2, 2, ENC_BIG_ENDIAN);
1348
1
  return tvb_captured_length(tvb);
1349
1
}
1350
1351
/* RFC 1063: MTU Probe and MTU Reply */
1352
static int
1353
dissect_ipopt_mtu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, int proto)
1354
30
{
1355
30
  proto_tree *field_tree;
1356
30
  proto_item *tf;
1357
1358
30
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto, ett_ip_option_mtu, &tf, IPOLEN_MTU, tvb_reported_length(tvb));
1359
1360
30
  proto_tree_add_item(field_tree, hf_ip_opt_mtu, tvb, 2, 2, ENC_BIG_ENDIAN);
1361
30
  return tvb_captured_length(tvb);
1362
30
}
1363
1364
static int
1365
dissect_ipopt_mtu_probe(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
1366
5
{
1367
5
  return dissect_ipopt_mtu(tvb, pinfo, tree, proto_ip_option_mtu_probe);
1368
5
}
1369
1370
static int
1371
dissect_ipopt_mtu_reply(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
1372
25
{
1373
25
  return dissect_ipopt_mtu(tvb, pinfo, tree, proto_ip_option_mtu_reply);
1374
25
}
1375
1376
/* RFC 1393: Traceroute */
1377
static int
1378
dissect_ipopt_tr(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1379
1
{
1380
1
  proto_tree *field_tree;
1381
1
  proto_item *tf;
1382
1
  int        offset = 2;
1383
1384
1
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_traceroute, ett_ip_option_tr, &tf, IPOLEN_TR, tvb_reported_length(tvb));
1385
1
  expert_add_info(pinfo, tf, &ei_ip_opt_deprecated);
1386
1387
1
  proto_tree_add_item(field_tree, hf_ip_opt_id_number, tvb, offset, 2, ENC_BIG_ENDIAN);
1388
1
  proto_tree_add_item(field_tree, hf_ip_opt_ohc, tvb, offset + 2, 2, ENC_BIG_ENDIAN);
1389
1
  proto_tree_add_item(field_tree, hf_ip_opt_rhc, tvb, offset + 4, 2, ENC_BIG_ENDIAN);
1390
1
  proto_tree_add_item(field_tree, hf_ip_opt_originator, tvb, offset + 6, 4, ENC_BIG_ENDIAN);
1391
1
  return tvb_captured_length(tvb);
1392
1
}
1393
1394
static const value_string ipopt_timestamp_flag_vals[] = {
1395
    {IPOPT_TS_TSONLY,    "Time stamps only"                      },
1396
    {IPOPT_TS_TSANDADDR, "Time stamp and address"                },
1397
    {IPOPT_TS_PRESPEC,   "Time stamps for prespecified addresses"},
1398
    {0,                  NULL                                    }};
1399
1400
static int
1401
dissect_ipopt_timestamp(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1402
12
{
1403
12
  proto_tree *field_tree;
1404
12
  proto_item *tf;
1405
12
  int        ptr;
1406
12
  int        optoffset = 0;
1407
12
  int        flg;
1408
12
  uint32_t addr;
1409
12
  int        offset = 0,
1410
12
             optlen = tvb_reported_length(tvb);
1411
1412
12
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_timestamp, ett_ip_option_timestamp, &tf, optlen);
1413
1414
12
  optoffset += 2;   /* skip past type and length */
1415
12
  optlen -= 2;      /* subtract size of type and length */
1416
1417
12
  ptr = tvb_get_uint8(tvb, offset + optoffset);
1418
12
  proto_tree_add_uint_format_value(field_tree, hf_ip_opt_ptr, tvb, offset + optoffset, 1, ptr, "%d%s",
1419
12
                      ptr, ((ptr == 1) ? " (header is full)" :
1420
12
                      (ptr < 5) ? " (points before first address)" :
1421
12
                      (((ptr - 1) & 3) ? " (points to middle of field)" : "")));
1422
12
  optoffset++;
1423
12
  optlen--;
1424
12
  ptr--;    /* ptr is 1-origin */
1425
1426
12
  flg = tvb_get_uint8(tvb, offset + optoffset);
1427
12
  proto_tree_add_item(field_tree, hf_ip_opt_overflow, tvb, offset + optoffset, 1, ENC_NA);
1428
12
  flg &= 0xF;
1429
12
  proto_tree_add_item(field_tree, hf_ip_opt_flag, tvb, offset + optoffset, 1, ENC_NA);
1430
12
  optoffset++;
1431
12
  optlen--;
1432
1433
31
  while (optlen > 0) {
1434
26
    if (flg == IPOPT_TS_TSANDADDR || flg == IPOPT_TS_PRESPEC) {
1435
4
      if (optlen < 8) {
1436
4
        proto_tree_add_expert(field_tree, pinfo, &ei_ip_subopt_too_long, tvb, offset + optoffset, optlen);
1437
4
        break;
1438
4
      }
1439
0
      addr = tvb_get_ipv4(tvb, offset + optoffset);
1440
0
      if (proto_field_is_referenced(field_tree, hf_ip_opt_time_stamp_addr)) {
1441
0
        proto_tree_add_ipv4_format_value(field_tree, hf_ip_opt_time_stamp_addr, tvb, offset + optoffset, 4, addr,
1442
0
              "%s", ((addr == 0) ? "-" : get_hostname_wmem(pinfo->pool, addr)));
1443
0
      }
1444
0
      optoffset += 4;
1445
0
      optlen -= 4;
1446
1447
0
      proto_tree_add_item(field_tree, hf_ip_opt_time_stamp, tvb, offset + optoffset, 4, ENC_BIG_ENDIAN);
1448
0
      optoffset += 4;
1449
0
      optlen -= 4;
1450
22
    } else {
1451
22
      if (optlen < 4) {
1452
3
        proto_tree_add_expert(field_tree, pinfo, &ei_ip_subopt_too_long, tvb, offset + optoffset, optlen);
1453
3
        break;
1454
3
      }
1455
19
      proto_tree_add_item(field_tree, hf_ip_opt_time_stamp, tvb, offset + optoffset, 4, ENC_BIG_ENDIAN);
1456
19
      optoffset += 4;
1457
19
      optlen -= 4;
1458
19
    }
1459
26
  }
1460
1461
12
  return tvb_captured_length(tvb);
1462
12
}
1463
1464
/* Router Alert */
1465
static const range_string ra_rvals[] = {
1466
  {0, 0, "Router shall examine packet"},
1467
  {1, 65535, "Reserved"},
1468
  {0, 0, NULL}
1469
};
1470
1471
static int
1472
dissect_ipopt_ra(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1473
2
{
1474
  /* Router-Alert, as defined by RFC2113 */
1475
2
  proto_tree *field_tree;
1476
2
  proto_item *tf;
1477
2
  uint32_t value;
1478
1479
2
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_routeralert, ett_ip_option_ra, &tf, IPOLEN_RA, tvb_reported_length(tvb));
1480
1481
2
  proto_tree_add_item_ret_uint(field_tree, hf_ip_opt_ra, tvb, 2, 2, ENC_BIG_ENDIAN, &value);
1482
2
  proto_item_append_text(tf, ": %s (%u)", rval_to_str_wmem(pinfo->pool, value, ra_rvals, "Unknown (%u)"), value);
1483
2
  return tvb_captured_length(tvb);
1484
2
}
1485
1486
/* RFC 1770: Selective Directed Broadcast */
1487
static int
1488
dissect_ipopt_sdb(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1489
6
{
1490
6
  proto_tree *field_tree;
1491
6
  proto_item *tf;
1492
6
  int        offset = 0,
1493
6
             optlen = tvb_reported_length(tvb);
1494
1495
6
  field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_sdb, ett_ip_option_sdb, &tf, optlen);
1496
6
  expert_add_info(pinfo, tf, &ei_ip_opt_deprecated);
1497
1498
7
  for (offset += 2, optlen -= 2; optlen >= 4; offset += 4, optlen -= 4)
1499
1
    proto_tree_add_item(field_tree, hf_ip_opt_addr, tvb, offset, 4, ENC_BIG_ENDIAN);
1500
1501
6
  if (optlen > 0)
1502
1
    proto_tree_add_item(field_tree, hf_ip_opt_padding, tvb, offset, optlen, ENC_NA);
1503
1504
6
  return tvb_captured_length(tvb);
1505
6
}
1506
1507
const value_string qs_func_vals[] = {
1508
  {QS_RATE_REQUEST, "Rate request"},
1509
  {QS_RATE_REPORT,  "Rate report"},
1510
  {0,               NULL}
1511
};
1512
1513
static const value_string qs_rate_vals[] = {
1514
  { 0, "0 bit/s"},
1515
  { 1, "80 Kbit/s"},
1516
  { 2, "160 Kbit/s"},
1517
  { 3, "320 Kbit/s"},
1518
  { 4, "640 Kbit/s"},
1519
  { 5, "1.28 Mbit/s"},
1520
  { 6, "2.56 Mbit/s"},
1521
  { 7, "5.12 Mbit/s"},
1522
  { 8, "10.24 Mbit/s"},
1523
  { 9, "20.48 Mbit/s"},
1524
  {10, "40.96 Mbit/s"},
1525
  {11, "81.92 Mbit/s"},
1526
  {12, "163.84 Mbit/s"},
1527
  {13, "327.68 Mbit/s"},
1528
  {14, "655.36 Mbit/s"},
1529
  {15, "1.31072 Gbit/s"},
1530
  {0, NULL}
1531
};
1532
value_string_ext qs_rate_vals_ext = VALUE_STRING_EXT_INIT(qs_rate_vals);
1533
1534
static int
1535
dissect_ipopt_qs(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data)
1536
5
{
1537
5
  proto_tree *field_tree;
1538
5
  proto_item *tf;
1539
5
  proto_item *ti;
1540
5
  ws_ip4 *iph = (ws_ip4 *)data;
1541
5
  int        offset = 2;
1542
1543
5
  uint8_t command = tvb_get_uint8(tvb, offset);
1544
5
  uint8_t function = command >> 4;
1545
5
  uint8_t rate = command & QS_RATE_MASK;
1546
5
  uint8_t ttl_diff;
1547
1548
5
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_qs, ett_ip_option_qs, &tf, IPOLEN_QS, tvb_reported_length(tvb));
1549
5
  proto_item_append_text(tf, ": %s (%u)", val_to_str(pinfo->pool, function, qs_func_vals, "Unknown (%u)"), function);
1550
1551
5
  proto_tree_add_item(field_tree, hf_ip_opt_qs_func, tvb, offset, 1, ENC_NA);
1552
1553
5
  if (function == QS_RATE_REQUEST) {
1554
2
    proto_tree_add_item(field_tree, hf_ip_opt_qs_rate, tvb, offset, 1, ENC_NA);
1555
2
    proto_tree_add_item(field_tree, hf_ip_opt_qs_ttl, tvb, offset + 1, 1, ENC_NA);
1556
2
    ttl_diff = (iph->ip_ttl - tvb_get_uint8(tvb, offset + 1) % 256);
1557
2
    ti = proto_tree_add_uint(field_tree, hf_ip_opt_qs_ttl_diff,
1558
2
                                          tvb, offset + 1, 1, ttl_diff);
1559
2
    proto_item_set_generated(ti);
1560
2
    proto_item_append_text(tf, ", %s, QS TTL %u, QS TTL diff %u",
1561
2
                           val_to_str_ext(pinfo->pool, rate, &qs_rate_vals_ext, "Unknown (%u)"),
1562
2
                           tvb_get_uint8(tvb, offset + 1), ttl_diff);
1563
2
    proto_tree_add_item(field_tree, hf_ip_opt_qs_nonce, tvb, offset + 2, 4, ENC_BIG_ENDIAN);
1564
2
    proto_tree_add_item(field_tree, hf_ip_opt_qs_reserved, tvb, offset + 2, 4, ENC_BIG_ENDIAN);
1565
3
  } else if (function == QS_RATE_REPORT) {
1566
1
    proto_tree_add_item(field_tree, hf_ip_opt_qs_rate, tvb, offset, 1, ENC_NA);
1567
1
    proto_item_append_text(tf, ", %s",
1568
1
                           val_to_str_ext(pinfo->pool, rate, &qs_rate_vals_ext, "Unknown (%u)"));
1569
1
    proto_tree_add_item(field_tree, hf_ip_opt_qs_unused, tvb, offset + 1, 1, ENC_NA);
1570
1
    proto_tree_add_item(field_tree, hf_ip_opt_qs_nonce, tvb, offset + 2, 4, ENC_BIG_ENDIAN);
1571
1
    proto_tree_add_item(field_tree, hf_ip_opt_qs_reserved, tvb, offset + 2, 4, ENC_BIG_ENDIAN);
1572
1
  }
1573
1574
5
  return tvb_captured_length(tvb);
1575
5
}
1576
1577
1578
static int
1579
dissect_ipopt_cilium_dsr(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_)
1580
1
{
1581
1
  proto_tree *field_tree;
1582
1
  proto_item *tf;
1583
1
  int        offset = 2;
1584
1585
1
  field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_dsr, ett_ip_option_dsr, &tf, IPOLEN_DSR, tvb_reported_length(tvb));
1586
1587
1
  proto_tree_add_item(field_tree, hf_ip_opt_dsr_cilium_service_port, tvb, offset, 2, ENC_LITTLE_ENDIAN);
1588
1
  offset += 2;
1589
1590
  /* Yes, it is encoded with little endian */
1591
1
  proto_tree_add_item(field_tree, hf_ip_opt_dsr_cilium_service_ip, tvb, offset, 4, ENC_LITTLE_ENDIAN);
1592
1593
1
  return tvb_captured_length(tvb);
1594
1
}
1595
1596
static void
1597
dissect_ip_options(tvbuff_t *tvb, int offset, unsigned length,
1598
                       packet_info *pinfo, proto_tree *opt_tree,
1599
                       proto_item *opt_item, void * data)
1600
55.6k
{
1601
55.6k
  unsigned char     opt;
1602
55.6k
  unsigned int      optlen;
1603
55.6k
  proto_tree       *field_tree;
1604
55.6k
  const char       *name;
1605
55.6k
  dissector_handle_t option_dissector;
1606
55.6k
  unsigned          nop_count = 0;
1607
55.6k
  tvbuff_t         *next_tvb;
1608
1609
61.7k
  while (length > 0) {
1610
61.1k
    opt = tvb_get_uint8(tvb, offset);
1611
61.1k
    --length;      /* account for type byte */
1612
1613
61.1k
    if ((opt == IPOPT_EOOL) || (opt == IPOPT_NOP)) {
1614
14.6k
      int local_proto;
1615
14.6k
      proto_item* field_item;
1616
      /* We assume that the only options with no length are EOL and NOP options,
1617
         so that we can treat unknown options as having a minimum length of 2,
1618
         and at least be able to move on to the next option by using the length in the option. */
1619
1620
14.6k
      if (opt == IPOPT_EOOL)
1621
12.6k
      {
1622
12.6k
        local_proto = proto_ip_option_eol;
1623
12.6k
      } else {
1624
        /* i.e. opt is IPOPT_NOP */
1625
1.97k
        local_proto = proto_ip_option_nop;
1626
1627
1.97k
        if (opt_item && (nop_count == 0 || offset % 4)) {
1628
          /* Count number of NOP in a row within a uint32 */
1629
1.94k
          nop_count++;
1630
1631
1.94k
          if (nop_count == 4) {
1632
38
            expert_add_info(pinfo, opt_item, &ei_ip_nop);
1633
38
          }
1634
1.94k
        } else {
1635
27
          nop_count = 0;
1636
27
        }
1637
1.97k
      }
1638
1639
14.6k
      field_item = proto_tree_add_item(opt_tree, local_proto, tvb, offset, 1, ENC_NA);
1640
14.6k
      field_tree = proto_item_add_subtree(field_item, ett_ip_option_other);
1641
1642
14.6k
      dissect_ipopt_type(tvb, offset, field_tree);
1643
14.6k
      offset++;
1644
1645
46.4k
    } else {
1646
46.4k
      option_dissector = dissector_get_uint_handle(ip_option_table, opt);
1647
46.4k
      if (option_dissector == NULL) {
1648
44.0k
        name = wmem_strdup_printf(pinfo->pool, "Unknown (0x%02x)", opt);
1649
44.0k
      } else {
1650
2.43k
        name = dissector_handle_get_protocol_short_name(option_dissector);
1651
2.43k
      }
1652
1653
      /* Option has a length. Is it in the packet? */
1654
46.4k
      if (length == 0) {
1655
        /* Bogus - packet must at least include option code byte and
1656
           length byte! */
1657
92
        proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, 1,
1658
92
                                     "%s (length byte past end of options)", name);
1659
92
        return;
1660
92
      }
1661
1662
46.3k
      optlen = tvb_get_uint8(tvb, offset + 1);  /* total including type, len */
1663
46.3k
      --length;    /* account for length byte */
1664
1665
46.3k
      if (optlen < 2) {
1666
        /* Bogus - option length is too short to include option code and option length. */
1667
10.2k
        proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, 2,
1668
10.2k
                                    "%s (with too-short option length = %u byte%s)",
1669
10.2k
                                    name, optlen, plurality(optlen, "", "s"));
1670
10.2k
        return;
1671
36.1k
      } else if (optlen - 2 > length) {
1672
        /* Bogus - option goes past the end of the header. */
1673
32.0k
        proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, length,
1674
32.0k
                                    "%s (option length = %u byte%s says option goes past end of options)",
1675
32.0k
                                    name, optlen, plurality(optlen, "", "s"));
1676
32.0k
        return;
1677
32.0k
      }
1678
1679
4.11k
      if (option_dissector == NULL) {
1680
3.88k
        field_tree = proto_tree_add_subtree_format(opt_tree, tvb, offset, optlen, ett_ip_unknown_opt, NULL, "%s (%u byte%s)",
1681
3.88k
                                              name, optlen, plurality(optlen, "", "s"));
1682
3.88k
        dissect_ipopt_type(tvb, offset, field_tree);
1683
1684
3.88k
        proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, offset+1, 1, ENC_NA);
1685
3.88k
        proto_tree_add_item(field_tree, hf_ip_opt_data, tvb, offset+2, optlen-2, ENC_NA);
1686
3.88k
      } else {
1687
230
        next_tvb = tvb_new_subset_length(tvb, offset, optlen);
1688
230
        call_dissector_with_data(option_dissector, next_tvb, pinfo, opt_tree, data);
1689
230
        proto_item_append_text(proto_tree_get_parent(opt_tree), ", %s", name);
1690
230
      }
1691
1692
4.11k
      offset += optlen;
1693
4.11k
      length -= (optlen-2); //already accounted for type and len bytes
1694
4.11k
    }
1695
1696
18.7k
    if (opt == IPOPT_EOOL)
1697
12.6k
      break;
1698
18.7k
  }
1699
55.6k
}
1700
1701
/* This function searches the IP options for either a loose or strict source
1702
 * route option, then returns the offset to the destination address if the
1703
 * pointer is still valid or zero if the pointer is greater than the length.
1704
 *
1705
 * The guts of this function was taken from dissect_ip_tcp_options().
1706
 */
1707
static int
1708
get_dst_offset(tvbuff_t *tvb, int offset, unsigned length)
1709
55.7k
{
1710
55.7k
  unsigned char     opt;
1711
55.7k
  unsigned          len;
1712
55.7k
  int               orig_offset = offset;
1713
1714
61.9k
  while (length > 0) {
1715
61.2k
    opt = tvb_get_uint8(tvb, offset);
1716
61.2k
    --length;      /* account for type byte */
1717
1718
61.2k
    if ((opt != IPOPT_EOOL) && (opt != IPOPT_NOP)) {
1719
      /* Option has a length. Is it in the packet? */
1720
46.4k
      if (length == 0) {
1721
        /* Bogus - packet must at least include option code byte and
1722
           length byte! */
1723
91
        return 0;
1724
91
      }
1725
46.3k
      len = tvb_get_uint8(tvb, offset + 1);  /* total including type, len */
1726
46.3k
      --length;    /* account for length byte */
1727
46.3k
      if (len < 2) {
1728
        /* Bogus - option length is too short to include option code and
1729
           option length. */
1730
10.2k
        return 0;
1731
36.1k
      } else if (len - 2 > length) {
1732
        /* Bogus - option goes past the end of the header. */
1733
32.0k
        return 0;
1734
32.0k
      }
1735
1736
4.14k
      if (opt == IPOPT_SSR || opt == IPOPT_LSR) {
1737
        /* Hmm, what if you have both options? */
1738
33
        uint8_t ptr;
1739
1740
33
        ptr = tvb_get_uint8(tvb, offset + 2);
1741
33
        if (ptr < 4 || (ptr & 3) || (ptr > len)) {
1742
31
          return 0;
1743
31
        }
1744
2
        return (offset - orig_offset) + 4 + (len - 4);
1745
33
      }
1746
1747
4.10k
      offset += len;
1748
4.10k
      length -= (len-2); /* subtract size of type and length */
1749
14.7k
    } else {
1750
14.7k
      offset += 1;
1751
14.7k
    }
1752
18.8k
    if (opt == IPOPT_EOOL)
1753
12.6k
      return 0;
1754
18.8k
  }
1755
1756
751
  return 0;
1757
55.7k
}
1758
1759
/* Returns the valid ttl for the group address */
1760
static uint16_t
1761
local_network_control_block_addr_valid_ttl(uint32_t addr)
1762
7
{
1763
  /* An exception list, as some protocols seem to insist on
1764
   * doing differently:
1765
   */
1766
1767
  /* IETF's VRRP (rfc3768) */
1768
7
  if (IPLOCAL_NETWRK_CTRL_BLK_VRRP_ADDR == addr)
1769
0
    return IPLOCAL_NETWRK_CTRL_BLK_VRRP_TTL;
1770
  /* Cisco's GLPB */
1771
7
  if (IPLOCAL_NETWRK_CTRL_BLK_GLPB_ADDR == addr)
1772
1
    return IPLOCAL_NETWRK_CTRL_BLK_GLPB_TTL;
1773
  /* mDNS (draft-cheshire-dnsext-multicastdns-07) */
1774
6
  if (IPLOCAL_NETWRK_CTRL_BLK_MDNS_ADDR == addr)
1775
0
    return IPLOCAL_NETWRK_CTRL_BLK_MDNS_TTL;
1776
  /* LLMNR (rfc4795) */
1777
6
  if (IPLOCAL_NETWRK_CTRL_BLK_LLMNR_ADDR == addr)
1778
0
    return IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL;
1779
6
  return IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL;
1780
6
}
1781
1782
static const value_string dscp_short_vals[] = {
1783
  { IPDSFIELD_DSCP_DEFAULT, "CS0"    },
1784
  { IPDSFIELD_DSCP_LE,      "LE"     },
1785
  { IPDSFIELD_DSCP_CS1,     "CS1"    },
1786
  { IPDSFIELD_DSCP_AF11,    "AF11"   },
1787
  { IPDSFIELD_DSCP_AF12,    "AF12"   },
1788
  { IPDSFIELD_DSCP_AF13,    "AF13"   },
1789
  { IPDSFIELD_DSCP_CS2,     "CS2"    },
1790
  { IPDSFIELD_DSCP_AF21,    "AF21"   },
1791
  { IPDSFIELD_DSCP_AF22,    "AF22"   },
1792
  { IPDSFIELD_DSCP_AF23,    "AF23"   },
1793
  { IPDSFIELD_DSCP_CS3,     "CS3"    },
1794
  { IPDSFIELD_DSCP_AF31,    "AF31"   },
1795
  { IPDSFIELD_DSCP_AF32,    "AF32"   },
1796
  { IPDSFIELD_DSCP_AF33,    "AF33"   },
1797
  { IPDSFIELD_DSCP_CS4,     "CS4"    },
1798
  { IPDSFIELD_DSCP_AF41,    "AF41"   },
1799
  { IPDSFIELD_DSCP_AF42,    "AF42"   },
1800
  { IPDSFIELD_DSCP_AF43,    "AF43"   },
1801
  { IPDSFIELD_DSCP_CS5,     "CS5"    },
1802
  { IPDSFIELD_VOICE_ADMIT,  "VOICE-ADMIT" },
1803
  { IPDSFIELD_DSCP_EF,      "EF"     },
1804
  { IPDSFIELD_DSCP_CS6,     "CS6"    },
1805
  { IPDSFIELD_DSCP_CS7,     "CS7"    },
1806
  { 0,                      NULL     }};
1807
value_string_ext dscp_short_vals_ext = VALUE_STRING_EXT_INIT(dscp_short_vals);
1808
1809
1810
static const value_string dscp_vals[] = {
1811
  { IPDSFIELD_DSCP_DEFAULT, "Default"               },
1812
  { IPDSFIELD_DSCP_LE,      "Lower Effort"          },
1813
  { IPDSFIELD_DSCP_CS1,     "Class Selector 1"      },
1814
  { IPDSFIELD_DSCP_AF11,    "Assured Forwarding 11" },
1815
  { IPDSFIELD_DSCP_AF12,    "Assured Forwarding 12" },
1816
  { IPDSFIELD_DSCP_AF13,    "Assured Forwarding 13" },
1817
  { IPDSFIELD_DSCP_CS2,     "Class Selector 2"      },
1818
  { IPDSFIELD_DSCP_AF21,    "Assured Forwarding 21" },
1819
  { IPDSFIELD_DSCP_AF22,    "Assured Forwarding 22" },
1820
  { IPDSFIELD_DSCP_AF23,    "Assured Forwarding 23" },
1821
  { IPDSFIELD_DSCP_CS3,     "Class Selector 3"      },
1822
  { IPDSFIELD_DSCP_AF31,    "Assured Forwarding 31" },
1823
  { IPDSFIELD_DSCP_AF32,    "Assured Forwarding 32" },
1824
  { IPDSFIELD_DSCP_AF33,    "Assured Forwarding 33" },
1825
  { IPDSFIELD_DSCP_CS4,     "Class Selector 4"      },
1826
  { IPDSFIELD_DSCP_AF41,    "Assured Forwarding 41" },
1827
  { IPDSFIELD_DSCP_AF42,    "Assured Forwarding 42" },
1828
  { IPDSFIELD_DSCP_AF43,    "Assured Forwarding 43" },
1829
  { IPDSFIELD_DSCP_CS5,     "Class Selector 5"      },
1830
  { IPDSFIELD_VOICE_ADMIT,  "Voice Admit"           },
1831
  { IPDSFIELD_DSCP_EF,      "Expedited Forwarding"  },
1832
  { IPDSFIELD_DSCP_CS6,     "Class Selector 6"      },
1833
  { IPDSFIELD_DSCP_CS7,     "Class Selector 7"      },
1834
  { 0,                      NULL                    }};
1835
value_string_ext dscp_vals_ext = VALUE_STRING_EXT_INIT(dscp_vals);
1836
1837
static const value_string ecn_short_vals[] = {
1838
  { IPDSFIELD_ECT_NOT, "Not-ECT" },
1839
  { IPDSFIELD_ECT_1,   "ECT(1)"  },
1840
  { IPDSFIELD_ECT_0,   "ECT(0)"  },
1841
  { IPDSFIELD_CE,      "CE"      },
1842
  { 0,                 NULL      }};
1843
value_string_ext ecn_short_vals_ext = VALUE_STRING_EXT_INIT(ecn_short_vals);
1844
1845
static const value_string ecn_vals[] = {
1846
  { IPDSFIELD_ECT_NOT, "Not ECN-Capable Transport"            },
1847
  { IPDSFIELD_ECT_1,   "ECN-Capable Transport codepoint '01'" },
1848
  { IPDSFIELD_ECT_0,   "ECN-Capable Transport codepoint '10'" },
1849
  { IPDSFIELD_CE,      "Congestion Experienced"               },
1850
  { 0,                 NULL                                   }};
1851
value_string_ext ecn_vals_ext = VALUE_STRING_EXT_INIT(ecn_vals);
1852
1853
static const value_string precedence_vals[] = {
1854
  { IPTOS_PREC_ROUTINE,         "routine"              },
1855
  { IPTOS_PREC_PRIORITY,        "priority"             },
1856
  { IPTOS_PREC_IMMEDIATE,       "immediate"            },
1857
  { IPTOS_PREC_FLASH,           "flash"                },
1858
  { IPTOS_PREC_FLASHOVERRIDE,   "flash override"       },
1859
  { IPTOS_PREC_CRITIC_ECP,      "CRITIC/ECP"           },
1860
  { IPTOS_PREC_INTERNETCONTROL, "internetwork control" },
1861
  { IPTOS_PREC_NETCONTROL,      "network control"      },
1862
  { 0,                          NULL                   }};
1863
1864
static const value_string iptos_vals[] = {
1865
  { IPTOS_NONE,        "None" },
1866
  { IPTOS_LOWCOST,     "Minimize cost" },
1867
  { IPTOS_RELIABILITY, "Maximize reliability" },
1868
  { IPTOS_THROUGHPUT,  "Maximize throughput" },
1869
  { IPTOS_LOWDELAY,    "Minimize delay" },
1870
  { IPTOS_SECURITY,    "Maximize security" },
1871
  { 0,                 NULL }
1872
};
1873
1874
static const true_false_string flags_sf_set_evil = {
1875
  "Evil",
1876
  "Not evil"
1877
};
1878
1879
bool
1880
ip_try_dissect(bool heur_first, unsigned nxt, tvbuff_t *tvb, packet_info *pinfo,
1881
               proto_tree *tree, void *iph)
1882
84.8k
{
1883
84.8k
  heur_dtbl_entry_t *hdtbl_entry;
1884
1885
84.8k
  if ((heur_first) && (dissector_try_heuristic(heur_subdissector_list, tvb,
1886
0
                       pinfo, tree, &hdtbl_entry, iph))) {
1887
0
    return true;
1888
0
  }
1889
1890
84.8k
  if (dissector_try_uint_with_data(ip_dissector_table, nxt, tvb, pinfo,
1891
84.8k
                             tree, true, iph)) {
1892
49.1k
    return true;
1893
49.1k
  }
1894
1895
35.7k
  if ((!heur_first) && (dissector_try_heuristic(heur_subdissector_list, tvb,
1896
573
                                                 pinfo, tree, &hdtbl_entry,
1897
573
                                                 iph))) {
1898
7
    return true;
1899
7
  }
1900
1901
35.7k
  return false;
1902
35.7k
}
1903
1904
static void
1905
export_pdu(tvbuff_t *tvb, packet_info *pinfo)
1906
65.6k
{
1907
65.6k
  if (have_tap_listener(exported_pdu_tap)) {
1908
0
    exp_pdu_data_t *exp_pdu_data = wmem_new0(pinfo->pool, exp_pdu_data_t);
1909
1910
0
    exp_pdu_data->tvb_captured_length = tvb_captured_length(tvb);
1911
0
    exp_pdu_data->tvb_reported_length = tvb_reported_length(tvb);
1912
0
    exp_pdu_data->pdu_tvb = tvb;
1913
0
    tap_queue_packet(exported_pdu_tap, pinfo, exp_pdu_data);
1914
0
  }
1915
65.6k
}
1916
1917
static struct ip_analysis *
1918
init_ip_conversation_data(packet_info *pinfo)
1919
14.6k
{
1920
14.6k
    struct ip_analysis *ipd;
1921
1922
    /* Initialize the ip protocol data structure to add to the ip conversation */
1923
14.6k
    ipd=wmem_new0(wmem_file_scope(), struct ip_analysis);
1924
1925
14.6k
    ipd->initial_frame = pinfo->num;
1926
14.6k
    ipd->stream = 0;
1927
14.6k
    ipd->stream = ip_stream_count++;
1928
1929
14.6k
    return ipd;
1930
14.6k
}
1931
1932
struct ip_analysis *
1933
get_ip_conversation_data(conversation_t *conv, packet_info *pinfo)
1934
65.0k
{
1935
65.0k
  struct ip_analysis *ipd;
1936
1937
  /* Did the caller supply the conversation pointer? */
1938
65.0k
  if( conv==NULL ) {
1939
0
    return NULL;
1940
0
  }
1941
1942
  /* Get the data for this conversation */
1943
65.0k
  ipd=(struct ip_analysis *)conversation_get_proto_data(conv, proto_ip);
1944
1945
65.0k
  if (!ipd) {
1946
14.6k
    ipd = init_ip_conversation_data(pinfo);
1947
14.6k
    conversation_add_proto_data(conv, proto_ip, ipd);
1948
14.6k
  }
1949
1950
65.0k
  if (!ipd) {
1951
0
    return NULL;
1952
0
  }
1953
1954
65.0k
  return ipd;
1955
65.0k
}
1956
1957
2.84k
const char* ipprotostr(const int proto) {
1958
2.84k
  return val_to_str_ext_const(proto, &ipproto_val_ext, "Unknown");
1959
2.84k
}
1960
1961
static int
1962
dissect_ip_v4(tvbuff_t *tvb, packet_info *pinfo, proto_tree *parent_tree, void* data _U_)
1963
65.7k
{
1964
65.7k
  proto_tree *ip_tree, *field_tree = NULL;
1965
65.7k
  proto_item *ti, *tf;
1966
65.7k
  uint32_t   addr;
1967
65.7k
  int        offset = 0, dst_off;
1968
65.7k
  unsigned   hlen, optlen;
1969
65.7k
  uint16_t   ipsum;
1970
65.7k
  fragment_head *ipfd_head = NULL;
1971
65.7k
  tvbuff_t   *next_tvb;
1972
65.7k
  bool       update_col_info = true;
1973
65.7k
  bool       save_fragmented;
1974
65.7k
  ws_ip4 *iph;
1975
65.7k
  uint32_t   src32, dst32;
1976
65.7k
  proto_tree *tree;
1977
65.7k
  proto_item *item = NULL, *ttl_item;
1978
65.7k
  uint16_t ttl_valid;
1979
65.7k
  struct ip_analysis *ipd=NULL;
1980
1981
65.7k
  tree = parent_tree;
1982
65.7k
  iph = wmem_new0(pinfo->pool, ws_ip4);
1983
1984
65.7k
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "IPv4");
1985
65.7k
  col_clear(pinfo->cinfo, COL_INFO);
1986
1987
65.7k
  iph->ip_ver = tvb_get_bits8(tvb, 0, 4);
1988
1989
65.7k
  hlen = tvb_get_bits8(tvb, 4, 4) * 4;  /* IP header length, in bytes */
1990
1991
65.7k
  ti = proto_tree_add_item(tree, proto_ip, tvb, offset, hlen, ENC_NA);
1992
65.7k
  ip_tree = proto_item_add_subtree(ti, ett_ip);
1993
1994
65.7k
  tf = proto_tree_add_bits_item(ip_tree, hf_ip_version, tvb, 0, 4, ENC_NA);
1995
65.7k
  if (iph->ip_ver != 4) {
1996
30
    col_add_fstr(pinfo->cinfo, COL_INFO,
1997
30
                 "Bogus IPv4 version (%u, must be 4)", iph->ip_ver);
1998
30
    expert_add_info_format(pinfo, tf, &ei_ip_bogus_ip_version, "Bogus IPv4 version");
1999
    /* I have a Linux cooked capture with ethertype IPv4 containing an IPv6 packet, continue dissection in that case*/
2000
30
    if (iph->ip_ver == 6) {
2001
13
        call_dissector(ipv6_handle, tvb, pinfo, tree);
2002
13
    }
2003
2004
30
    return tvb_captured_length(tvb);
2005
30
  }
2006
2007
  /* if IP is not referenced from any filters we don't need to worry about
2008
     generating any tree items.  We must do this after we created the actual
2009
     protocol above so that proto hier stat still works though.
2010
     XXX: Note that because of the following optimization expert items must
2011
          not be generated inside of an 'if (tree) ...'
2012
          so that Analyze ! Expert ...  will work.
2013
  */
2014
65.7k
  if (!proto_field_is_referenced(parent_tree, proto_ip)) {
2015
10.0k
    tree = NULL;
2016
10.0k
  }
2017
2018
65.7k
  if (hlen < IPH_MIN_LEN) {
2019
87
    col_add_fstr(pinfo->cinfo, COL_INFO,
2020
87
                 "Bogus IP header length (%u, must be at least %u)",
2021
87
                 hlen, IPH_MIN_LEN);
2022
87
    tf = proto_tree_add_uint_bits_format_value(ip_tree, hf_ip_hdr_len, tvb, (offset<<3)+4, 4, hlen,
2023
87
                                               ENC_BIG_ENDIAN, "%u bytes (%u)", hlen, hlen>>2);
2024
87
    expert_add_info_format(pinfo, tf, &ei_ip_bogus_header_length,
2025
87
                           "Bogus IP header length (%u, must be at least %u)", hlen, IPH_MIN_LEN);
2026
87
    return tvb_captured_length(tvb);
2027
87
  }
2028
2029
  // This should be consistent with tcp.hdr_len.
2030
65.6k
  proto_tree_add_uint_bits_format_value(ip_tree, hf_ip_hdr_len, tvb, (offset<<3)+4, 4, hlen,
2031
65.6k
                               ENC_BIG_ENDIAN, "%u bytes (%u)", hlen, hlen>>2);
2032
2033
65.6k
  iph->ip_tos = tvb_get_uint8(tvb, offset + 1);
2034
65.6k
  if (g_ip_dscp_actif) {
2035
65.6k
    col_add_str(pinfo->cinfo, COL_DSCP_VALUE,
2036
65.6k
                val_to_str_ext(pinfo->pool, IPDSFIELD_DSCP(iph->ip_tos), &dscp_short_vals_ext, "%u"));
2037
65.6k
  }
2038
2039
65.6k
  if (tree) {
2040
55.5k
    if (g_ip_dscp_actif) {
2041
55.5k
      tf = proto_tree_add_item(ip_tree, hf_ip_dsfield, tvb, offset + 1, 1, ENC_NA);
2042
55.5k
      proto_item_append_text(tf, " (DSCP: %s, ECN: %s)",
2043
55.5k
            val_to_str_ext_const(IPDSFIELD_DSCP(iph->ip_tos), &dscp_short_vals_ext, "Unknown"),
2044
55.5k
            val_to_str_ext_const(IPDSFIELD_ECN(iph->ip_tos), &ecn_short_vals_ext, "Unknown"));
2045
2046
55.5k
      field_tree = proto_item_add_subtree(tf, ett_ip_dsfield);
2047
55.5k
      proto_tree_add_item(field_tree, hf_ip_dsfield_dscp, tvb, offset + 1, 1, ENC_NA);
2048
55.5k
      proto_tree_add_item(field_tree, hf_ip_dsfield_ecn, tvb, offset + 1, 1, ENC_NA);
2049
55.5k
    } else {
2050
0
      tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_tos, tvb, offset + 1, 1,
2051
0
                                      iph->ip_tos,
2052
0
                                      "0x%02x (%s)",
2053
0
                                      iph->ip_tos,
2054
0
                                      val_to_str_const(IPTOS_TOS(iph->ip_tos),
2055
0
                                                       iptos_vals, "Unknown"));
2056
2057
0
      field_tree = proto_item_add_subtree(tf, ett_ip_tos);
2058
0
      proto_tree_add_item(field_tree, hf_ip_tos_precedence, tvb, offset + 1, 1, ENC_NA);
2059
0
      proto_tree_add_item(field_tree, hf_ip_tos_delay, tvb, offset + 1, 1, ENC_NA);
2060
0
      proto_tree_add_item(field_tree, hf_ip_tos_throughput, tvb, offset + 1, 1, ENC_NA);
2061
0
      proto_tree_add_item(field_tree, hf_ip_tos_reliability, tvb, offset + 1, 1, ENC_NA);
2062
0
      proto_tree_add_item(field_tree, hf_ip_tos_cost, tvb, offset + 1, 1, ENC_NA);
2063
0
    }
2064
55.5k
  }
2065
2066
  /* Length of IP datagram.
2067
     XXX - what if this is greater than the reported length of the
2068
     tvbuff?  This could happen, for example, in an IP datagram
2069
     inside an ICMP datagram; we need to somehow let the
2070
     dissector we call know that, as it might want to avoid
2071
     doing its checksumming. */
2072
65.6k
  iph->ip_len = tvb_get_ntohs(tvb, offset + 2);
2073
2074
65.6k
  if (iph->ip_len < hlen) {
2075
10.8k
    if (ip_tso_supported && !iph->ip_len) {
2076
      /* TSO support enabled, and zero length.  Assume the zero length is
2077
       * the result of TSO, and use the reported length instead.  Note that
2078
       * we need to use the frame/reported length instead of the actually-
2079
       * available length, just in case a snaplen was used on capture. */
2080
10.8k
      iph->ip_len = tvb_reported_length(tvb);
2081
10.8k
      if (tree) {
2082
9.05k
        tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_len, tvb, offset + 2, 2,
2083
9.05k
          iph->ip_len,
2084
9.05k
          "%u bytes (reported as 0, presumed to be because of \"TCP segmentation offload\" (TSO))",
2085
9.05k
          iph->ip_len);
2086
9.05k
        proto_item_set_generated(tf);
2087
9.05k
      }
2088
10.8k
    } else {
2089
      /* TSO support not enabled, or non-zero length, so treat it as an error. */
2090
14
      col_add_fstr(pinfo->cinfo, COL_INFO,
2091
14
                   "Bogus IP length (%u, less than header length %u)",
2092
14
                   iph->ip_len, hlen);
2093
14
      tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_len, tvb, offset + 2, 2,
2094
14
          iph->ip_len,
2095
14
          "%u bytes (bogus, less than header length %u)",
2096
14
          iph->ip_len, hlen);
2097
14
      expert_add_info(pinfo, tf, &ei_ip_bogus_ip_length);
2098
      /* Can't dissect any further */
2099
14
      return tvb_captured_length(tvb);
2100
14
    }
2101
54.8k
  } else {
2102
54.8k
    tf = proto_tree_add_uint(ip_tree, hf_ip_len, tvb, offset + 2, 2, iph->ip_len);
2103
54.8k
    if (iph->ip_len > tvb_reported_length(tvb)) {
2104
      /*
2105
       * Length runs past the data we're given.
2106
       * Note that if not in a ICMP error packet.
2107
       */
2108
54.5k
      if (!pinfo->flags.in_error_pkt) {
2109
52.0k
        expert_add_info_format(pinfo, tf, &ei_ip_bogus_ip_length,
2110
52.0k
                               "IPv4 total length exceeds packet length (%u bytes)",
2111
52.0k
                               tvb_reported_length(tvb));
2112
52.0k
      }
2113
54.5k
    } else {
2114
292
      if (iph->ip_len == hlen) {
2115
        /* IP header with no data.  Let the user know */
2116
1
        expert_add_info(pinfo, tf, &ei_ip_zero_data_length);
2117
1
      }
2118
2119
      /*
2120
       * Now that we know that the total length of this IP datagram isn't
2121
       * obviously bogus, adjust the length of this tvbuff to include only
2122
       * the IP datagram.
2123
       */
2124
292
      set_actual_length(tvb, iph->ip_len);
2125
292
    }
2126
54.8k
  }
2127
2128
  /* Only export after adjusting the length */
2129
65.6k
  export_pdu(tvb, pinfo);
2130
2131
65.6k
  iph->ip_id  = tvb_get_ntohs(tvb, offset + 4);
2132
65.6k
  if (tree)
2133
55.5k
    proto_tree_add_uint(ip_tree, hf_ip_id, tvb, offset + 4, 2, iph->ip_id);
2134
2135
65.6k
  iph->ip_off = tvb_get_ntohs(tvb, offset + 6);
2136
2137
65.6k
  if (ip_security_flag) {
2138
    /* RFC 3514 - The Security Flag in the IPv4 Header (April Fool's joke) */
2139
0
    static int * const ip_flags_evil[] = {
2140
0
        &hf_ip_flags_sf,
2141
0
        &hf_ip_flags_df,
2142
0
        &hf_ip_flags_mf,
2143
0
        NULL
2144
0
    };
2145
2146
0
    tf = proto_tree_add_bitmask_with_flags(ip_tree, tvb, offset + 6, hf_ip_flags,
2147
0
        ett_ip_flags, ip_flags_evil, ENC_BIG_ENDIAN, BMT_NO_FALSE | BMT_NO_TFS | BMT_NO_INT);
2148
0
    if (iph->ip_off & IP_RF) {
2149
0
        expert_add_info(pinfo, tf, &ei_ip_evil_packet);
2150
0
    }
2151
65.6k
  } else {
2152
65.6k
    static int * const ip_flags[] = {
2153
65.6k
        &hf_ip_flags_rf,
2154
65.6k
        &hf_ip_flags_df,
2155
65.6k
        &hf_ip_flags_mf,
2156
65.6k
        NULL
2157
65.6k
    };
2158
65.6k
    tf = proto_tree_add_bitmask_with_flags(ip_tree, tvb, offset + 6, hf_ip_flags,
2159
65.6k
        ett_ip_flags, ip_flags, ENC_BIG_ENDIAN, BMT_NO_FALSE | BMT_NO_TFS | BMT_NO_INT);
2160
65.6k
    if (iph->ip_off & IP_RF) {
2161
6.06k
      expert_add_info(pinfo, tf, &ei_ip_reserved_bit_set);
2162
6.06k
    }
2163
65.6k
  }
2164
2165
65.6k
  tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_frag_offset, tvb, offset + 6, 2,
2166
65.6k
                                        iph->ip_off, "%u", (iph->ip_off & IP_OFFSET) * 8);
2167
2168
65.6k
  iph->ip_ttl = tvb_get_uint8(tvb, offset + 8);
2169
65.6k
  ttl_item = proto_tree_add_item(ip_tree, hf_ip_ttl, tvb, offset + 8, 1, ENC_BIG_ENDIAN);
2170
2171
65.6k
  iph->ip_proto = tvb_get_uint8(tvb, offset + 9);
2172
65.6k
  if (tree) {
2173
55.5k
    proto_tree_add_item(ip_tree, hf_ip_proto, tvb, offset + 9, 1, ENC_BIG_ENDIAN);
2174
55.5k
  }
2175
2176
65.6k
  iph->ip_sum = tvb_get_ntohs(tvb, offset + 10);
2177
2178
  /*
2179
   * If checksum checking is enabled, and we have the entire IP header
2180
   * available, check the checksum.
2181
   */
2182
65.6k
  if (ip_check_checksum && tvb_bytes_exist(tvb, offset, hlen)) {
2183
0
    ipsum = ip_checksum_tvb(tvb, offset, hlen);
2184
0
    item = proto_tree_add_checksum(ip_tree, tvb, offset + 10, hf_ip_checksum, hf_ip_checksum_status, &ei_ip_checksum_bad, pinfo, ipsum,
2185
0
                                ENC_BIG_ENDIAN, PROTO_CHECKSUM_VERIFY|PROTO_CHECKSUM_IN_CKSUM);
2186
    /*
2187
     * ip_checksum_tvb() should never return 0xFFFF here, because, to
2188
     * quote RFC 1624 section 3 "Discussion":
2189
     *
2190
     *     In one's complement, there are two representations of
2191
     *     zero: the all zero and the all one bit values, often
2192
     *     referred to as +0 and -0.  One's complement addition
2193
     *     of non-zero inputs can produce -0 as a result, but
2194
     *     never +0.  Since there is guaranteed to be at least
2195
     *     one non-zero field in the IP header, and the checksum
2196
     *     field in the protocol header is the complement of the
2197
     *     sum, the checksum field can never contain ~(+0), which
2198
     *     is -0 (0xFFFF).  It can, however, contain ~(-0), which
2199
     *     is +0 (0x0000).
2200
     *
2201
     * ip_checksum_tvb() checksums the IPv4 header, where the "version"
2202
     * field is 4, ensuring that, in a valid IPv4 header, there is at
2203
     * least one non-zero field.  We've already verified that the
2204
     * version is 4.
2205
     *
2206
     * ip_checksum_tvb() returns the negation of the one's-complement
2207
     * sum of all the data handed to it, and that data won't be
2208
     * all zero, so the sum won't be 0 (+0), and thus the negation
2209
     * won't be -0, i.e. won't be 0xFFFF.
2210
     */
2211
0
    if (ipsum == 0) {
2212
      /* XXX - Keeping hf_ip_checksum_calculated field for now.  Doesn't fit into the
2213
        proto_tree_add_checksum design, but IP is a popular enough dissector that somebody
2214
        may have a legitimate reason for wanting it filtered */
2215
0
      item = proto_tree_add_uint(ip_tree, hf_ip_checksum_calculated, tvb,
2216
0
                                    offset + 10, 2, iph->ip_sum);
2217
0
      proto_item_set_generated(item);
2218
0
    } else {
2219
0
      proto_item_append_text(item, "(may be caused by \"IP checksum offload\"?)");
2220
2221
0
      item = proto_tree_add_uint(ip_tree, hf_ip_checksum_calculated, tvb,
2222
0
                                      offset + 10, 2, in_cksum_shouldbe(iph->ip_sum, ipsum));
2223
0
      proto_item_set_generated(item);
2224
0
    }
2225
65.6k
  } else {
2226
65.6k
    ipsum = 0;
2227
65.6k
    proto_tree_add_uint_format_value(ip_tree, hf_ip_checksum, tvb,
2228
65.6k
                                        offset + 10, 2, iph->ip_sum,
2229
65.6k
                                        "0x%04x [%s]",
2230
65.6k
                                        iph->ip_sum,
2231
65.6k
                                        ip_check_checksum ?
2232
0
                                            "not all data available" :
2233
65.6k
                                            "validation disabled");
2234
65.6k
    item = proto_tree_add_uint(ip_tree, hf_ip_checksum_status, tvb,
2235
65.6k
                                    offset + 10, 0, PROTO_CHECKSUM_E_UNVERIFIED);
2236
65.6k
    proto_item_set_generated(item);
2237
65.6k
  }
2238
65.6k
  src32 = tvb_get_ntohl(tvb, offset + IPH_SRC);
2239
65.6k
  set_address_tvb(&pinfo->net_src, AT_IPv4, 4, tvb, offset + IPH_SRC);
2240
65.6k
  copy_address_shallow(&pinfo->src, &pinfo->net_src);
2241
65.6k
  copy_address_shallow(&iph->ip_src, &pinfo->src);
2242
65.6k
  if (tree) {
2243
55.2k
    const char *src_host;
2244
2245
55.2k
    memcpy(&addr, iph->ip_src.data, 4);
2246
55.2k
    if (ip_summary_in_tree) {
2247
55.2k
      proto_item_append_text(ti, ", Src: %s", address_with_resolution_to_str(pinfo->pool, &iph->ip_src));
2248
55.2k
    }
2249
55.2k
    proto_tree_add_ipv4(ip_tree, hf_ip_src, tvb, offset + 12, 4, addr);
2250
55.2k
    item = proto_tree_add_ipv4(ip_tree, hf_ip_addr, tvb, offset + 12, 4, addr);
2251
55.2k
    proto_item_set_hidden(item);
2252
55.2k
    if (proto_field_is_referenced(ip_tree, hf_ip_src_host) || proto_field_is_referenced(ip_tree, hf_ip_host)) {
2253
55.2k
      src_host = get_hostname_wmem(pinfo->pool, addr);
2254
55.2k
      item = proto_tree_add_string(ip_tree, hf_ip_src_host, tvb, offset + 12, 4,
2255
55.2k
                                   src_host);
2256
55.2k
      proto_item_set_generated(item);
2257
55.2k
      proto_item_set_hidden(item);
2258
55.2k
      item = proto_tree_add_string(ip_tree, hf_ip_host, tvb, offset + 12, 4,
2259
55.2k
                                   src_host);
2260
55.2k
      proto_item_set_generated(item);
2261
55.2k
      proto_item_set_hidden(item);
2262
55.2k
    }
2263
55.2k
  }
2264
2265
  /* If there's an IP strict or loose source routing option, then the final
2266
   * L3 IP destination address will be the last entry in the routing header
2267
   * EXCEPT when the table is exhausted (pointer is greater than the length).
2268
   * In this case, the final L3 IP destination address is the one in the L3
2269
   * header. (REF: https://tools.ietf.org/html/rfc791#section-3.1)
2270
   */
2271
65.6k
  if (hlen > IPH_MIN_LEN) {
2272
    /* There's more than just the fixed-length header.  See if we've got
2273
     * either a strict or loose source route option and if so, return the
2274
     * offset into the tvb to where the real destination IP address is located.
2275
     */
2276
55.7k
    dst_off = get_dst_offset(tvb, offset + 20, hlen - IPH_MIN_LEN);
2277
55.7k
  }
2278
9.84k
  else
2279
9.84k
    dst_off = 0;
2280
2281
65.6k
  dst32 = tvb_get_ntohl(tvb, offset + IPH_DST + dst_off);
2282
65.6k
  set_address_tvb(&pinfo->net_dst, AT_IPv4, 4, tvb, offset + IPH_DST + dst_off);
2283
65.6k
  copy_address_shallow(&pinfo->dst, &pinfo->net_dst);
2284
65.6k
  copy_address_shallow(&iph->ip_dst, &pinfo->net_dst);
2285
2286
  /* XXX - We do not want pinfo->conv_elements, if set, to be used to find the
2287
   * default conversation after this, or else subdissectors will set the
2288
   * wrong dissector. This is a bit of a hack, it should be solved more
2289
   * generally. */
2290
65.6k
  pinfo->conv_elements = NULL;
2291
2292
  /* If an IP is destined for an IP address in the Local Network Control Block
2293
   * (e.g. 224.0.0.0/24), the packet should never be routed and the TTL would
2294
   * be expected to be 1.  (see RFC 3171)  Flag a TTL greater than 1.
2295
   *
2296
   * Flag a low TTL if the packet is not destined for a multicast address
2297
   * (e.g. 224.0.0.0/4) ... and the payload isn't protocol 103 (PIM).
2298
   * (see https://tools.ietf.org/html/rfc3973#section-4.7).
2299
   */
2300
65.6k
  if (in4_addr_is_local_network_control_block(dst32)) {
2301
8
    if (iph->ip_proto == IP_PROTO_IGMP)
2302
1
      ttl_valid = IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL;
2303
7
    else
2304
7
      ttl_valid = local_network_control_block_addr_valid_ttl(dst32);
2305
8
    if (iph->ip_ttl != ttl_valid && ttl_valid != IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL) {
2306
6
      expert_add_info_format(pinfo, ttl_item, &ei_ip_ttl_lncb, "\"Time To Live\" != %d for a packet sent to the "
2307
6
                             "Local Network Control Block (see RFC 3171)",
2308
6
                             ttl_valid);
2309
6
    }
2310
65.6k
  } else if (iph->ip_ttl < 5 && !in4_addr_is_multicast(dst32) &&
2311
        /* At least BGP should appear here as well */
2312
16.8k
        iph->ip_proto != IP_PROTO_PIM &&
2313
16.7k
        iph->ip_proto != IP_PROTO_OSPFIGP) {
2314
16.7k
    expert_add_info_format(pinfo, ttl_item, &ei_ip_ttl_too_small, "\"Time To Live\" only %u", iph->ip_ttl);
2315
16.7k
  }
2316
2317
65.6k
  if (tree) {
2318
55.1k
    const char *dst_host;
2319
2320
55.1k
    memcpy(&addr, iph->ip_dst.data, 4);
2321
55.1k
    if (ip_summary_in_tree) {
2322
55.1k
      proto_item_append_text(ti, ", Dst: %s", address_with_resolution_to_str(pinfo->pool, &iph->ip_dst));
2323
55.1k
    }
2324
2325
55.1k
    if (dst_off) {
2326
1
      uint32_t cur_rt;
2327
2328
1
      cur_rt = tvb_get_ipv4(tvb, offset + 16);
2329
1
      if (ip_summary_in_tree) {
2330
1
        proto_item_append_text(ti, ", Via: %s",
2331
1
            tvb_address_with_resolution_to_str(pinfo->pool, tvb, AT_IPv4, offset + 16));
2332
1
      }
2333
1
      proto_tree_add_ipv4(ip_tree, hf_ip_cur_rt, tvb, offset + 16, 4, cur_rt);
2334
1
      if (proto_field_is_referenced(ip_tree, hf_ip_cur_rt_host)) {
2335
1
        item = proto_tree_add_string(ip_tree, hf_ip_cur_rt_host, tvb,
2336
1
                                     offset + 16, 4, get_hostname_wmem(pinfo->pool, cur_rt));
2337
1
        proto_item_set_generated(item);
2338
1
        proto_item_set_hidden(item);
2339
1
      }
2340
1
    }
2341
55.1k
    else {
2342
55.1k
      proto_tree_add_ipv4(ip_tree, hf_ip_dst, tvb, offset + 16, 4, addr);
2343
55.1k
      item = proto_tree_add_ipv4(ip_tree, hf_ip_addr, tvb, offset + 16, 4,
2344
55.1k
                                 addr);
2345
55.1k
      proto_item_set_hidden(item);
2346
55.1k
      if (proto_field_is_referenced(ip_tree, hf_ip_dst_host) || proto_field_is_referenced(ip_tree, hf_ip_host)) {
2347
55.1k
        dst_host = get_hostname_wmem(pinfo->pool, addr);
2348
55.1k
        item = proto_tree_add_string(ip_tree, hf_ip_dst_host, tvb, offset + 16,
2349
55.1k
                                     4, dst_host);
2350
55.1k
        proto_item_set_generated(item);
2351
55.1k
        proto_item_set_hidden(item);
2352
55.1k
        item = proto_tree_add_string(ip_tree, hf_ip_host, tvb,
2353
55.1k
                                     offset + 16 + dst_off, 4, dst_host);
2354
55.1k
        proto_item_set_generated(item);
2355
55.1k
        proto_item_set_hidden(item);
2356
55.1k
      }
2357
55.1k
    }
2358
2359
55.1k
    if (gbl_resolv_flags.maxmind_geoip) {
2360
55.1k
      add_geoip_info(ip_tree, pinfo, tvb, offset, src32, dst32);
2361
55.1k
    }
2362
55.1k
  }
2363
2364
  /* Decode IP options, if any. */
2365
65.6k
  if (hlen > IPH_MIN_LEN) {
2366
    /* There's more than just the fixed-length header.  Decode the options. */
2367
55.6k
    optlen = hlen - IPH_MIN_LEN;  /* length of options, in bytes */
2368
55.6k
    field_tree = proto_tree_add_subtree_format(ip_tree, tvb, offset + 20, optlen,
2369
55.6k
                             ett_ip_options, &tf, "Options: (%u bytes)", optlen);
2370
55.6k
    dissect_ip_options(tvb, offset + 20, optlen, pinfo, field_tree, tf, iph);
2371
55.6k
  }
2372
2373
65.6k
  p_add_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num, iph);
2374
65.6k
  tap_queue_packet(ip_tap, pinfo, iph);
2375
2376
  /* Skip over header + options */
2377
65.6k
  offset += hlen;
2378
2379
  /* If ip_defragment is on, this is a fragment, we have all the data
2380
   * in the fragment, and the header checksum is valid, then just add
2381
   * the fragment to the hashtable.
2382
   */
2383
65.6k
  save_fragmented = pinfo->fragmented;
2384
65.6k
  if (ip_defragment && (iph->ip_off & (IP_MF|IP_OFFSET)) &&
2385
0
      iph->ip_len >= hlen &&
2386
0
      tvb_bytes_exist(tvb, offset, iph->ip_len - hlen) &&
2387
0
      ipsum == 0) {
2388
0
    uint32_t frag_id;
2389
0
    frag_id = iph->ip_proto ^ iph->ip_id ^ src32 ^ dst32;
2390
    /* XXX: Should there be a way to force the VLAN ID not to
2391
     * be taken into account for reassembly even with non publicly
2392
     * routable IP addresses?
2393
     */
2394
0
    if (in4_addr_is_private(dst32) || in4_addr_is_private(src32) ||
2395
0
        in4_addr_is_link_local(dst32) || in4_addr_is_link_local(src32) ||
2396
0
        prefs.strict_conversation_tracking_heuristics) {
2397
0
      frag_id ^= pinfo->vlan_id;
2398
0
    }
2399
0
    ipfd_head = fragment_add_check(&ip_reassembly_table, tvb, offset,
2400
0
                                   pinfo,
2401
0
                                   frag_id,
2402
0
                                   NULL,
2403
0
                                   (iph->ip_off & IP_OFFSET) * 8,
2404
0
                                   iph->ip_len - hlen,
2405
0
                                   iph->ip_off & IP_MF);
2406
2407
0
    next_tvb = process_reassembled_data(tvb, offset, pinfo, "Reassembled IPv4",
2408
0
                                        ipfd_head, &ip_frag_items,
2409
0
                                        &update_col_info, ip_tree);
2410
65.6k
  } else {
2411
    /* If this is the first fragment, dissect its contents, otherwise
2412
       just show it as a fragment.
2413
2414
       XXX - if we eventually don't save the reassembled contents of all
2415
       fragmented datagrams, we may want to always reassemble. */
2416
65.6k
    if (iph->ip_off & IP_OFFSET) {
2417
      /* Not the first fragment - don't dissect it. */
2418
414
      next_tvb = NULL;
2419
65.2k
    } else {
2420
      /* First fragment, or not fragmented.  Dissect what we have here. */
2421
2422
      /* Get a tvbuff for the payload. */
2423
65.2k
      next_tvb = tvb_new_subset_remaining(tvb, offset);
2424
2425
      /*
2426
       * If this is the first fragment, but not the only fragment,
2427
       * tell the next protocol that.
2428
       */
2429
65.2k
      if (iph->ip_off & IP_MF)
2430
30.1k
        pinfo->fragmented = true;
2431
35.0k
      else
2432
35.0k
        pinfo->fragmented = false;
2433
65.2k
    }
2434
65.6k
  }
2435
2436
#if 0
2437
  /* This would be automatic, but have the side effect that the stream IDs
2438
   * would depend on the order in which packets were dissected with a visible
2439
   * tree (e.g., clicking on them in Wireshark) instead of always being the
2440
   * same for a given file, which is probably unexpected.
2441
   */
2442
  if (proto_field_is_referenced(tree, hf_stream_id) || have_tap_listener(ip_tap)) {
2443
#endif
2444
65.6k
  if (ip_track_conv_id) {
2445
65.0k
    conversation_t *conv;
2446
2447
    /* find (and extend) an existing conversation, or create a new one */
2448
65.0k
    conv = find_conversation_strat(pinfo, CONVERSATION_IP, NO_PORT_X, false);
2449
65.0k
    if(!conv) {
2450
14.6k
      conv=conversation_new_strat(pinfo, CONVERSATION_IP, NO_PORTS);
2451
14.6k
    }
2452
50.4k
    else {
2453
      /*
2454
       * while not strictly necessary because there is only 1
2455
       * conversation between 2 IPs, we still move the last frame
2456
       * indicator as being a usual practice.
2457
       */
2458
50.4k
      if (!(pinfo->fd->visited)) {
2459
50.4k
        if (pinfo->num > conv->last_frame) {
2460
48.1k
          conv->last_frame = pinfo->num;
2461
48.1k
        }
2462
50.4k
      }
2463
50.4k
    }
2464
2465
65.0k
    ipd = get_ip_conversation_data(conv, pinfo);
2466
65.0k
    if(ipd) {
2467
65.0k
      iph->ip_stream = ipd->stream;
2468
2469
65.0k
      item = proto_tree_add_uint(ip_tree, hf_ip_stream, tvb, offset, 0, ipd->stream);
2470
65.0k
      proto_item_set_generated(item);
2471
65.0k
    }
2472
65.0k
  }
2473
2474
65.6k
  if (next_tvb == NULL) {
2475
    /* Just show this as a fragment. */
2476
414
    col_add_fstr(pinfo->cinfo, COL_INFO,
2477
414
                 "Fragmented IP protocol (proto=%s %u, off=%u, ID=%04x)",
2478
414
                 ipprotostr(iph->ip_proto), iph->ip_proto,
2479
414
                 (iph->ip_off & IP_OFFSET) * 8, iph->ip_id);
2480
414
    if ( ipfd_head && ipfd_head->reassembled_in != pinfo->num ) {
2481
0
      col_append_frame_number(pinfo, COL_INFO, " [Reassembled in #%u]",
2482
0
                      ipfd_head->reassembled_in);
2483
0
    }
2484
2485
414
    call_data_dissector(tvb_new_subset_remaining(tvb, offset), pinfo,
2486
414
                   parent_tree);
2487
414
    pinfo->fragmented = save_fragmented;
2488
414
    return tvb_captured_length(tvb);
2489
414
  }
2490
2491
65.2k
  if (tvb_reported_length(next_tvb) > 0) {
2492
    /* Hand off to the next protocol.
2493
2494
     XXX - setting the columns only after trying various dissectors means
2495
     that if one of those dissectors throws an exception, the frame won't
2496
     even be labeled as an IP frame; ideally, if a frame being dissected
2497
     throws an exception, it'll be labeled as a mangled frame of the
2498
     type in question. */
2499
64.6k
    if (!ip_try_dissect(try_heuristic_first, iph->ip_proto, next_tvb, pinfo,
2500
64.6k
                        parent_tree, iph)) {
2501
      /* Unknown protocol */
2502
148
      if (update_col_info) {
2503
148
        col_add_fstr(pinfo->cinfo, COL_INFO, "%s (%u)",
2504
148
                   ipprotostr(iph->ip_proto), iph->ip_proto);
2505
148
      }
2506
148
      call_data_dissector(next_tvb, pinfo, parent_tree);
2507
148
    }
2508
64.6k
  }
2509
65.2k
  pinfo->fragmented = save_fragmented;
2510
65.2k
  return tvb_captured_length(tvb);
2511
65.6k
}
2512
2513
/*
2514
 * Dissector that doesn't assume the packet is IPv4, it looks at the
2515
 * upper 4 bits of the first octet and:
2516
 *
2517
 *    if they're 4, dissects the packet as IPv4;
2518
 *
2519
 *    if they're 6, dissects the packet as IPv6;
2520
 *
2521
 *    otherwise, reports it as an error.
2522
 *
2523
 * This handles some strange cases where IPv6 packets are encapsulated
2524
 * with a header that indicates an IPv4 packet (see commit
2525
 * a784b121502575a8930de9a34accb85c29ce9b80, which, as I remember, was
2526
 * done to handle such a case), as well as cases where there is no
2527
 * header to distinguish between IPv4 and IPv6 (e.g., LINKTYPE_RAW
2528
 * packets in pcap and pcapng files).
2529
 */
2530
static int
2531
dissect_ip(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_)
2532
77.9k
{
2533
77.9k
  proto_tree *ip_tree;
2534
77.9k
  proto_item *ti, *tf;
2535
77.9k
  uint8_t version;
2536
2537
77.9k
  version = tvb_get_uint8(tvb, 0) >> 4;
2538
2539
77.9k
  if(version == 4){
2540
65.7k
    return dissect_ip_v4(tvb, pinfo, tree, data);
2541
65.7k
  }
2542
12.2k
  if(version == 6){
2543
11.7k
    return call_dissector(ipv6_handle, tvb, pinfo, tree);
2544
11.7k
  }
2545
2546
  /* Bogus IP version */
2547
509
  ti = proto_tree_add_protocol_format(tree, proto_ip, tvb, 0, 1, "Internet Protocol, bogus version (%u)", version);
2548
509
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "IP");
2549
509
  col_clear(pinfo->cinfo, COL_INFO);
2550
509
  col_add_fstr(pinfo->cinfo, COL_INFO, "Bogus IP version (%u)", version);
2551
509
  ip_tree = proto_item_add_subtree(ti, ett_ip);
2552
509
  tf = proto_tree_add_bits_item(ip_tree, hf_ip_version, tvb, 0, 4, ENC_NA);
2553
509
  expert_add_info(pinfo, tf, &ei_ip_bogus_ip_version);
2554
509
  return 1;
2555
12.2k
}
2556
2557
static bool
2558
dissect_ip_heur(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data)
2559
46
{
2560
46
  unsigned length, tot_length;
2561
46
  uint8_t oct, version, ihl;
2562
46
  bool ipv4_good = false;
2563
2564
  /*
2565
   * IPv4 Header Format
2566
   *
2567
   *  0                   1                   2                   3
2568
   *  0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
2569
   * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
2570
   * |Version|  IHL  |Type of Service|          Total Length         |
2571
   * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
2572
   */
2573
2574
46
  length = tvb_captured_length(tvb);
2575
46
  if (length < 4) {
2576
    /* Need at least 4 bytes to make some sort of decision */
2577
3
    return false;
2578
3
  }
2579
2580
43
  oct = tvb_get_uint8(tvb,0);
2581
43
  ihl = oct & 0x0f;
2582
43
  version = oct >> 4;
2583
2584
43
  if (version == 6) {
2585
2
    return dissect_ipv6_heur(tvb, pinfo, tree, data);
2586
2
  }
2587
2588
  /* version == IPv4, the minimum value for a correct header is 5 */
2589
41
  if ((version != 4) || (ihl < 5)) {
2590
40
    return false;
2591
40
  }
2592
2593
  /* Total Length is the length of the datagram, measured in octets,
2594
   *  including internet header and data.
2595
   */
2596
1
  tot_length = tvb_get_ntohs(tvb, 2);
2597
1
  if (tot_length == tvb_reported_length(tvb)) {
2598
0
    ipv4_good = true;
2599
1
  } else if (ip_check_checksum && tvb_bytes_exist(tvb, 0, ihl * 4)) {
2600
0
    if (ip_checksum_tvb(tvb, 0, ihl * 4) == 0) {
2601
0
      ipv4_good = true;
2602
0
    }
2603
0
  }
2604
2605
1
  if (ipv4_good)
2606
0
    dissect_ip_v4(tvb, pinfo, tree, data);
2607
1
  return ipv4_good;
2608
41
}
2609
2610
static void
2611
ip_init(void)
2612
16
{
2613
16
    ip_stream_count = 0;
2614
16
}
2615
2616
void
2617
proto_register_ip(void)
2618
16
{
2619
16
  static hf_register_info hf[] = {
2620
16
    { &hf_ip_version,
2621
16
      { "Version", "ip.version", FT_UINT8, BASE_DEC,
2622
16
        NULL, 0x00, NULL, HFILL }},
2623
2624
    // "IHL" in https://tools.ietf.org/html/rfc791#section-3.1 and
2625
    // https://en.wikipedia.org/wiki/IPv4#Header
2626
16
    { &hf_ip_hdr_len,
2627
16
      { "Header Length", "ip.hdr_len", FT_UINT8, BASE_DEC,
2628
16
        NULL, 0x0, "Header length in 32-bit words", HFILL }},
2629
2630
16
    { &hf_ip_dsfield,
2631
16
      { "Differentiated Services Field", "ip.dsfield", FT_UINT8, BASE_HEX,
2632
16
        NULL, 0x0, NULL, HFILL }},
2633
2634
16
    { &hf_ip_dsfield_dscp,
2635
16
      { "Differentiated Services Codepoint", "ip.dsfield.dscp", FT_UINT8, BASE_DEC | BASE_EXT_STRING,
2636
16
        &dscp_vals_ext, IPDSFIELD_DSCP_MASK, NULL, HFILL }},
2637
2638
16
    { &hf_ip_dsfield_ecn,
2639
16
      { "Explicit Congestion Notification", "ip.dsfield.ecn", FT_UINT8, BASE_DEC | BASE_EXT_STRING,
2640
16
        &ecn_vals_ext, IPDSFIELD_ECN_MASK, NULL, HFILL }},
2641
2642
16
    { &hf_ip_tos,
2643
16
      { "Type of Service", "ip.tos", FT_UINT8, BASE_DEC,
2644
16
        NULL, 0x0, NULL, HFILL }},
2645
2646
16
    { &hf_ip_tos_precedence,
2647
16
      { "Precedence", "ip.tos.precedence", FT_UINT8, BASE_DEC,
2648
16
        VALS(precedence_vals), IPTOS_PREC_MASK, NULL, HFILL }},
2649
2650
16
    { &hf_ip_tos_delay,
2651
16
      { "Delay", "ip.tos.delay", FT_BOOLEAN, 8,
2652
16
        TFS(&tfs_low_normal), IPTOS_LOWDELAY, NULL, HFILL }},
2653
2654
16
    { &hf_ip_tos_throughput,
2655
16
      { "Throughput", "ip.tos.throughput", FT_BOOLEAN, 8,
2656
16
        TFS(&tfs_high_normal), IPTOS_THROUGHPUT, NULL, HFILL }},
2657
2658
16
    { &hf_ip_tos_reliability,
2659
16
      { "Reliability", "ip.tos.reliability", FT_BOOLEAN, 8,
2660
16
        TFS(&tfs_high_normal), IPTOS_RELIABILITY, NULL, HFILL }},
2661
2662
16
    { &hf_ip_tos_cost,
2663
16
      { "Cost", "ip.tos.cost", FT_BOOLEAN, 8,
2664
16
        TFS(&tfs_low_normal), IPTOS_LOWCOST, NULL, HFILL }},
2665
2666
16
    { &hf_ip_len,
2667
16
      { "Total Length", "ip.len", FT_UINT16, BASE_DEC,
2668
16
        NULL, 0x0, NULL, HFILL }},
2669
2670
16
    { &hf_ip_id,
2671
16
      { "Identification", "ip.id", FT_UINT16, BASE_HEX_DEC,
2672
16
        NULL, 0x0, NULL, HFILL }},
2673
2674
16
    { &hf_ip_dst,
2675
16
      { "Destination Address", "ip.dst", FT_IPv4, BASE_NONE,
2676
16
        NULL, 0x0, NULL, HFILL }},
2677
2678
16
    { &hf_ip_dst_host,
2679
16
      { "Destination Host", "ip.dst_host", FT_STRING, BASE_NONE,
2680
16
        NULL, 0x0, NULL, HFILL }},
2681
2682
16
    { &hf_ip_src,
2683
16
      { "Source Address", "ip.src", FT_IPv4, BASE_NONE,
2684
16
        NULL, 0x0, NULL, HFILL }},
2685
2686
16
    { &hf_ip_src_host,
2687
16
      { "Source Host", "ip.src_host", FT_STRING, BASE_NONE,
2688
16
        NULL, 0x0, NULL, HFILL }},
2689
2690
16
    { &hf_ip_addr,
2691
16
      { "Source or Destination Address", "ip.addr", FT_IPv4, BASE_NONE,
2692
16
        NULL, 0x0, NULL, HFILL }},
2693
2694
16
    { &hf_ip_host,
2695
16
      { "Source or Destination Host", "ip.host", FT_STRING, BASE_NONE,
2696
16
        NULL, 0x0, NULL, HFILL }},
2697
2698
16
    { &hf_ip_stream,
2699
16
      { "Stream index", "ip.stream", FT_UINT32, BASE_DEC,
2700
16
        NULL, 0x0, NULL, HFILL }},
2701
2702
16
    { &hf_geoip_country,
2703
16
      { "Source or Destination GeoIP Country", "ip.geoip.country",
2704
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2705
16
    { &hf_geoip_country_iso,
2706
16
      { "Source or Destination GeoIP ISO Two Letter Country Code", "ip.geoip.country_iso",
2707
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2708
16
    { &hf_geoip_city,
2709
16
      { "Source or Destination GeoIP City", "ip.geoip.city",
2710
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2711
16
    { &hf_geoip_as_number,
2712
16
      { "Source or Destination GeoIP AS Number", "ip.geoip.asnum",
2713
16
        FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }},
2714
16
    { &hf_geoip_as_org,
2715
16
      { "Source or Destination GeoIP AS Organization", "ip.geoip.org",
2716
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2717
16
    { &hf_geoip_latitude,
2718
16
      { "Source or Destination GeoIP Latitude", "ip.geoip.lat",
2719
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2720
16
    { &hf_geoip_longitude,
2721
16
      { "Source or Destination GeoIP Longitude", "ip.geoip.lon",
2722
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2723
16
    { &hf_geoip_src_summary,
2724
16
      { "Source GeoIP", "ip.geoip.src_summary",
2725
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2726
16
    { &hf_geoip_src_country,
2727
16
      { "Source GeoIP Country", "ip.geoip.src_country",
2728
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2729
16
    { &hf_geoip_src_country_iso,
2730
16
      { "Source GeoIP ISO Two Letter Country Code", "ip.geoip.src_country_iso",
2731
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2732
16
    { &hf_geoip_src_city,
2733
16
      { "Source GeoIP City", "ip.geoip.src_city",
2734
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2735
16
    { &hf_geoip_src_as_number,
2736
16
      { "Source GeoIP AS Number", "ip.geoip.src_asnum",
2737
16
        FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }},
2738
16
    { &hf_geoip_src_as_org,
2739
16
      { "Source GeoIP AS Organization", "ip.geoip.src_org",
2740
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2741
16
    { &hf_geoip_src_latitude,
2742
16
      { "Source GeoIP Latitude", "ip.geoip.src_lat",
2743
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2744
16
    { &hf_geoip_src_longitude,
2745
16
      { "Source GeoIP Longitude", "ip.geoip.src_lon",
2746
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2747
16
    { &hf_geoip_dst_summary,
2748
16
      { "Destination GeoIP", "ip.geoip.dst_summary",
2749
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2750
16
    { &hf_geoip_dst_country,
2751
16
      { "Destination GeoIP Country", "ip.geoip.dst_country",
2752
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2753
16
    { &hf_geoip_dst_country_iso,
2754
16
      { "Destination GeoIP ISO Two Letter Country Code", "ip.geoip.dst_country_iso",
2755
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2756
16
    { &hf_geoip_dst_city,
2757
16
      { "Destination GeoIP City", "ip.geoip.dst_city",
2758
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2759
16
    { &hf_geoip_dst_as_number,
2760
16
      { "Destination GeoIP AS Number", "ip.geoip.dst_asnum",
2761
16
        FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }},
2762
16
    { &hf_geoip_dst_as_org,
2763
16
      { "Destination GeoIP AS Organization", "ip.geoip.dst_org",
2764
16
        FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2765
16
    { &hf_geoip_dst_latitude,
2766
16
      { "Destination GeoIP Latitude", "ip.geoip.dst_lat",
2767
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2768
16
    { &hf_geoip_dst_longitude,
2769
16
      { "Destination GeoIP Longitude", "ip.geoip.dst_lon",
2770
16
        FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }},
2771
2772
16
    { &hf_ip_flags,
2773
16
      { "Flags", "ip.flags", FT_UINT8, BASE_HEX,
2774
16
        NULL, 0xE0, NULL, HFILL }},
2775
2776
16
    { &hf_ip_flags_sf,
2777
16
      { "Security flag", "ip.flags.sf", FT_BOOLEAN, 8,
2778
16
        TFS(&flags_sf_set_evil), 0x80, "Security flag (RFC 3514)", HFILL }},
2779
2780
16
    { &hf_ip_flags_rf,
2781
16
      { "Reserved bit", "ip.flags.rb", FT_BOOLEAN, 8,
2782
16
        TFS(&tfs_set_notset), 0x80, "Reserved bit (must be zero; RFC 791)", HFILL } },
2783
2784
16
    { &hf_ip_flags_df,
2785
16
      { "Don't fragment", "ip.flags.df", FT_BOOLEAN, 8,
2786
16
        TFS(&tfs_set_notset), 0x40, NULL, HFILL }},
2787
2788
16
    { &hf_ip_flags_mf,
2789
16
      { "More fragments", "ip.flags.mf", FT_BOOLEAN, 8,
2790
16
        TFS(&tfs_set_notset), 0x20, NULL, HFILL }},
2791
2792
16
    { &hf_ip_frag_offset,
2793
16
      { "Fragment Offset", "ip.frag_offset", FT_UINT16, BASE_DEC,
2794
16
        NULL, IP_OFFSET, NULL, HFILL }},
2795
2796
16
    { &hf_ip_ttl,
2797
16
      { "Time to Live", "ip.ttl", FT_UINT8, BASE_DEC,
2798
16
        NULL, 0x0, NULL, HFILL }},
2799
2800
16
    { &hf_ip_proto,
2801
16
      { "Protocol", "ip.proto", FT_UINT8, BASE_DEC | BASE_EXT_STRING,
2802
16
        &ipproto_val_ext, 0x0, NULL, HFILL }},
2803
2804
16
    { &hf_ip_checksum,
2805
16
      { "Header Checksum", "ip.checksum", FT_UINT16, BASE_HEX,
2806
16
        NULL, 0x0, NULL, HFILL }},
2807
2808
16
    { &hf_ip_checksum_calculated,
2809
16
    { "Calculated Checksum", "ip.checksum_calculated", FT_UINT16, BASE_HEX, NULL, 0x0,
2810
16
        "The expected IP checksum field as calculated from the IP datagram", HFILL }},
2811
2812
16
    { &hf_ip_checksum_status,
2813
16
      { "Header checksum status", "ip.checksum.status", FT_UINT8, BASE_NONE, VALS(proto_checksum_vals), 0x0,
2814
16
        NULL, HFILL }},
2815
2816
    /* IP options related fields */
2817
16
    { &hf_ip_opt_type,
2818
16
      { "Type", "ip.opt.type", FT_UINT8, BASE_DEC,
2819
16
        NULL, 0x0, NULL, HFILL }},
2820
2821
16
    { &hf_ip_opt_type_copy,
2822
16
      { "Copy on fragmentation", "ip.opt.type.copy", FT_BOOLEAN, 8,
2823
16
        TFS(&tfs_yes_no), IPOPT_COPY_MASK, NULL, HFILL }},
2824
2825
16
    { &hf_ip_opt_type_class,
2826
16
      { "Class", "ip.opt.type.class", FT_UINT8, BASE_DEC,
2827
16
        VALS(ipopt_type_class_vals), IPOPT_CLASS_MASK, NULL, HFILL }},
2828
2829
16
    { &hf_ip_opt_type_number,
2830
16
      { "Number", "ip.opt.type.number", FT_UINT8, BASE_DEC,
2831
16
        VALS(ipopt_type_number_vals), IPOPT_NUMBER_MASK, NULL, HFILL }},
2832
2833
16
    { &hf_ip_opt_len,
2834
16
      { "Length", "ip.opt.len", FT_UINT8, BASE_DEC,
2835
16
        NULL, 0x0, NULL, HFILL }},
2836
2837
16
    { &hf_ip_opt_data,
2838
16
      { "Data", "ip.opt.data", FT_BYTES, BASE_NONE,
2839
16
        NULL, 0x0, NULL, HFILL }},
2840
2841
16
    { &hf_ip_opt_ptr,
2842
16
      { "Pointer", "ip.opt.ptr", FT_UINT8, BASE_DEC,
2843
16
        NULL, 0x0, NULL, HFILL }},
2844
2845
16
    { &hf_ip_opt_sid,
2846
16
      { "Stream Identifier", "ip.opt.sid", FT_UINT16, BASE_DEC,
2847
16
        NULL, 0x0, "SATNET stream identifier", HFILL }},
2848
2849
16
    { &hf_ip_opt_mtu,
2850
16
      { "MTU", "ip.opt.mtu", FT_UINT16, BASE_DEC,
2851
16
        NULL, 0x0, NULL, HFILL }},
2852
2853
16
    { &hf_ip_opt_id_number,
2854
16
      { "ID Number", "ip.opt.id_number", FT_UINT16, BASE_DEC,
2855
16
        NULL, 0x0, NULL, HFILL }},
2856
2857
16
    { &hf_ip_opt_ohc,
2858
16
      { "Outbound Hop Count", "ip.opt.ohc", FT_UINT16, BASE_DEC,
2859
16
        NULL, 0x0, NULL, HFILL }},
2860
2861
16
    { &hf_ip_opt_rhc,
2862
16
      { "Return Hop Count", "ip.opt.rhc", FT_UINT16, BASE_DEC,
2863
16
        NULL, 0x0, NULL, HFILL }},
2864
2865
16
    { &hf_ip_opt_originator,
2866
16
      { "Originator IP Address", "ip.opt.originator", FT_IPv4, BASE_NONE,
2867
16
        NULL, 0x0, NULL, HFILL }},
2868
2869
16
    { &hf_ip_opt_ra,
2870
16
      { "Router Alert", "ip.opt.ra", FT_UINT16, BASE_DEC | BASE_RANGE_STRING,
2871
16
        RVALS(ra_rvals), 0x0, NULL, HFILL }},
2872
2873
16
    { &hf_ip_opt_addr,
2874
16
      { "IP Address", "ip.opt.addr", FT_IPv4, BASE_NONE,
2875
16
        NULL, 0x0, NULL, HFILL }},
2876
2877
16
    { &hf_ip_opt_padding,
2878
16
      { "Padding", "ip.opt.padding", FT_BYTES, BASE_NONE,
2879
16
        NULL, 0x0, NULL, HFILL }},
2880
2881
16
    { &hf_ip_opt_qs_func,
2882
16
      { "Function", "ip.opt.qs_func", FT_UINT8, BASE_DEC,
2883
16
        VALS(qs_func_vals), QS_FUNC_MASK, NULL, HFILL }},
2884
2885
16
    { &hf_ip_opt_qs_rate,
2886
16
      { "Rate", "ip.opt.qs_rate", FT_UINT8, BASE_DEC | BASE_EXT_STRING,
2887
16
        &qs_rate_vals_ext, QS_RATE_MASK, NULL, HFILL }},
2888
2889
16
    { &hf_ip_opt_qs_ttl,
2890
16
      { "QS TTL", "ip.opt.qs_ttl", FT_UINT8, BASE_DEC,
2891
16
        NULL, 0x0, NULL, HFILL }},
2892
2893
16
    { &hf_ip_opt_qs_ttl_diff,
2894
16
      { "TTL Diff", "ip.opt.qs_ttl_diff", FT_UINT8, BASE_DEC,
2895
16
        NULL, 0x0, NULL, HFILL }},
2896
2897
16
    { &hf_ip_opt_qs_unused,
2898
16
      { "Not Used", "ip.opt.qs_unused", FT_UINT8, BASE_DEC,
2899
16
        NULL, 0x0, NULL, HFILL }},
2900
2901
16
    { &hf_ip_opt_qs_nonce,
2902
16
      { "QS Nonce", "ip.opt.qs_nonce", FT_UINT32, BASE_HEX,
2903
16
        NULL, 0xFFFFFFFC, NULL, HFILL }},
2904
2905
16
    { &hf_ip_opt_qs_reserved,
2906
16
      { "Reserved", "ip.opt.qs_reserved", FT_UINT32, BASE_HEX,
2907
16
        NULL, 0x00000003, NULL, HFILL }},
2908
2909
16
    { &hf_ip_opt_sec_rfc791_sec,
2910
16
      { "Security", "ip.opt.sec_rfc791_sec", FT_UINT16, BASE_HEX,
2911
16
        VALS(secl_rfc791_vals), 0x0, NULL, HFILL }},
2912
2913
16
    { &hf_ip_opt_sec_rfc791_comp,
2914
16
      { "Compartments", "ip.opt.sec_rfc791_comp", FT_UINT16, BASE_DEC,
2915
16
        NULL, 0x0, NULL, HFILL }},
2916
2917
16
    { &hf_ip_opt_sec_rfc791_hr,
2918
16
      { "Handling Restrictions", "ip.opt.sec_rfc791_hr", FT_STRING, BASE_NONE,
2919
16
        NULL, 0x0, NULL, HFILL }},
2920
2921
16
    { &hf_ip_opt_sec_rfc791_tcc,
2922
16
      { "Transmission Control Code", "ip.opt.sec_rfc791_tcc", FT_STRING, BASE_NONE,
2923
16
        NULL, 0x0, NULL, HFILL }},
2924
2925
16
    { &hf_ip_opt_sec_cl,
2926
16
      { "Classification Level", "ip.opt.sec_cl", FT_UINT8, BASE_HEX,
2927
16
        VALS(sec_cl_vals), 0x0, NULL, HFILL }},
2928
2929
16
    { &hf_ip_opt_sec_prot_auth_flags,
2930
16
      { "Protection Authority Flags", "ip.opt.sec_prot_auth_flags", FT_UINT8, BASE_HEX,
2931
16
        NULL, 0x0, NULL, HFILL }},
2932
2933
16
    { &hf_ip_opt_sec_prot_auth_genser,
2934
16
      { "GENSER", "ip.opt.sec_prot_auth_genser", FT_BOOLEAN, 8,
2935
16
        TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x80, NULL, HFILL }},
2936
2937
16
    { &hf_ip_opt_sec_prot_auth_siop_esi,
2938
16
      { "SIOP-ESI", "ip.opt.sec_prot_auth_siop_esi", FT_BOOLEAN, 8,
2939
16
        TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x40, NULL, HFILL }},
2940
2941
16
    { &hf_ip_opt_sec_prot_auth_sci,
2942
16
      { "SCI", "ip.opt.sec_prot_auth_sci", FT_BOOLEAN, 8,
2943
16
        TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x20, NULL, HFILL }},
2944
2945
16
    { &hf_ip_opt_sec_prot_auth_nsa,
2946
16
      { "NSA", "ip.opt.sec_prot_auth_nsa", FT_BOOLEAN, 8,
2947
16
        TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x10, NULL, HFILL }},
2948
2949
16
    { &hf_ip_opt_sec_prot_auth_doe,
2950
16
      { "DOE", "ip.opt.sec_prot_auth_doe", FT_BOOLEAN, 8,
2951
16
        TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x08, NULL, HFILL }},
2952
2953
16
    { &hf_ip_opt_sec_prot_auth_unassigned,
2954
16
      { "Unassigned", "ip.opt.sec_prot_auth_unassigned", FT_UINT8, BASE_HEX,
2955
16
        NULL, 0x06, NULL, HFILL }},
2956
2957
16
    { &hf_ip_opt_sec_prot_auth_unassigned2,
2958
16
      { "Unassigned", "ip.opt.sec_prot_auth_unassigned", FT_UINT8, BASE_HEX,
2959
16
        NULL, 0xFE, NULL, HFILL }},
2960
2961
16
    { &hf_ip_opt_sec_prot_auth_fti,
2962
16
      { "Field Termination Indicator", "ip.opt.sec_prot_auth_fti", FT_BOOLEAN, 8,
2963
16
        TFS(&ip_opt_sec_prot_auth_fti_tfs), 0x01, NULL, HFILL }},
2964
2965
16
    { &hf_ip_opt_ext_sec_add_sec_info_format_code,
2966
16
      { "Additional Security Info Format Code", "ip.opt.ext_sec_add_sec_info_format_code", FT_UINT8, BASE_HEX,
2967
16
        NULL, 0x0, NULL, HFILL }},
2968
2969
16
    { &hf_ip_opt_ext_sec_add_sec_info,
2970
16
      { "Additional Security Info", "ip.opt.ext_sec_add_sec_info", FT_BYTES, BASE_NONE,
2971
16
        NULL, 0x0, NULL, HFILL }},
2972
2973
    /* Cilum DSR */
2974
16
    { &hf_ip_opt_dsr_cilium_service_port,
2975
16
      { "Service Port", "ip.opt.dsr.cilium.service_port", FT_UINT16, BASE_DEC,
2976
16
        NULL, 0x0, NULL, HFILL }},
2977
2978
16
    { &hf_ip_opt_dsr_cilium_service_ip,
2979
16
      { "Service IPv4", "ip.opt.dsr.cilium.service_ip", FT_IPv4, BASE_NONE,
2980
16
        NULL, 0x0, NULL, HFILL }},
2981
2982
16
    { &hf_ip_rec_rt,
2983
16
      { "Recorded Route", "ip.rec_rt", FT_IPv4, BASE_NONE, NULL, 0x0,
2984
16
        NULL, HFILL }},
2985
2986
16
    { &hf_ip_rec_rt_host,
2987
16
      { "Recorded Route Host", "ip.rec_rt_host", FT_STRING, BASE_NONE,
2988
16
        NULL, 0x0, NULL, HFILL }},
2989
2990
16
    { &hf_ip_cur_rt,
2991
16
      { "Current Route", "ip.cur_rt", FT_IPv4, BASE_NONE, NULL, 0x0,
2992
16
        NULL, HFILL }},
2993
2994
16
    { &hf_ip_cur_rt_host,
2995
16
      { "Current Route Host", "ip.cur_rt_host", FT_STRING, BASE_NONE,
2996
16
        NULL, 0x0, NULL, HFILL }},
2997
2998
16
    { &hf_ip_src_rt,
2999
16
      { "Source Route", "ip.src_rt", FT_IPv4, BASE_NONE, NULL, 0x0,
3000
16
        NULL, HFILL }},
3001
3002
16
    { &hf_ip_src_rt_host,
3003
16
      { "Source Route Host", "ip.src_rt_host", FT_STRING, BASE_NONE,
3004
16
        NULL, 0x0, NULL, HFILL }},
3005
3006
16
    { &hf_ip_empty_rt,
3007
16
      { "Empty Route", "ip.empty_rt", FT_IPv4, BASE_NONE, NULL, 0x0,
3008
16
        NULL, HFILL }},
3009
3010
16
    { &hf_ip_empty_rt_host,
3011
16
      { "Empty Route Host", "ip.empty_rt_host", FT_STRING, BASE_NONE,
3012
16
        NULL, 0x0, NULL, HFILL }},
3013
3014
16
    { &hf_ip_cipso_tag_type,
3015
16
      { "Tag Type", "ip.cipso.tag_type", FT_UINT8, BASE_DEC,
3016
16
        VALS(cipso_tag_type_vals), 0x0, NULL, HFILL }},
3017
3018
3019
16
    { &hf_ip_fragment_overlap,
3020
16
      { "Fragment overlap", "ip.fragment.overlap", FT_BOOLEAN, BASE_NONE,
3021
16
        NULL, 0x0, "Fragment overlaps with other fragments", HFILL }},
3022
3023
16
    { &hf_ip_fragment_overlap_conflict,
3024
16
      { "Conflicting data in fragment overlap", "ip.fragment.overlap.conflict",
3025
16
        FT_BOOLEAN, BASE_NONE, NULL, 0x0,
3026
16
        "Overlapping fragments contained conflicting data", HFILL }},
3027
3028
16
    { &hf_ip_fragment_multiple_tails,
3029
16
      { "Multiple tail fragments found", "ip.fragment.multipletails",
3030
16
        FT_BOOLEAN, BASE_NONE, NULL, 0x0,
3031
16
        "Several tails were found when defragmenting the packet", HFILL }},
3032
3033
16
    { &hf_ip_fragment_too_long_fragment,
3034
16
      { "Fragment too long", "ip.fragment.toolongfragment",
3035
16
        FT_BOOLEAN, BASE_NONE, NULL, 0x0,
3036
16
        "Fragment contained data past end of packet", HFILL }},
3037
3038
16
    { &hf_ip_fragment_error,
3039
16
      { "Defragmentation error", "ip.fragment.error", FT_FRAMENUM, BASE_NONE,
3040
16
        NULL, 0x0, "Defragmentation error due to illegal fragments", HFILL }},
3041
3042
16
    { &hf_ip_fragment_count,
3043
16
      { "Fragment count", "ip.fragment.count", FT_UINT32, BASE_DEC,
3044
16
        NULL, 0x0, NULL, HFILL }},
3045
3046
16
    { &hf_ip_fragment,
3047
16
      { "IPv4 Fragment", "ip.fragment", FT_FRAMENUM, BASE_NONE,
3048
16
        NULL, 0x0, NULL, HFILL }},
3049
3050
16
    { &hf_ip_fragments,
3051
16
      { "IPv4 Fragments", "ip.fragments", FT_BYTES, BASE_NONE,
3052
16
        NULL, 0x0, NULL, HFILL }},
3053
3054
16
    { &hf_ip_reassembled_in,
3055
16
      { "Reassembled IPv4 in frame", "ip.reassembled_in", FT_FRAMENUM, BASE_NONE,
3056
16
      NULL, 0x0, "This IPv4 packet is reassembled in this frame", HFILL }},
3057
3058
16
    { &hf_ip_reassembled_length,
3059
16
      { "Reassembled IPv4 length", "ip.reassembled.length", FT_UINT32, BASE_DEC,
3060
16
        NULL, 0x0, "The total length of the reassembled payload", HFILL }},
3061
3062
16
    { &hf_ip_reassembled_data,
3063
16
      { "Reassembled IPv4 data", "ip.reassembled.data", FT_BYTES, BASE_NONE,
3064
16
        NULL, 0x0, "The reassembled payload", HFILL }},
3065
3066
      /* Generated from convert_proto_tree_add_text.pl */
3067
16
      { &hf_ip_cipso_doi, { "DOI", "ip.cipso.doi", FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }},
3068
16
      { &hf_ip_cipso_sensitivity_level, { "Sensitivity Level", "ip.cipso.sensitivity_level", FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }},
3069
16
      { &hf_ip_cipso_categories, { "Categories", "ip.cipso.categories", FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }},
3070
16
      { &hf_ip_cipso_tag_data, { "Tag data", "ip.cipso.tag_data", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }},
3071
16
      { &hf_ip_opt_overflow, { "Overflow", "ip.opt.overflow", FT_UINT8, BASE_DEC, NULL, 0xF0, NULL, HFILL }},
3072
16
      { &hf_ip_opt_flag, { "Flag", "ip.opt.flag", FT_UINT8, BASE_HEX, VALS(ipopt_timestamp_flag_vals), 0x0F, NULL, HFILL }},
3073
16
      { &hf_ip_opt_time_stamp, { "Time stamp", "ip.opt.time_stamp", FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }},
3074
16
      { &hf_ip_opt_time_stamp_addr, { "Address", "ip.opt.time_stamp_addr", FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }},
3075
3076
16
};
3077
3078
16
  static int *ett[] = {
3079
16
    &ett_ip,
3080
16
    &ett_ip_dsfield,
3081
16
    &ett_ip_tos,
3082
16
    &ett_ip_flags,
3083
16
    &ett_ip_options,
3084
16
    &ett_ip_option_eool,
3085
16
    &ett_ip_option_nop,
3086
16
    &ett_ip_option_sec,
3087
16
    &ett_ip_option_route,
3088
16
    &ett_ip_option_timestamp,
3089
16
    &ett_ip_option_ext_security,
3090
16
    &ett_ip_option_cipso,
3091
16
    &ett_ip_option_sid,
3092
16
    &ett_ip_option_mtu,
3093
16
    &ett_ip_option_tr,
3094
16
    &ett_ip_option_ra,
3095
16
    &ett_ip_option_sdb,
3096
16
    &ett_ip_option_qs,
3097
16
    &ett_ip_option_dsr,
3098
16
    &ett_ip_option_other,
3099
16
    &ett_ip_fragments,
3100
16
    &ett_ip_fragment,
3101
16
    &ett_ip_opt_type,
3102
16
    &ett_ip_opt_sec_prot_auth_flags,
3103
16
    &ett_ip_unknown_opt,
3104
16
    &ett_geoip_info
3105
16
  };
3106
16
  static ei_register_info ei[] = {
3107
16
     { &ei_ip_opt_len_invalid, { "ip.opt.len.invalid", PI_PROTOCOL, PI_WARN, "Invalid length for option", EXPFILL }},
3108
16
     { &ei_ip_opt_deprecated, { "ip.opt.deprecated", PI_DEPRECATED, PI_NOTE, "Option type is deprecated", EXPFILL }},
3109
16
     { &ei_ip_opt_sec_prot_auth_fti, { "ip.opt.fti_1_last_byte", PI_PROTOCOL, PI_WARN, "Field Termination Indicator set to 1 for last byte of option", EXPFILL }},
3110
16
     { &ei_ip_extraneous_data, { "ip.opt.len.extra_found", PI_PROTOCOL, PI_WARN, "Extraneous data in option", EXPFILL }},
3111
16
     { &ei_ip_opt_ptr_before_address, { "ip.opt.ptr.before_address", PI_PROTOCOL, PI_WARN, "Pointer points before first address", EXPFILL }},
3112
16
     { &ei_ip_opt_ptr_middle_address, { "ip.opt.ptr.middle_address", PI_PROTOCOL, PI_WARN, "Pointer points to middle of address", EXPFILL }},
3113
16
     { &ei_ip_subopt_too_long, { "ip.subopt_too_long", PI_PROTOCOL, PI_WARN, "Suboption would go past end of option", EXPFILL }},
3114
16
     { &ei_ip_nop, { "ip.nop", PI_PROTOCOL, PI_WARN, "4 NOP in a row - a router may have removed some options", EXPFILL }},
3115
16
     { &ei_ip_bogus_ip_length, { "ip.bogus_ip_length", PI_PROTOCOL, PI_ERROR, "Bogus IP length", EXPFILL }},
3116
16
     { &ei_ip_zero_data_length, { "ip.zero_data_length", PI_PROTOCOL, PI_NOTE, "Empty data packet", EXPFILL }},
3117
16
     { &ei_ip_evil_packet, { "ip.evil_packet", PI_PROTOCOL, PI_WARN, "Packet has evil intent", EXPFILL }},
3118
16
     { &ei_ip_checksum_bad, { "ip.checksum_bad.expert", PI_CHECKSUM, PI_ERROR, "Bad checksum", EXPFILL }},
3119
16
     { &ei_ip_ttl_lncb, { "ip.ttl.lncb", PI_SEQUENCE, PI_NOTE, "Time To Live", EXPFILL }},
3120
16
     { &ei_ip_ttl_too_small, { "ip.ttl.too_small", PI_SEQUENCE, PI_NOTE, "Time To Live too small", EXPFILL }},
3121
16
     { &ei_ip_cipso_tag, { "ip.cipso.malformed", PI_SEQUENCE, PI_ERROR, "Malformed CIPSO tag", EXPFILL }},
3122
16
     { &ei_ip_bogus_ip_version, { "ip.bogus_ip_version", PI_PROTOCOL, PI_ERROR, "Bogus IP version", EXPFILL }},
3123
16
     { &ei_ip_bogus_header_length, { "ip.bogus_header_length", PI_PROTOCOL, PI_ERROR, "Bogus IP header length", EXPFILL }},
3124
16
     { &ei_ip_reserved_bit_set, { "ip.flags.rb.set", PI_PROTOCOL, PI_WARN, "Reserved bit is set (must be zero)", EXPFILL }},
3125
16
  };
3126
3127
  /* Decode As handling */
3128
16
  static build_valid_func ip_da_build_value[1] = {ip_value};
3129
16
  static decode_as_value_t ip_da_values = {ip_prompt, 1, ip_da_build_value};
3130
16
  static decode_as_t ip_da = {"ip", "ip.proto", 1, 0, &ip_da_values, NULL, NULL,
3131
16
                              decode_as_default_populate_list, decode_as_default_reset, decode_as_default_change, NULL, NULL, NULL };
3132
3133
16
  module_t *ip_module;
3134
16
  expert_module_t* expert_ip;
3135
3136
16
  proto_ip = proto_register_protocol("Internet Protocol Version 4", "IPv4", "ip");
3137
16
  proto_register_field_array(proto_ip, hf, array_length(hf));
3138
16
  proto_register_subtree_array(ett, array_length(ett));
3139
16
  expert_ip = expert_register_protocol(proto_ip);
3140
16
  expert_register_field_array(expert_ip, ei, array_length(ei));
3141
3142
  /* subdissector code */
3143
16
  ip_dissector_table = register_dissector_table("ip.proto", "IP protocol",
3144
16
                                                proto_ip, FT_UINT8, BASE_DEC);
3145
16
  ip_option_table = register_dissector_table("ip.option", "IP Options",
3146
16
                                                proto_ip, FT_UINT8, BASE_DEC);
3147
16
  heur_subdissector_list = register_heur_dissector_list_with_description("ip", "IPv4 heuristic", proto_ip);
3148
16
  register_capture_dissector_table("ip.proto", "IP protocol");
3149
3150
  /* Register configuration options */
3151
16
  ip_module = prefs_register_protocol(proto_ip, NULL);
3152
16
  prefs_register_bool_preference(ip_module, "decode_tos_as_diffserv",
3153
16
    "Decode IPv4 TOS field as DiffServ field",
3154
16
    "Whether the IPv4 type-of-service field should be decoded as a "
3155
16
    "Differentiated Services field (see RFC2474/RFC2475)", &g_ip_dscp_actif);
3156
16
  prefs_register_bool_preference(ip_module, "defragment",
3157
16
    "Reassemble fragmented IPv4 datagrams",
3158
16
    "Whether fragmented IPv4 datagrams should be reassembled", &ip_defragment);
3159
16
  prefs_register_bool_preference(ip_module, "summary_in_tree",
3160
16
    "Show IPv4 summary in protocol tree",
3161
16
    "Whether the IPv4 summary line should be shown in the protocol tree",
3162
16
    &ip_summary_in_tree);
3163
16
  prefs_register_bool_preference(ip_module, "check_checksum",
3164
16
  "Validate the IPv4 checksum if possible",
3165
16
  "Whether to validate the IPv4 checksum", &ip_check_checksum);
3166
16
  prefs_register_bool_preference(ip_module, "tso_support",
3167
16
    "Support packet-capture from IP TSO-enabled hardware",
3168
16
    "Whether to correct for TSO-enabled (TCP segmentation offload) hardware "
3169
16
    "captures, such as spoofing the IP packet length", &ip_tso_supported);
3170
3171
16
  prefs_register_obsolete_preference(ip_module, "use_geoip");
3172
16
  prefs_register_bool_preference(ip_module, "security_flag" ,
3173
16
    "Interpret Reserved flag as Security flag (RFC 3514)",
3174
16
    "Whether to interpret the originally reserved flag as security flag",
3175
16
    &ip_security_flag);
3176
16
  prefs_register_bool_preference(ip_module, "try_heuristic_first",
3177
16
    "Try heuristic sub-dissectors first",
3178
16
    "Try to decode a packet using an heuristic sub-dissector before using a sub-dissector registered to a specific port",
3179
16
    &try_heuristic_first);
3180
3181
16
  prefs_register_bool_preference(ip_module, "conv_id",
3182
16
    "Assign IPv4 conversation IDs",
3183
16
    "Whether to assign unique numbers to each IPv4 conversation (increases resource consumption)",
3184
16
    &ip_track_conv_id);
3185
3186
16
  prefs_register_bool_preference(ip_module, "conv_agg_flag" ,
3187
16
    "Aggregate subnets in Statistics Dialogs",
3188
16
    "Whether to group conversations based on the subnets file; requires \"Assign IPv4 conversation IDs\"",
3189
16
    &ip_conv_agg_flag);
3190
3191
16
  prefs_register_static_text_preference(ip_module, "text_use_geoip",
3192
16
    "IP geolocation settings can be changed in the Name Resolution preferences",
3193
16
    "IP geolocation settings can be changed in the Name Resolution preferences");
3194
3195
16
  register_init_routine(ip_init);
3196
3197
16
  ip_handle = register_dissector("ip", dissect_ip, proto_ip);
3198
16
  ipv4_handle = register_dissector("ipv4", dissect_ip_v4, proto_ip);
3199
16
  reassembly_table_register(&ip_reassembly_table,
3200
16
                        &addresses_reassembly_table_functions);
3201
16
  ip_tap = register_tap("ip");
3202
3203
  /* This needs a different (& more user-friendly) name than the other tap */
3204
16
  exported_pdu_tap = register_export_pdu_tap_with_encap("IP", WTAP_ENCAP_RAW_IP);
3205
3206
16
  register_decode_as(&ip_da);
3207
16
  register_conversation_table(proto_ip, true, ip_conversation_packet, ip_endpoint_packet);
3208
16
  register_conversation_filter("ip", "IPv4", ip_filter_valid, ip_build_filter, NULL);
3209
3210
16
  ip_cap_handle = register_capture_dissector("ip", capture_ip, proto_ip);
3211
3212
  /* Register IP options as their own protocols so we can get the name of the option */
3213
16
  proto_ip_option_eol = proto_register_protocol_in_name_only("IP Option - End of Options List (EOL)", "End of Options List (EOL)", "ip.options.eol", proto_ip, FT_BYTES);
3214
16
  proto_ip_option_nop = proto_register_protocol_in_name_only("IP Option - No-Operation (NOP)", "No Operation (NOP)", "ip.options.nop", proto_ip, FT_BYTES);
3215
16
  proto_ip_option_security = proto_register_protocol_in_name_only("IP Option - Security", "Security", "ip.options.security", proto_ip, FT_BYTES);
3216
16
  proto_ip_option_route = proto_register_protocol_in_name_only("IP Option - Loose Source Route", "Loose Source Route", "ip.options.route", proto_ip, FT_BYTES);
3217
16
  proto_ip_option_timestamp = proto_register_protocol_in_name_only("IP Option - Time Stamp", "Time Stamp", "ip.options.timestamp", proto_ip, FT_BYTES);
3218
16
  proto_ip_option_ext_security = proto_register_protocol_in_name_only("IP Option - Extended Security", "Extended Security", "ip.options.ext_security", proto_ip, FT_BYTES);
3219
16
  proto_ip_option_cipso = proto_register_protocol_in_name_only("IP Option - Commercial Security", "Commercial Security", "ip.options.cipso", proto_ip, FT_BYTES);
3220
16
  proto_ip_option_record_route = proto_register_protocol_in_name_only("IP Option - Record Route", "Record Route", "ip.options.record_route", proto_ip, FT_BYTES);
3221
16
  proto_ip_option_sid = proto_register_protocol_in_name_only("IP Option - Stream ID", "Stream ID", "ip.options.sid", proto_ip, FT_BYTES);
3222
16
  proto_ip_option_source_route = proto_register_protocol_in_name_only("IP Option - Strict Source Route", "Strict Source Route", "ip.options.source_route", proto_ip, FT_BYTES);
3223
16
  proto_ip_option_mtu_probe = proto_register_protocol_in_name_only("IP Option - MTU Probe", "MTU Probe", "ip.options.mtu_probe", proto_ip, FT_BYTES);
3224
16
  proto_ip_option_mtu_reply = proto_register_protocol_in_name_only("IP Option - MTU Reply", "MTU Reply", "ip.options.mtu_reply", proto_ip, FT_BYTES);
3225
16
  proto_ip_option_traceroute = proto_register_protocol_in_name_only("IP Option - Traceroute", "Traceroute", "ip.options.traceroute", proto_ip, FT_BYTES);
3226
16
  proto_ip_option_routeralert = proto_register_protocol_in_name_only("IP Option - Router Alert", "Router Alert", "ip.options.routeralert", proto_ip, FT_BYTES);
3227
16
  proto_ip_option_sdb = proto_register_protocol_in_name_only("IP Option - Selective Directed Broadcast", "Selective Directed Broadcast", "ip.options.sdb", proto_ip, FT_BYTES);
3228
16
  proto_ip_option_qs = proto_register_protocol_in_name_only("IP Option - Quick-Start", "Quick-Start", "ip.options.qs", proto_ip, FT_BYTES);
3229
16
  proto_ip_option_dsr = proto_register_protocol_in_name_only("IP Option - Cilium DSR", "Cilium DSR", "ip.options.dsr", proto_ip, FT_BYTES);
3230
16
}
3231
3232
void
3233
proto_reg_handoff_ip(void)
3234
16
{
3235
16
  capture_dissector_handle_t clip_cap_handle;
3236
16
  int proto_clip;
3237
3238
16
  ipv6_handle = find_dissector("ipv6");
3239
3240
16
  dissector_add_uint("ethertype", ETHERTYPE_IP, ipv4_handle);
3241
16
  dissector_add_uint("erf.types.type", ERF_TYPE_IPV4, ip_handle);
3242
16
  dissector_add_uint("ppp.protocol", PPP_IP, ip_handle);
3243
16
  dissector_add_uint("ppp.protocol", ETHERTYPE_IP, ip_handle);
3244
16
  dissector_add_uint("gre.proto", ETHERTYPE_IP, ip_handle);
3245
16
  dissector_add_uint("gre.proto", GRE_WCCP, ip_handle);
3246
16
  dissector_add_uint("llc.dsap", SAP_IP, ip_handle);
3247
16
  dissector_add_uint("ip.proto", IP_PROTO_IPV4, ip_handle);
3248
16
  dissector_add_uint("null.type", BSD_AF_INET, ip_handle);
3249
16
  dissector_add_uint("chdlc.protocol", ETHERTYPE_IP, ip_handle);
3250
16
  dissector_add_uint("osinl.excl", NLPID_IP, ip_handle);
3251
16
  dissector_add_uint("fr.nlpid", NLPID_IP, ip_handle);
3252
16
  dissector_add_uint("x.25.spi", NLPID_IP, ip_handle);
3253
16
  dissector_add_uint("arcnet.protocol_id", ARCNET_PROTO_IP_1051, ip_handle);
3254
16
  dissector_add_uint("arcnet.protocol_id", ARCNET_PROTO_IP_1201, ip_handle);
3255
16
  dissector_add_uint("ax25.pid", AX25_P_IP, ip_handle);
3256
16
  dissector_add_uint("juniper.proto", JUNIPER_PROTO_IP, ip_handle);
3257
16
  dissector_add_uint("juniper.proto", JUNIPER_PROTO_MPLS_IP, ip_handle);
3258
16
  dissector_add_uint("pwach.channel_type", PW_ACH_TYPE_IPV4, ip_handle);
3259
16
  dissector_add_uint("mcc.proto", PW_ACH_TYPE_IPV4, ip_handle);
3260
16
  dissector_add_uint("sflow_245.header_protocol", SFLOW_245_HEADER_IPv4, ip_handle);
3261
16
  dissector_add_uint("l2tp.pw_type", L2TPv3_PW_IP, ip_handle);
3262
16
  dissector_add_for_decode_as_with_preference("udp.port", ip_handle);
3263
16
  dissector_add_for_decode_as("pcli.payload", ip_handle);
3264
16
  dissector_add_uint("enc", BSD_AF_INET, ip_handle);
3265
16
  dissector_add_uint("vxlan.next_proto", VXLAN_IPV4, ip_handle);
3266
16
  dissector_add_uint("nsh.next_proto", NSH_IPV4, ip_handle);
3267
3268
16
  heur_dissector_add("tipc", dissect_ip_heur, "IP over TIPC", "ip_tipc", proto_ip, HEURISTIC_ENABLE);
3269
16
  heur_dissector_add("zbee_zcl_se.tun", dissect_ip_heur, "IP over ZigBee SE Tunneling", "ip_zbee_zcl_se.tun", proto_ip, HEURISTIC_ENABLE);
3270
16
  heur_dissector_add("gtp.tpdu", dissect_ip_heur, "IP over GTP", "ip_gtp.tpdu", proto_ip, HEURISTIC_ENABLE);
3271
3272
16
  capture_dissector_add_uint("ethertype", ETHERTYPE_IP, ip_cap_handle);
3273
16
  capture_dissector_add_uint("ax25.pid", AX25_P_IP, ip_cap_handle);
3274
16
  capture_dissector_add_uint("enc", BSD_AF_INET, ip_cap_handle);
3275
16
  capture_dissector_add_uint("ppp_hdlc", PPP_IP, ip_cap_handle);
3276
16
  capture_dissector_add_uint("llc.dsap", SAP_IP, ip_cap_handle);
3277
16
  capture_dissector_add_uint("null.bsd", BSD_AF_INET, ip_cap_handle);
3278
16
  capture_dissector_add_uint("fr.nlpid", NLPID_IP, ip_cap_handle);
3279
3280
  /* Create dissection function handles for all IP options */
3281
16
  dissector_add_uint("ip.option", IPOPT_SEC, create_dissector_handle( dissect_ipopt_security, proto_ip_option_security ));
3282
16
  dissector_add_uint("ip.option", IPOPT_LSR, create_dissector_handle( dissect_ipopt_loose_route, proto_ip_option_route ));
3283
16
  dissector_add_uint("ip.option", IPOPT_TS, create_dissector_handle( dissect_ipopt_timestamp, proto_ip_option_timestamp ));
3284
16
  dissector_add_uint("ip.option", IPOPT_ESEC, create_dissector_handle( dissect_ipopt_ext_security, proto_ip_option_ext_security ));
3285
16
  dissector_add_uint("ip.option", IPOPT_CIPSO, create_dissector_handle( dissect_ipopt_cipso, proto_ip_option_cipso ));
3286
16
  dissector_add_uint("ip.option", IPOPT_RR, create_dissector_handle( dissect_ipopt_record_route, proto_ip_option_record_route ));
3287
16
  dissector_add_uint("ip.option", IPOPT_SID, create_dissector_handle( dissect_ipopt_sid, proto_ip_option_sid ));
3288
16
  dissector_add_uint("ip.option", IPOPT_SSR, create_dissector_handle( dissect_ipopt_source_route, proto_ip_option_source_route ));
3289
16
  dissector_add_uint("ip.option", IPOPT_MTUP, create_dissector_handle( dissect_ipopt_mtu_probe, proto_ip_option_mtu_probe ));
3290
16
  dissector_add_uint("ip.option", IPOPT_MTUR, create_dissector_handle( dissect_ipopt_mtu_reply, proto_ip_option_mtu_reply ));
3291
16
  dissector_add_uint("ip.option", IPOPT_TR, create_dissector_handle( dissect_ipopt_tr, proto_ip_option_traceroute ));
3292
16
  dissector_add_uint("ip.option", IPOPT_RTRALT, create_dissector_handle( dissect_ipopt_ra, proto_ip_option_routeralert ));
3293
16
  dissector_add_uint("ip.option", IPOPT_SDB, create_dissector_handle( dissect_ipopt_sdb, proto_ip_option_sdb ));
3294
16
  dissector_add_uint("ip.option", IPOPT_QS, create_dissector_handle( dissect_ipopt_qs, proto_ip_option_qs ));
3295
16
  dissector_add_uint("ip.option", IPOPT_DSR, create_dissector_handle( dissect_ipopt_cilium_dsr, proto_ip_option_dsr ));
3296
3297
  /* Classic IP uses the same capture function, but wants its own
3298
     protocol associated with it.  To eliminate linking dependencies,
3299
     just add it here */
3300
16
  proto_clip = proto_get_id_by_filter_name( "clip" );
3301
16
  clip_cap_handle = register_capture_dissector("clip", capture_ip, proto_clip);
3302
16
  capture_dissector_add_uint("wtap_encap", WTAP_ENCAP_LINUX_ATM_CLIP, clip_cap_handle);
3303
16
}
3304
3305
/*
3306
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
3307
 *
3308
 * Local variables:
3309
 * c-basic-offset: 2
3310
 * tab-width: 8
3311
 * indent-tabs-mode: nil
3312
 * End:
3313
 *
3314
 * vi: set shiftwidth=2 tabstop=8 expandtab:
3315
 * :indentSize=2:tabSize=8:noTabs=true:
3316
 */