/src/wireshark/epan/dissectors/packet-ip.c
Line | Count | Source |
1 | | /* packet-ip.c |
2 | | * Routines for IP and miscellaneous IP protocol packet disassembly |
3 | | * |
4 | | * Wireshark - Network traffic analyzer |
5 | | * By Gerald Combs <gerald@wireshark.org> |
6 | | * Copyright 1998 Gerald Combs |
7 | | * |
8 | | * Wednesday, January 17, 2006 |
9 | | * Support for the CIPSO IPv4 option |
10 | | * (http://sourceforge.net/docman/display_doc.php?docid=34650&group_id=174379) |
11 | | * by Paul Moore <paul.moore@hp.com> |
12 | | * |
13 | | * SPDX-License-Identifier: GPL-2.0-or-later |
14 | | */ |
15 | | |
16 | | #include "config.h" |
17 | | |
18 | | #include <epan/packet.h> |
19 | | #include <epan/capture_dissectors.h> |
20 | | #include <epan/addr_resolv.h> |
21 | | #include <epan/maxmind_db.h> |
22 | | #include <epan/expert.h> |
23 | | #include <epan/ip_opts.h> |
24 | | #include <epan/prefs.h> |
25 | | #include <epan/conversation_table.h> |
26 | | #include <epan/conversation_filter.h> |
27 | | #include <epan/reassemble.h> |
28 | | #include <epan/etypes.h> |
29 | | #include <epan/aftypes.h> |
30 | | #include <epan/in_cksum.h> |
31 | | #include <epan/decode_as.h> |
32 | | #include <epan/proto_data.h> |
33 | | #include <epan/exported_pdu.h> |
34 | | #include <epan/tfs.h> |
35 | | #include <epan/iana-info.h> |
36 | | #include <wsutil/array.h> |
37 | | #include <wiretap/erf_record.h> |
38 | | #include <wsutil/str_util.h> |
39 | | |
40 | | #include "packet-ip.h" |
41 | | #include "packet-juniper.h" |
42 | | #include "packet-sflow.h" |
43 | | #include "packet-gre.h" |
44 | | #include "packet-l2tp.h" |
45 | | #include "packet-vxlan.h" |
46 | | #include "packet-mpls.h" |
47 | | #include "packet-nsh.h" |
48 | | #include "packet-eth.h" |
49 | | #include "packet-osi.h" |
50 | | #include "packet-ppp.h" |
51 | | #include "packet-llc.h" |
52 | | #include "packet-arcnet.h" |
53 | | #include "packet-ax25.h" |
54 | | |
55 | | |
56 | | void proto_register_ip(void); |
57 | | void proto_reg_handoff_ip(void); |
58 | | |
59 | | static int ip_tap; |
60 | | |
61 | | static int exported_pdu_tap; |
62 | | |
63 | | /* Decode the old IPv4 TOS field as the DiffServ DS Field (RFC2474/2475) */ |
64 | | static bool g_ip_dscp_actif = true; |
65 | | |
66 | | /* Defragment fragmented IP datagrams */ |
67 | | static bool ip_defragment = true; |
68 | | |
69 | | /* Place IP summary in proto tree */ |
70 | | static bool ip_summary_in_tree = true; |
71 | | |
72 | | /* Perform IP checksum */ |
73 | | static bool ip_check_checksum; |
74 | | |
75 | | /* Assume TSO and correct zero-length IP packets */ |
76 | | static bool ip_tso_supported = true; |
77 | | |
78 | | /* Use heuristics to determine subdissector */ |
79 | | static bool try_heuristic_first; |
80 | | |
81 | | /* Interpret the reserved flag as security flag (RFC 3514) */ |
82 | | static bool ip_security_flag; |
83 | | |
84 | | /* Assign unique stream numbers to each IP conversation. This increases |
85 | | * resource use (CPU and memory) because of having to lookup and create |
86 | | * conversations. |
87 | | */ |
88 | | static bool ip_track_conv_id = true; |
89 | | |
90 | | /* Aggregate subnets in Statistics Endpoints/Conversations Dialogs |
91 | | * defaults to false to not impact resources |
92 | | */ |
93 | | static bool ip_conv_agg_flag = false; |
94 | | |
95 | | static int proto_ip; |
96 | | |
97 | | static int proto_ip_option_eol; |
98 | | static int proto_ip_option_nop; |
99 | | static int proto_ip_option_security; |
100 | | static int proto_ip_option_route; |
101 | | static int proto_ip_option_timestamp; |
102 | | static int proto_ip_option_ext_security; |
103 | | static int proto_ip_option_cipso; |
104 | | static int proto_ip_option_record_route; |
105 | | static int proto_ip_option_sid; |
106 | | static int proto_ip_option_source_route; |
107 | | static int proto_ip_option_mtu_probe; |
108 | | static int proto_ip_option_mtu_reply; |
109 | | static int proto_ip_option_traceroute; |
110 | | static int proto_ip_option_routeralert; |
111 | | static int proto_ip_option_sdb; |
112 | | static int proto_ip_option_qs; |
113 | | static int proto_ip_option_dsr; |
114 | | static int hf_ip_version; |
115 | | static int hf_ip_hdr_len; |
116 | | static int hf_ip_dsfield; |
117 | | static int hf_ip_dsfield_dscp; |
118 | | static int hf_ip_dsfield_ecn; |
119 | | static int hf_ip_tos; |
120 | | static int hf_ip_tos_precedence; |
121 | | static int hf_ip_tos_delay; |
122 | | static int hf_ip_tos_throughput; |
123 | | static int hf_ip_tos_reliability; |
124 | | static int hf_ip_tos_cost; |
125 | | static int hf_ip_len; |
126 | | static int hf_ip_id; |
127 | | static int hf_ip_dst; |
128 | | static int hf_ip_dst_host; |
129 | | static int hf_ip_src; |
130 | | static int hf_ip_src_host; |
131 | | static int hf_ip_addr; |
132 | | static int hf_ip_host; |
133 | | static int hf_ip_flags; |
134 | | static int hf_ip_flags_sf; |
135 | | static int hf_ip_flags_rf; |
136 | | static int hf_ip_flags_df; |
137 | | static int hf_ip_flags_mf; |
138 | | static int hf_ip_frag_offset; |
139 | | static int hf_ip_ttl; |
140 | | static int hf_ip_proto; |
141 | | static int hf_ip_checksum; |
142 | | static int hf_ip_checksum_calculated; |
143 | | static int hf_ip_checksum_status; |
144 | | static int hf_ip_stream; |
145 | | |
146 | | /* IP option fields */ |
147 | | static int hf_ip_opt_type; |
148 | | static int hf_ip_opt_type_copy; |
149 | | static int hf_ip_opt_type_class; |
150 | | static int hf_ip_opt_type_number; |
151 | | static int hf_ip_opt_len; |
152 | | static int hf_ip_opt_data; |
153 | | static int hf_ip_opt_ptr; |
154 | | static int hf_ip_opt_sid; |
155 | | static int hf_ip_opt_mtu; |
156 | | static int hf_ip_opt_id_number; |
157 | | static int hf_ip_opt_ohc; |
158 | | static int hf_ip_opt_rhc; |
159 | | static int hf_ip_opt_originator; |
160 | | static int hf_ip_opt_ra; |
161 | | static int hf_ip_opt_addr; |
162 | | static int hf_ip_opt_padding; |
163 | | static int hf_ip_opt_qs_func; |
164 | | static int hf_ip_opt_qs_rate; |
165 | | static int hf_ip_opt_qs_ttl; |
166 | | static int hf_ip_opt_qs_ttl_diff; |
167 | | static int hf_ip_opt_qs_unused; |
168 | | static int hf_ip_opt_qs_nonce; |
169 | | static int hf_ip_opt_qs_reserved; |
170 | | static int hf_ip_opt_sec_rfc791_sec; |
171 | | static int hf_ip_opt_sec_rfc791_comp; |
172 | | static int hf_ip_opt_sec_rfc791_hr; |
173 | | static int hf_ip_opt_sec_rfc791_tcc; |
174 | | static int hf_ip_opt_sec_cl; |
175 | | static int hf_ip_opt_sec_prot_auth_flags; |
176 | | static int hf_ip_opt_sec_prot_auth_genser; |
177 | | static int hf_ip_opt_sec_prot_auth_siop_esi; |
178 | | static int hf_ip_opt_sec_prot_auth_sci; |
179 | | static int hf_ip_opt_sec_prot_auth_nsa; |
180 | | static int hf_ip_opt_sec_prot_auth_doe; |
181 | | static int hf_ip_opt_sec_prot_auth_unassigned; |
182 | | static int hf_ip_opt_sec_prot_auth_unassigned2; |
183 | | static int hf_ip_opt_sec_prot_auth_fti; |
184 | | static int hf_ip_opt_ext_sec_add_sec_info_format_code; |
185 | | static int hf_ip_opt_ext_sec_add_sec_info; |
186 | | static int hf_ip_opt_dsr_cilium_service_port; |
187 | | static int hf_ip_opt_dsr_cilium_service_ip; |
188 | | static int hf_ip_rec_rt; |
189 | | static int hf_ip_rec_rt_host; |
190 | | static int hf_ip_cur_rt; |
191 | | static int hf_ip_cur_rt_host; |
192 | | static int hf_ip_src_rt; |
193 | | static int hf_ip_src_rt_host; |
194 | | static int hf_ip_empty_rt; |
195 | | static int hf_ip_empty_rt_host; |
196 | | static int hf_ip_cipso_tag_type; |
197 | | |
198 | | static int hf_ip_fragments; |
199 | | static int hf_ip_fragment; |
200 | | static int hf_ip_fragment_overlap; |
201 | | static int hf_ip_fragment_overlap_conflict; |
202 | | static int hf_ip_fragment_multiple_tails; |
203 | | static int hf_ip_fragment_too_long_fragment; |
204 | | static int hf_ip_fragment_error; |
205 | | static int hf_ip_fragment_count; |
206 | | static int hf_ip_reassembled_in; |
207 | | static int hf_ip_reassembled_length; |
208 | | static int hf_ip_reassembled_data; |
209 | | |
210 | | /* Generated from convert_proto_tree_add_text.pl */ |
211 | | static int hf_ip_opt_flag; |
212 | | static int hf_ip_opt_overflow; |
213 | | static int hf_ip_cipso_tag_data; |
214 | | static int hf_ip_cipso_sensitivity_level; |
215 | | static int hf_ip_cipso_categories; |
216 | | static int hf_ip_cipso_doi; |
217 | | static int hf_ip_opt_time_stamp; |
218 | | static int hf_ip_opt_time_stamp_addr; |
219 | | |
220 | | static int hf_geoip_country; |
221 | | static int hf_geoip_country_iso; |
222 | | static int hf_geoip_city; |
223 | | static int hf_geoip_as_number; |
224 | | static int hf_geoip_as_org; |
225 | | static int hf_geoip_latitude; |
226 | | static int hf_geoip_longitude; |
227 | | static int hf_geoip_src_summary; |
228 | | static int hf_geoip_src_country; |
229 | | static int hf_geoip_src_country_iso; |
230 | | static int hf_geoip_src_city; |
231 | | static int hf_geoip_src_as_number; |
232 | | static int hf_geoip_src_as_org; |
233 | | static int hf_geoip_src_latitude; |
234 | | static int hf_geoip_src_longitude; |
235 | | static int hf_geoip_dst_summary; |
236 | | static int hf_geoip_dst_country; |
237 | | static int hf_geoip_dst_country_iso; |
238 | | static int hf_geoip_dst_city; |
239 | | static int hf_geoip_dst_as_number; |
240 | | static int hf_geoip_dst_as_org; |
241 | | static int hf_geoip_dst_latitude; |
242 | | static int hf_geoip_dst_longitude; |
243 | | |
244 | | static int ett_ip; |
245 | | static int ett_ip_dsfield; |
246 | | static int ett_ip_tos; |
247 | | static int ett_ip_flags; |
248 | | static int ett_ip_options; |
249 | | static int ett_ip_option_eool; |
250 | | static int ett_ip_option_nop; |
251 | | static int ett_ip_option_sec; |
252 | | static int ett_ip_option_route; |
253 | | static int ett_ip_option_timestamp; |
254 | | static int ett_ip_option_ext_security; |
255 | | static int ett_ip_option_cipso; |
256 | | static int ett_ip_option_sid; |
257 | | static int ett_ip_option_mtu; |
258 | | static int ett_ip_option_tr; |
259 | | static int ett_ip_option_ra; |
260 | | static int ett_ip_option_sdb; |
261 | | static int ett_ip_option_qs; |
262 | | static int ett_ip_option_dsr; |
263 | | static int ett_ip_option_other; |
264 | | static int ett_ip_fragments; |
265 | | static int ett_ip_fragment; |
266 | | static int ett_ip_opt_type; |
267 | | static int ett_ip_opt_sec_prot_auth_flags; |
268 | | static int ett_ip_unknown_opt; |
269 | | |
270 | | static expert_field ei_ip_opt_len_invalid; |
271 | | static expert_field ei_ip_opt_deprecated; |
272 | | static expert_field ei_ip_opt_sec_prot_auth_fti; |
273 | | static expert_field ei_ip_extraneous_data; |
274 | | static expert_field ei_ip_opt_ptr_before_address; |
275 | | static expert_field ei_ip_opt_ptr_middle_address; |
276 | | static expert_field ei_ip_subopt_too_long; |
277 | | static expert_field ei_ip_nop; |
278 | | static expert_field ei_ip_bogus_ip_length; |
279 | | static expert_field ei_ip_zero_data_length; |
280 | | static expert_field ei_ip_evil_packet; |
281 | | static expert_field ei_ip_checksum_bad; |
282 | | static expert_field ei_ip_ttl_lncb; |
283 | | static expert_field ei_ip_ttl_too_small; |
284 | | static expert_field ei_ip_cipso_tag; |
285 | | static expert_field ei_ip_bogus_ip_version; |
286 | | static expert_field ei_ip_bogus_header_length; |
287 | | static expert_field ei_ip_reserved_bit_set; |
288 | | |
289 | | static dissector_handle_t ip_handle; |
290 | | static dissector_handle_t ipv4_handle; |
291 | | static dissector_table_t ip_option_table; |
292 | | |
293 | | static int ett_geoip_info; |
294 | | |
295 | | static uint32_t ip_stream_count; |
296 | | |
297 | | static const fragment_items ip_frag_items = { |
298 | | &ett_ip_fragment, |
299 | | &ett_ip_fragments, |
300 | | &hf_ip_fragments, |
301 | | &hf_ip_fragment, |
302 | | &hf_ip_fragment_overlap, |
303 | | &hf_ip_fragment_overlap_conflict, |
304 | | &hf_ip_fragment_multiple_tails, |
305 | | &hf_ip_fragment_too_long_fragment, |
306 | | &hf_ip_fragment_error, |
307 | | &hf_ip_fragment_count, |
308 | | &hf_ip_reassembled_in, |
309 | | &hf_ip_reassembled_length, |
310 | | &hf_ip_reassembled_data, |
311 | | "IPv4 fragments" |
312 | | }; |
313 | | |
314 | | static heur_dissector_list_t heur_subdissector_list; |
315 | | |
316 | | static dissector_table_t ip_dissector_table; |
317 | | |
318 | | static dissector_handle_t ipv6_handle; |
319 | | static capture_dissector_handle_t ip_cap_handle; |
320 | | |
321 | | |
322 | | /* IP structs and definitions */ |
323 | | |
324 | | const value_string ip_version_vals[] = { |
325 | | { IP_VERSION_NUM_RESERVED, "Reserved" }, |
326 | | { IP_VERSION_NUM_INET, "IPv4" }, |
327 | | { IP_VERSION_NUM_ST, "ST Datagram" }, |
328 | | { IP_VERSION_NUM_INET6, "IPv6" }, |
329 | | { IP_VERSION_NUM_TPIX, "TP/IX" }, |
330 | | { IP_VERSION_NUM_PIP, "PIP" }, |
331 | | { IP_VERSION_NUM_TUBA, "TUBA" }, |
332 | | { 0, NULL }, |
333 | | }; |
334 | | |
335 | | /* Offsets of fields within an IP header. */ |
336 | | #define IPH_V_HL 0 |
337 | | #define IPH_TOS 1 |
338 | | #define IPH_LEN 2 |
339 | | #define IPH_ID 4 |
340 | | #define IPH_TTL 6 |
341 | | #define IPH_OFF 8 |
342 | | #define IPH_P 9 |
343 | | #define IPH_SUM 10 |
344 | 131k | #define IPH_SRC 12 |
345 | 131k | #define IPH_DST 16 |
346 | | |
347 | | /* Minimum IP header length. */ |
348 | 308k | #define IPH_MIN_LEN 20 |
349 | | |
350 | | /* IP flags. */ |
351 | 65.6k | #define IP_RF 0x8000 /* Flag: "Reserved bit" */ |
352 | | #define IP_DF 0x4000 /* Flag: "Don't Fragment" */ |
353 | 65.2k | #define IP_MF 0x2000 /* Flag: "More Fragments" */ |
354 | 131k | #define IP_OFFSET 0x1FFF /* "Fragment Offset" part */ |
355 | | |
356 | | /* Differentiated Services Field. See RFCs 2474, 2597, 2598 and 3168. */ |
357 | | #define IPDSFIELD_DSCP_DEFAULT 0x00 |
358 | | #define IPDSFIELD_DSCP_LE 0x01 |
359 | | #define IPDSFIELD_DSCP_CS1 0x08 |
360 | | #define IPDSFIELD_DSCP_AF11 0x0A |
361 | | #define IPDSFIELD_DSCP_AF12 0x0C |
362 | | #define IPDSFIELD_DSCP_AF13 0x0E |
363 | | #define IPDSFIELD_DSCP_CS2 0x10 |
364 | | #define IPDSFIELD_DSCP_AF21 0x12 |
365 | | #define IPDSFIELD_DSCP_AF22 0x14 |
366 | | #define IPDSFIELD_DSCP_AF23 0x16 |
367 | | #define IPDSFIELD_DSCP_CS3 0x18 |
368 | | #define IPDSFIELD_DSCP_AF31 0x1A |
369 | | #define IPDSFIELD_DSCP_AF32 0x1C |
370 | | #define IPDSFIELD_DSCP_AF33 0x1E |
371 | | #define IPDSFIELD_DSCP_CS4 0x20 |
372 | | #define IPDSFIELD_DSCP_AF41 0x22 |
373 | | #define IPDSFIELD_DSCP_AF42 0x24 |
374 | | #define IPDSFIELD_DSCP_AF43 0x26 |
375 | | #define IPDSFIELD_DSCP_CS5 0x28 |
376 | | #define IPDSFIELD_VOICE_ADMIT 0x2C |
377 | | #define IPDSFIELD_DSCP_EF 0x2E |
378 | | #define IPDSFIELD_DSCP_CS6 0x30 |
379 | | #define IPDSFIELD_DSCP_CS7 0x38 |
380 | | |
381 | | #define IPDSFIELD_ECT_NOT 0x00 |
382 | | #define IPDSFIELD_ECT_1 0x01 |
383 | | #define IPDSFIELD_ECT_0 0x02 |
384 | | #define IPDSFIELD_CE 0x03 |
385 | | |
386 | | /* IP TOS, superseded by the DS Field, RFC 2474. */ |
387 | 0 | #define IPTOS_TOS_MASK 0x1E |
388 | 0 | #define IPTOS_TOS(tos) ((tos) & IPTOS_TOS_MASK) |
389 | | #define IPTOS_NONE 0x00 |
390 | 16 | #define IPTOS_LOWCOST 0x02 |
391 | 16 | #define IPTOS_RELIABILITY 0x04 |
392 | 16 | #define IPTOS_THROUGHPUT 0x08 |
393 | 16 | #define IPTOS_LOWDELAY 0x10 |
394 | | #define IPTOS_SECURITY 0x1E |
395 | | |
396 | 16 | #define IPTOS_PREC_MASK 0xE0 |
397 | | #define IPTOS_PREC_SHIFT 5 |
398 | | #define IPTOS_PREC(tos) (((tos)&IPTOS_PREC_MASK)>>IPTOS_PREC_SHIFT) |
399 | | #define IPTOS_PREC_NETCONTROL 7 |
400 | | #define IPTOS_PREC_INTERNETCONTROL 6 |
401 | | #define IPTOS_PREC_CRITIC_ECP 5 |
402 | | #define IPTOS_PREC_FLASHOVERRIDE 4 |
403 | | #define IPTOS_PREC_FLASH 3 |
404 | | #define IPTOS_PREC_IMMEDIATE 2 |
405 | | #define IPTOS_PREC_PRIORITY 1 |
406 | | #define IPTOS_PREC_ROUTINE 0 |
407 | | |
408 | | /* IP options */ |
409 | 8.40k | #define IPOPT_COPY 0x80 |
410 | | |
411 | 279k | #define IPOPT_CONTROL 0x00 |
412 | | #define IPOPT_RESERVED1 0x20 |
413 | 32 | #define IPOPT_MEASUREMENT 0x40 |
414 | | #define IPOPT_RESERVED2 0x60 |
415 | | |
416 | | /* REF: http://www.iana.org/assignments/ip-parameters */ |
417 | | /* TODO: Not all of these are implemented, especially those |
418 | | * deprecated by RFC 6814. */ |
419 | 174k | #define IPOPT_EOOL (0 |IPOPT_CONTROL) |
420 | 96.9k | #define IPOPT_NOP (1 |IPOPT_CONTROL) |
421 | 16 | #define IPOPT_SEC (2 |IPOPT_COPY|IPOPT_CONTROL) /* RFC 791/1108 */ |
422 | 4.13k | #define IPOPT_LSR (3 |IPOPT_COPY|IPOPT_CONTROL) |
423 | 16 | #define IPOPT_TS (4 |IPOPT_MEASUREMENT) |
424 | 16 | #define IPOPT_ESEC (5 |IPOPT_COPY|IPOPT_CONTROL) /* RFC 1108 */ |
425 | 16 | #define IPOPT_CIPSO (6 |IPOPT_COPY|IPOPT_CONTROL) /* draft-ietf-cipso-ipsecurity-01 */ |
426 | 16 | #define IPOPT_RR (7 |IPOPT_CONTROL) |
427 | 16 | #define IPOPT_SID (8 |IPOPT_COPY|IPOPT_CONTROL) /* Deprecated */ |
428 | 8.29k | #define IPOPT_SSR (9 |IPOPT_COPY|IPOPT_CONTROL) |
429 | | #define IPOPT_ZSU (10|IPOPT_CONTROL) /* Zsu */ |
430 | 16 | #define IPOPT_MTUP (11|IPOPT_CONTROL) /* RFC 1063 */ |
431 | 16 | #define IPOPT_MTUR (12|IPOPT_CONTROL) /* RFC 1063 */ |
432 | | #define IPOPT_FINN (13|IPOPT_COPY|IPOPT_MEASUREMENT) /* Finn */ |
433 | | #define IPOPT_VISA (14|IPOPT_COPY|IPOPT_CONTROL) /* Estrin; Deprecated */ |
434 | | #define IPOPT_ENCODE (15|IPOPT_CONTROL) /* VerSteeg; Deprecated */ |
435 | | #define IPOPT_IMITD (16|IPOPT_COPY|IPOPT_CONTROL) /* Lee */ |
436 | | #define IPOPT_EIP (17|IPOPT_COPY|IPOPT_CONTROL) /* RFC 1385; Deprecated */ |
437 | 16 | #define IPOPT_TR (18|IPOPT_MEASUREMENT) /* RFC 1393; Deprecated */ |
438 | | #define IPOPT_ADDEXT (19|IPOPT_COPY|IPOPT_CONTROL) /* Ullmann IPv7; Deprecated */ |
439 | 16 | #define IPOPT_RTRALT (20|IPOPT_COPY|IPOPT_CONTROL) /* RFC 2113 */ |
440 | 16 | #define IPOPT_SDB (21|IPOPT_COPY|IPOPT_CONTROL) /* RFC 1770 Graff; Deprecated */ |
441 | | #define IPOPT_UN (22|IPOPT_COPY|IPOPT_CONTROL) /* Released 18-Oct-2005 */ |
442 | | #define IPOPT_DPS (23|IPOPT_COPY|IPOPT_CONTROL) /* Malis; Deprecated */ |
443 | | #define IPOPT_UMP (24|IPOPT_COPY|IPOPT_CONTROL) /* Farinacci; Deprecated */ |
444 | 16 | #define IPOPT_QS (25|IPOPT_CONTROL) /* RFC 4782 */ |
445 | 16 | #define IPOPT_DSR (26|IPOPT_COPY) /* From Cilium for DSR https://github.com/cilium/cilium/blob/9acb306ce3003304c73394e2f9fe133253934213/bpf/lib/common.h#L612 */ |
446 | | #define IPOPT_EXP (30|IPOPT_CONTROL) /* RFC 4727 */ |
447 | | |
448 | | |
449 | | /* IP option lengths */ |
450 | | #define IPOLEN_SEC_MIN 3 |
451 | 29 | #define IPOLEN_LSR_MIN 3 |
452 | | #define IPOLEN_TS_MIN 4 |
453 | | #define IPOLEN_ESEC_MIN 3 |
454 | | #define IPOLEN_CIPSO_MIN 10 |
455 | 272 | #define IPOLEN_RR_MIN 3 |
456 | 1 | #define IPOLEN_SID 4 |
457 | 4 | #define IPOLEN_SSR_MIN 3 |
458 | 30 | #define IPOLEN_MTU 4 |
459 | 1 | #define IPOLEN_TR 12 |
460 | 2 | #define IPOLEN_RA 4 |
461 | | #define IPOLEN_SDB_MIN 6 |
462 | 5 | #define IPOLEN_QS 8 |
463 | 1 | #define IPOLEN_DSR 8 |
464 | 190 | #define IPOLEN_MAX 40 |
465 | | |
466 | | #define IPSEC_RFC791_UNCLASSIFIED 0x0000 |
467 | | #define IPSEC_RFC791_CONFIDENTIAL 0xF135 |
468 | | #define IPSEC_RFC791_EFTO 0x789A |
469 | | #define IPSEC_RFC791_MMMM 0xBC4D |
470 | | #define IPSEC_RFC791_PROG 0x5E26 |
471 | | #define IPSEC_RFC791_RESTRICTED 0xAF13 |
472 | | #define IPSEC_RFC791_SECRET 0xD788 |
473 | | #define IPSEC_RFC791_TOPSECRET 0x6BC5 |
474 | | #define IPSEC_RFC791_RESERVED1 0x35E2 |
475 | | #define IPSEC_RFC791_RESERVED2 0x9AF1 |
476 | | #define IPSEC_RFC791_RESERVED3 0x4D78 |
477 | | #define IPSEC_RFC791_RESERVED4 0x24BD |
478 | | #define IPSEC_RFC791_RESERVED5 0x135E |
479 | | #define IPSEC_RFC791_RESERVED6 0x89AF |
480 | | #define IPSEC_RFC791_RESERVED7 0xC4D6 |
481 | | #define IPSEC_RFC791_RESERVED8 0xE26B |
482 | | |
483 | | #define IPSEC_RESERVED4 0x01 |
484 | | #define IPSEC_TOPSECRET 0x3D |
485 | | #define IPSEC_SECRET 0x5A |
486 | | #define IPSEC_CONFIDENTIAL 0x96 |
487 | | #define IPSEC_RESERVED3 0x66 |
488 | | #define IPSEC_RESERVED2 0xCC |
489 | | #define IPSEC_UNCLASSIFIED 0xAB |
490 | | #define IPSEC_RESERVED1 0xF1 |
491 | | |
492 | | #define IPOPT_TS_TSONLY 0 /* timestamps only */ |
493 | 52 | #define IPOPT_TS_TSANDADDR 1 /* timestamps and addresses */ |
494 | 25 | #define IPOPT_TS_PRESPEC 3 /* specified modules only */ |
495 | | |
496 | 7 | #define IPLOCAL_NETWRK_CTRL_BLK_VRRP_ADDR 0xE0000012 |
497 | 0 | #define IPLOCAL_NETWRK_CTRL_BLK_VRRP_TTL 0xFF |
498 | 7 | #define IPLOCAL_NETWRK_CTRL_BLK_GLPB_ADDR 0xE0000066 |
499 | 1 | #define IPLOCAL_NETWRK_CTRL_BLK_GLPB_TTL 0XFF |
500 | 6 | #define IPLOCAL_NETWRK_CTRL_BLK_MDNS_ADDR 0xE00000FB |
501 | 0 | #define IPLOCAL_NETWRK_CTRL_BLK_MDNS_TTL 0XFF |
502 | 6 | #define IPLOCAL_NETWRK_CTRL_BLK_LLMNR_ADDR 0xE00000FC |
503 | | |
504 | 6 | #define IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL 0x1000 /* larger than max ttl */ |
505 | 7 | #define IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL 0X01 |
506 | | |
507 | | static void ip_prompt(packet_info *pinfo, char* result) |
508 | 0 | { |
509 | 0 | ws_ip4* iph = (ws_ip4*)p_get_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num); |
510 | 0 | snprintf(result, MAX_DECODE_AS_PROMPT_LEN, "IP protocol %u as", iph->ip_proto); |
511 | 0 | } |
512 | | |
513 | | static void *ip_value(packet_info *pinfo) |
514 | 0 | { |
515 | 0 | ws_ip4* iph = (ws_ip4*)p_get_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num); |
516 | 0 | return GUINT_TO_POINTER(iph->ip_proto); |
517 | 0 | } |
518 | | |
519 | | static const char* ip_conv_get_filter_type(conv_item_t* conv, conv_filter_type_e filter) |
520 | 0 | { |
521 | | /* addr type is AT_STRINGZ for subnets, as it is a very flexible format |
522 | | * XXX - create a new type when required, at this moment it's only used in |
523 | | * conversation tables and is not justified. See #19481. |
524 | | */ |
525 | 0 | if ((filter == CONV_FT_SRC_ADDRESS) && ((conv->src_address.type == AT_IPv4) || |
526 | 0 | (conv->src_address.type == AT_STRINGZ))) |
527 | 0 | return "ip.src"; |
528 | | |
529 | 0 | if ((filter == CONV_FT_DST_ADDRESS) && ((conv->dst_address.type == AT_IPv4) || |
530 | 0 | (conv->dst_address.type == AT_STRINGZ))) |
531 | 0 | return "ip.dst"; |
532 | | |
533 | 0 | if ((filter == CONV_FT_ANY_ADDRESS) && ((conv->src_address.type == AT_IPv4) || |
534 | 0 | (conv->src_address.type == AT_STRINGZ))) |
535 | 0 | return "ip.addr"; |
536 | | |
537 | 0 | return CONV_FILTER_INVALID; |
538 | 0 | } |
539 | | |
540 | | static ct_dissector_info_t ip_ct_dissector_info = {&ip_conv_get_filter_type}; |
541 | | |
542 | | static tap_packet_status |
543 | | ip_conversation_packet(void *pct, packet_info *pinfo, epan_dissect_t *edt _U_, const void *vip, tap_flags_t flags) |
544 | 0 | { |
545 | 0 | conv_hash_t *hash = (conv_hash_t*) pct; |
546 | 0 | hash->flags = flags; |
547 | 0 | const ws_ip4 *iph=(const ws_ip4 *)vip; |
548 | | |
549 | | /* Try aggregating into subnets if asked so, |
550 | | * if no subnets are found it will still end in calling xxx_with_conv_id() |
551 | | */ |
552 | 0 | if (!ip_track_conv_id) { |
553 | 0 | add_conversation_table_data(hash, &iph->ip_src, &iph->ip_dst, 0, 0, 1, pinfo->fd->pkt_len, |
554 | 0 | &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP); |
555 | 0 | } else if(ip_conv_agg_flag) { |
556 | 0 | add_conversation_table_data_ipv4_subnet(hash, &iph->ip_src, &iph->ip_dst, 0, 0, (conv_id_t)iph->ip_stream, 1, pinfo->fd->pkt_len, |
557 | 0 | &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP); |
558 | 0 | } else { |
559 | 0 | add_conversation_table_data_with_conv_id(hash, &iph->ip_src, &iph->ip_dst, 0, 0, (conv_id_t)iph->ip_stream, 1, pinfo->fd->pkt_len, |
560 | 0 | &pinfo->rel_ts, &pinfo->abs_ts, &ip_ct_dissector_info, CONVERSATION_IP); |
561 | 0 | } |
562 | |
|
563 | 0 | return TAP_PACKET_REDRAW; |
564 | 0 | } |
565 | | |
566 | | static const char* ip_endpoint_get_filter_type(endpoint_item_t* endpoint, conv_filter_type_e filter) |
567 | 0 | { |
568 | | /* subnets: handled similarly to ip_conv_get_filter_type() */ |
569 | 0 | if ((filter == CONV_FT_ANY_ADDRESS) && ((endpoint->myaddress.type == AT_IPv4) || |
570 | 0 | (endpoint->myaddress.type == AT_STRINGZ))) |
571 | 0 | return "ip.addr"; |
572 | | |
573 | 0 | return CONV_FILTER_INVALID; |
574 | 0 | } |
575 | | |
576 | | static et_dissector_info_t ip_endpoint_dissector_info = {&ip_endpoint_get_filter_type}; |
577 | | |
578 | | static tap_packet_status |
579 | | ip_endpoint_packet(void *pit, packet_info *pinfo, epan_dissect_t *edt _U_, const void *vip, tap_flags_t flags) |
580 | 0 | { |
581 | 0 | conv_hash_t *hash = (conv_hash_t*) pit; |
582 | 0 | hash->flags = flags; |
583 | 0 | const ws_ip4 *iph=(const ws_ip4 *)vip; |
584 | | |
585 | | /* Take two "add" passes per packet, adding for each direction, ensures that all |
586 | | packets are counted properly (even if address is sending to itself) |
587 | | XXX - this could probably be done more efficiently inside endpoint_table */ |
588 | 0 | if(ip_conv_agg_flag) { |
589 | 0 | add_endpoint_table_data_ipv4_subnet(hash, &iph->ip_src, 0, true, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE); |
590 | 0 | add_endpoint_table_data_ipv4_subnet(hash, &iph->ip_dst, 0, false, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE); |
591 | 0 | } |
592 | 0 | else { |
593 | 0 | add_endpoint_table_data(hash, &iph->ip_src, 0, true, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE); |
594 | 0 | add_endpoint_table_data(hash, &iph->ip_dst, 0, false, 1, pinfo->fd->pkt_len, &ip_endpoint_dissector_info, ENDPOINT_NONE); |
595 | 0 | } |
596 | 0 | return TAP_PACKET_REDRAW; |
597 | 0 | } |
598 | | |
599 | | static bool |
600 | | ip_filter_valid(packet_info *pinfo, void *user_data _U_) |
601 | 0 | { |
602 | 0 | return proto_is_frame_protocol(pinfo->layers, "ip"); |
603 | 0 | } |
604 | | |
605 | | static char* |
606 | | ip_build_filter(packet_info *pinfo, void *user_data _U_) |
607 | 0 | { |
608 | 0 | return ws_strdup_printf("ip.addr eq %s and ip.addr eq %s", |
609 | 0 | address_to_str(pinfo->pool, &pinfo->net_src), |
610 | 0 | address_to_str(pinfo->pool, &pinfo->net_dst)); |
611 | 0 | } |
612 | | |
613 | | /* |
614 | | * defragmentation of IPv4 |
615 | | */ |
616 | | static reassembly_table ip_reassembly_table; |
617 | | |
618 | | static bool |
619 | 0 | capture_ip(const unsigned char *pd, int offset, int len, capture_packet_info_t *cpinfo, const union wtap_pseudo_header *pseudo_header _U_) { |
620 | 0 | if (!BYTES_ARE_IN_FRAME(offset, len, IPH_MIN_LEN)) |
621 | 0 | return false; |
622 | | |
623 | 0 | capture_dissector_increment_count(cpinfo, proto_ip); |
624 | 0 | return try_capture_dissector("ip.proto", pd[offset + 9], pd, offset+IPH_MIN_LEN, len, cpinfo, pseudo_header); |
625 | 0 | } |
626 | | |
627 | | static void |
628 | | add_geoip_info_entry(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, ws_in4_addr ip, bool isdst) |
629 | 110k | { |
630 | 110k | const mmdb_lookup_t *lookup = maxmind_db_lookup_ipv4(&ip); |
631 | 110k | if (!lookup->found) return; |
632 | | |
633 | 0 | wmem_strbuf_t *summary = wmem_strbuf_new(pinfo->pool, ""); |
634 | 0 | if (lookup->city) { |
635 | 0 | wmem_strbuf_append(summary, lookup->city); |
636 | 0 | } |
637 | 0 | if (lookup->country_iso) { |
638 | 0 | if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", "); |
639 | 0 | wmem_strbuf_append(summary, lookup->country_iso); |
640 | 0 | } else if (lookup->country) { |
641 | 0 | if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", "); |
642 | 0 | wmem_strbuf_append(summary, lookup->country); |
643 | 0 | } |
644 | 0 | if (lookup->as_number > 0) { |
645 | 0 | if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", "); |
646 | 0 | wmem_strbuf_append_printf(summary, "ASN %u", lookup->as_number); |
647 | 0 | } |
648 | 0 | if (lookup->as_org) { |
649 | 0 | if (wmem_strbuf_get_len(summary) > 0) wmem_strbuf_append(summary, ", "); |
650 | 0 | wmem_strbuf_append(summary, lookup->as_org); |
651 | 0 | } |
652 | |
|
653 | 0 | int addr_offset = offset + (isdst ? IPH_DST : IPH_SRC); |
654 | 0 | int dir_hf = isdst ? hf_geoip_dst_summary : hf_geoip_src_summary; |
655 | 0 | proto_item *geoip_info_item = proto_tree_add_string(tree, dir_hf, tvb, addr_offset, 4, wmem_strbuf_finalize(summary)); |
656 | 0 | proto_item_set_generated(geoip_info_item); |
657 | 0 | proto_tree *geoip_info_tree = proto_item_add_subtree(geoip_info_item, ett_geoip_info); |
658 | |
|
659 | 0 | proto_item *item; |
660 | |
|
661 | 0 | if (lookup->city) { |
662 | 0 | dir_hf = isdst ? hf_geoip_dst_city : hf_geoip_src_city; |
663 | 0 | item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->city); |
664 | 0 | proto_item_set_generated(item); |
665 | 0 | item = proto_tree_add_string(geoip_info_tree, hf_geoip_city, tvb, addr_offset, 4, lookup->city); |
666 | 0 | proto_item_set_generated(item); |
667 | 0 | } |
668 | |
|
669 | 0 | if (lookup->country) { |
670 | 0 | dir_hf = isdst ? hf_geoip_dst_country : hf_geoip_src_country; |
671 | 0 | item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->country); |
672 | 0 | proto_item_set_generated(item); |
673 | 0 | item = proto_tree_add_string(geoip_info_tree, hf_geoip_country, tvb, addr_offset, 4, lookup->country); |
674 | 0 | proto_item_set_generated(item); |
675 | 0 | } |
676 | |
|
677 | 0 | if (lookup->country_iso) { |
678 | 0 | dir_hf = isdst ? hf_geoip_dst_country_iso : hf_geoip_src_country_iso; |
679 | 0 | item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->country_iso); |
680 | 0 | proto_item_set_generated(item); |
681 | 0 | item = proto_tree_add_string(geoip_info_tree, hf_geoip_country_iso, tvb, addr_offset, 4, lookup->country_iso); |
682 | 0 | proto_item_set_generated(item); |
683 | 0 | } |
684 | |
|
685 | 0 | if (lookup->as_number > 0) { |
686 | 0 | dir_hf = isdst ? hf_geoip_dst_as_number : hf_geoip_src_as_number; |
687 | 0 | item = proto_tree_add_uint(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->as_number); |
688 | 0 | proto_item_set_generated(item); |
689 | 0 | item = proto_tree_add_uint(geoip_info_tree, hf_geoip_as_number, tvb, addr_offset, 4, lookup->as_number); |
690 | 0 | proto_item_set_generated(item); |
691 | 0 | } |
692 | |
|
693 | 0 | if (lookup->as_org) { |
694 | 0 | dir_hf = isdst ? hf_geoip_dst_as_org : hf_geoip_src_as_org; |
695 | 0 | item = proto_tree_add_string(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->as_org); |
696 | 0 | proto_item_set_generated(item); |
697 | 0 | item = proto_tree_add_string(geoip_info_tree, hf_geoip_as_org, tvb, addr_offset, 4, lookup->as_org); |
698 | 0 | proto_item_set_generated(item); |
699 | 0 | } |
700 | |
|
701 | 0 | if (lookup->latitude >= -90.0 && lookup->latitude <= 90.0) { |
702 | 0 | dir_hf = isdst ? hf_geoip_dst_latitude : hf_geoip_src_latitude; |
703 | 0 | item = proto_tree_add_double(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->latitude); |
704 | 0 | proto_item_set_generated(item); |
705 | 0 | item = proto_tree_add_double(geoip_info_tree, hf_geoip_latitude, tvb, addr_offset, 4, lookup->latitude); |
706 | 0 | proto_item_set_generated(item); |
707 | 0 | } |
708 | |
|
709 | 0 | if (lookup->longitude >= -180.0 && lookup->longitude <= 180.0) { |
710 | 0 | dir_hf = isdst ? hf_geoip_dst_longitude : hf_geoip_src_longitude; |
711 | 0 | item = proto_tree_add_double(geoip_info_tree, dir_hf, tvb, addr_offset, 4, lookup->longitude); |
712 | 0 | proto_item_set_generated(item); |
713 | 0 | item = proto_tree_add_double(geoip_info_tree, hf_geoip_longitude, tvb, addr_offset, 4, lookup->longitude); |
714 | 0 | proto_item_set_generated(item); |
715 | 0 | } |
716 | 0 | } |
717 | | |
718 | | static void |
719 | | add_geoip_info(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, uint32_t src32, |
720 | | uint32_t dst32) |
721 | 55.1k | { |
722 | 55.1k | add_geoip_info_entry(tree, pinfo, tvb, offset, g_htonl(src32), false); |
723 | 55.1k | add_geoip_info_entry(tree, pinfo, tvb, offset, g_htonl(dst32), true); |
724 | 55.1k | } |
725 | | |
726 | | const value_string ipopt_type_class_vals[] = { |
727 | | {(IPOPT_CONTROL & IPOPT_CLASS_MASK) >> 5, "Control"}, |
728 | | {(IPOPT_RESERVED1 & IPOPT_CLASS_MASK) >> 5, "Reserved for future use"}, |
729 | | {(IPOPT_MEASUREMENT & IPOPT_CLASS_MASK) >> 5, "Debugging and measurement"}, |
730 | | {(IPOPT_RESERVED2 & IPOPT_CLASS_MASK) >> 5, "Reserved for future use"}, |
731 | | {0, NULL} |
732 | | }; |
733 | | |
734 | | const value_string ipopt_type_number_vals[] = { |
735 | | {IPOPT_EOOL & IPOPT_NUMBER_MASK, "End of Option List (EOL)"}, |
736 | | {IPOPT_NOP & IPOPT_NUMBER_MASK, "No-Operation (NOP)"}, |
737 | | {IPOPT_SEC & IPOPT_NUMBER_MASK, "Security"}, |
738 | | {IPOPT_LSR & IPOPT_NUMBER_MASK, "Loose source route"}, |
739 | | {IPOPT_TS & IPOPT_NUMBER_MASK, "Time stamp"}, |
740 | | {IPOPT_ESEC & IPOPT_NUMBER_MASK, "Extended security"}, |
741 | | {IPOPT_CIPSO & IPOPT_NUMBER_MASK, "Commercial IP security option"}, |
742 | | {IPOPT_RR & IPOPT_NUMBER_MASK, "Record route"}, |
743 | | {IPOPT_SID & IPOPT_NUMBER_MASK, "Stream identifier"}, |
744 | | {IPOPT_SSR & IPOPT_NUMBER_MASK, "Strict source route"}, |
745 | | {IPOPT_ZSU & IPOPT_NUMBER_MASK, "Experimental Measurement"}, |
746 | | {IPOPT_MTUP & IPOPT_NUMBER_MASK, "MTU probe"}, |
747 | | {IPOPT_MTUR & IPOPT_NUMBER_MASK, "MTU Reply"}, |
748 | | {IPOPT_FINN & IPOPT_NUMBER_MASK, "Experimental Flow Control"}, |
749 | | {IPOPT_VISA & IPOPT_NUMBER_MASK, "Experimental Access Control"}, |
750 | | {IPOPT_ENCODE & IPOPT_NUMBER_MASK, "Ask Estrin"}, |
751 | | {IPOPT_IMITD & IPOPT_NUMBER_MASK, "IMI Traffic Descriptor"}, |
752 | | {IPOPT_EIP & IPOPT_NUMBER_MASK, "Extended Internet Protocol"}, |
753 | | {IPOPT_TR & IPOPT_NUMBER_MASK, "Traceroute"}, |
754 | | {IPOPT_ADDEXT & IPOPT_NUMBER_MASK, "Address Extension"}, |
755 | | {IPOPT_RTRALT & IPOPT_NUMBER_MASK, "Router Alert"}, |
756 | | {IPOPT_SDB & IPOPT_NUMBER_MASK, "Selective Directed Broadcast"}, |
757 | | {IPOPT_UN & IPOPT_NUMBER_MASK, "Unassigned"}, |
758 | | {IPOPT_DPS & IPOPT_NUMBER_MASK, "Dynamic Packet State"}, |
759 | | {IPOPT_UMP & IPOPT_NUMBER_MASK, "Upstream Multicast Packet"}, |
760 | | {IPOPT_QS & IPOPT_NUMBER_MASK, "Quick-Start"}, |
761 | | {IPOPT_DSR & IPOPT_NUMBER_MASK, "Cilium DSR"}, |
762 | | {IPOPT_EXP & IPOPT_NUMBER_MASK, "RFC 3692-style experiment"}, |
763 | | {0, NULL} |
764 | | }; |
765 | | |
766 | | static void |
767 | | dissect_ipopt_type(tvbuff_t *tvb, int offset, proto_tree *tree) |
768 | 18.7k | { |
769 | 18.7k | proto_tree *type_tree; |
770 | 18.7k | proto_item *ti; |
771 | | |
772 | 18.7k | ti = proto_tree_add_item(tree, hf_ip_opt_type, tvb, offset, 1, ENC_NA); |
773 | 18.7k | type_tree = proto_item_add_subtree(ti, ett_ip_opt_type); |
774 | 18.7k | proto_tree_add_item(type_tree, hf_ip_opt_type_copy, tvb, offset, 1, ENC_NA); |
775 | 18.7k | proto_tree_add_item(type_tree, hf_ip_opt_type_class, tvb, offset, 1, ENC_NA); |
776 | 18.7k | proto_tree_add_item(type_tree, hf_ip_opt_type_number, tvb, offset, 1, ENC_NA); |
777 | 18.7k | } |
778 | | |
779 | | static proto_tree* |
780 | | ip_fixed_option_header(proto_tree* tree, packet_info *pinfo, tvbuff_t *tvb, int proto, int ett, proto_item** ti, unsigned len, unsigned optlen) |
781 | 40 | { |
782 | 40 | proto_tree *field_tree; |
783 | 40 | proto_item *tf; |
784 | | |
785 | 40 | *ti = proto_tree_add_item(tree, proto, tvb, 0, optlen, ENC_NA); |
786 | 40 | field_tree = proto_item_add_subtree(*ti, ett); |
787 | 40 | proto_item_append_text(*ti, " (%u bytes)", len); |
788 | | |
789 | 40 | dissect_ipopt_type(tvb, 0, field_tree); |
790 | 40 | tf = proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, 1, 1, ENC_NA); |
791 | | |
792 | 40 | if (len != optlen) { |
793 | | /* Bogus - option length isn't what it's supposed to be for this option. */ |
794 | 37 | expert_add_info_format(pinfo, tf, &ei_ip_opt_len_invalid, |
795 | 37 | "%s (with option length = %u byte%s; should be %u)", |
796 | 37 | proto_get_protocol_short_name(find_protocol_by_id(proto)), |
797 | 37 | optlen, plurality(optlen, "", "s"), len); |
798 | 37 | } |
799 | | |
800 | 40 | return field_tree; |
801 | 40 | } |
802 | | |
803 | | static proto_tree* |
804 | | ip_var_option_header(proto_tree* tree, packet_info *pinfo, tvbuff_t *tvb, int proto, int ett, proto_item** ti, unsigned optlen) |
805 | 190 | { |
806 | 190 | proto_tree *field_tree; |
807 | 190 | proto_item *tf; |
808 | | |
809 | 190 | *ti = proto_tree_add_item(tree, proto, tvb, 0, optlen, ENC_NA); |
810 | 190 | field_tree = proto_item_add_subtree(*ti, ett); |
811 | 190 | proto_item_append_text(*ti, " (%u bytes)", optlen); |
812 | | |
813 | 190 | dissect_ipopt_type(tvb, 0, field_tree); |
814 | 190 | tf = proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, 1, 1, ENC_NA); |
815 | 190 | if (optlen > IPOLEN_MAX) |
816 | 0 | expert_add_info(pinfo, tf, &ei_ip_opt_len_invalid); |
817 | | |
818 | 190 | return field_tree; |
819 | 190 | } |
820 | | |
821 | | static const value_string secl_rfc791_vals[] = { |
822 | | {IPSEC_RFC791_UNCLASSIFIED, "Unclassified"}, |
823 | | {IPSEC_RFC791_CONFIDENTIAL, "Confidential"}, |
824 | | {IPSEC_RFC791_EFTO, "EFTO" }, |
825 | | {IPSEC_RFC791_MMMM, "MMMM" }, |
826 | | {IPSEC_RFC791_PROG, "PROG" }, |
827 | | {IPSEC_RFC791_RESTRICTED, "Restricted" }, |
828 | | {IPSEC_RFC791_SECRET, "Secret" }, |
829 | | {IPSEC_RFC791_TOPSECRET, "Top secret" }, |
830 | | {IPSEC_RFC791_RESERVED1, "Reserved" }, |
831 | | {IPSEC_RFC791_RESERVED2, "Reserved" }, |
832 | | {IPSEC_RFC791_RESERVED3, "Reserved" }, |
833 | | {IPSEC_RFC791_RESERVED4, "Reserved" }, |
834 | | {IPSEC_RFC791_RESERVED5, "Reserved" }, |
835 | | {IPSEC_RFC791_RESERVED6, "Reserved" }, |
836 | | {IPSEC_RFC791_RESERVED7, "Reserved" }, |
837 | | {IPSEC_RFC791_RESERVED8, "Reserved" }, |
838 | | {0, NULL } |
839 | | }; |
840 | | |
841 | | static const value_string sec_cl_vals[] = { |
842 | | {IPSEC_RESERVED4, "Reserved 4" }, |
843 | | {IPSEC_TOPSECRET, "Top secret" }, |
844 | | {IPSEC_SECRET, "Secret" }, |
845 | | {IPSEC_CONFIDENTIAL, "Confidential"}, |
846 | | {IPSEC_RESERVED3, "Reserved 3" }, |
847 | | {IPSEC_RESERVED2, "Reserved 2" }, |
848 | | {IPSEC_UNCLASSIFIED, "Unclassified"}, |
849 | | {IPSEC_RESERVED1, "Reserved 1" }, |
850 | | {0, NULL } |
851 | | }; |
852 | | |
853 | | static const true_false_string ip_opt_sec_prot_auth_flag_tfs = { |
854 | | "Datagram protected in accordance with its rules", |
855 | | "Datagram not protected in accordance with its rules" |
856 | | }; |
857 | | |
858 | | static const true_false_string ip_opt_sec_prot_auth_fti_tfs = { |
859 | | "Additional octet present", |
860 | | "Final octet" |
861 | | }; |
862 | | |
863 | | static int * const ip_opt_sec_prot_auth_fields_byte_1[] = { |
864 | | &hf_ip_opt_sec_prot_auth_genser, |
865 | | &hf_ip_opt_sec_prot_auth_siop_esi, |
866 | | &hf_ip_opt_sec_prot_auth_sci, |
867 | | &hf_ip_opt_sec_prot_auth_nsa, |
868 | | &hf_ip_opt_sec_prot_auth_doe, |
869 | | &hf_ip_opt_sec_prot_auth_unassigned, |
870 | | &hf_ip_opt_sec_prot_auth_fti, |
871 | | NULL |
872 | | }; |
873 | | |
874 | | static int * const ip_opt_sec_prot_auth_fields_byte_n[] = { |
875 | | &hf_ip_opt_sec_prot_auth_unassigned2, |
876 | | &hf_ip_opt_sec_prot_auth_fti, |
877 | | NULL |
878 | | }; |
879 | | static int |
880 | | dissect_ipopt_security(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
881 | 19 | { |
882 | 19 | proto_tree *field_tree; |
883 | 19 | proto_item *tf; |
884 | 19 | unsigned val; |
885 | 19 | unsigned curr_offset = 2; |
886 | 19 | unsigned optlen = tvb_reported_length(tvb); |
887 | | |
888 | 19 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_security, ett_ip_option_sec, &tf, optlen); |
889 | | |
890 | 19 | if (optlen == 11) { |
891 | | /* Analyze payload start to decide whether it should be dissected |
892 | | according to RFC 791 or RFC 1108 */ |
893 | 0 | val = tvb_get_ntohs(tvb, curr_offset); |
894 | 0 | if (try_val_to_str(val, secl_rfc791_vals)) { |
895 | | /* Dissect as RFC 791 */ |
896 | 0 | proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_sec, |
897 | 0 | tvb, curr_offset, 2, ENC_BIG_ENDIAN); |
898 | 0 | curr_offset += 2; |
899 | 0 | proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_comp, |
900 | 0 | tvb, curr_offset, 2, ENC_BIG_ENDIAN); |
901 | 0 | curr_offset += 2; |
902 | 0 | proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_hr, |
903 | 0 | tvb, curr_offset, 2, ENC_ASCII); |
904 | 0 | curr_offset += 2; |
905 | 0 | proto_tree_add_item(field_tree, hf_ip_opt_sec_rfc791_tcc, |
906 | 0 | tvb, curr_offset, 3, ENC_ASCII); |
907 | 0 | return curr_offset; |
908 | 0 | } |
909 | 0 | } |
910 | | |
911 | | /* Dissect as RFC 108 */ |
912 | 19 | proto_tree_add_item(field_tree, hf_ip_opt_sec_cl, tvb, curr_offset, 1, ENC_BIG_ENDIAN); |
913 | 19 | curr_offset++; |
914 | 19 | if (curr_offset >= optlen) { |
915 | 7 | return curr_offset; |
916 | 7 | } |
917 | 12 | val = tvb_get_uint8(tvb, curr_offset); |
918 | 12 | proto_tree_add_bitmask(field_tree, tvb, curr_offset, hf_ip_opt_sec_prot_auth_flags, |
919 | 12 | ett_ip_opt_sec_prot_auth_flags, ip_opt_sec_prot_auth_fields_byte_1, |
920 | 12 | ENC_BIG_ENDIAN); |
921 | 12 | curr_offset++; |
922 | 27 | while (val & 0x01) { |
923 | 17 | if (curr_offset == optlen) { |
924 | 2 | expert_add_info(pinfo, tf, &ei_ip_opt_sec_prot_auth_fti); |
925 | 2 | break; |
926 | 2 | } |
927 | 15 | val = tvb_get_uint8(tvb, curr_offset); |
928 | 15 | proto_tree_add_bitmask(field_tree, tvb, curr_offset, hf_ip_opt_sec_prot_auth_flags, |
929 | 15 | ett_ip_opt_sec_prot_auth_flags, ip_opt_sec_prot_auth_fields_byte_n, |
930 | 15 | ENC_BIG_ENDIAN); |
931 | 15 | curr_offset++; |
932 | 15 | } |
933 | 12 | if (curr_offset < optlen) { |
934 | 3 | expert_add_info(pinfo, tf, &ei_ip_extraneous_data); |
935 | 3 | } |
936 | | |
937 | 12 | return curr_offset; |
938 | 19 | } |
939 | | |
940 | | static int |
941 | | dissect_ipopt_ext_security(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
942 | 4 | { |
943 | 4 | proto_tree *field_tree; |
944 | 4 | proto_item *tf; |
945 | 4 | unsigned curr_offset = 2; |
946 | 4 | int remaining; |
947 | 4 | int optlen = tvb_reported_length(tvb); |
948 | | |
949 | 4 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_ext_security, ett_ip_option_ext_security, &tf, optlen); |
950 | | |
951 | 4 | proto_tree_add_item(field_tree, hf_ip_opt_ext_sec_add_sec_info_format_code, tvb, curr_offset, 1, ENC_BIG_ENDIAN); |
952 | 4 | curr_offset++; |
953 | 4 | remaining = optlen - curr_offset; |
954 | 4 | if (remaining > 0) { |
955 | 4 | proto_tree_add_item(field_tree, hf_ip_opt_ext_sec_add_sec_info, tvb, curr_offset, remaining, ENC_NA); |
956 | 4 | } |
957 | | |
958 | 4 | return tvb_captured_length(tvb); |
959 | 4 | } |
960 | | |
961 | | /* USHRT_MAX can hold at most 5 (base 10) digits (6 for the NULL byte) */ |
962 | | #define USHRT_MAX_STRLEN 6 |
963 | | |
964 | | /* Maximum CIPSO tag length: |
965 | | * (IP hdr max)60 - (IPv4 hdr std)20 - (CIPSO base)6 = 34 */ |
966 | 19 | #define CIPSO_TAG_LEN_MAX 34 |
967 | | |
968 | | /* The Commercial IP Security Option (CIPSO) is defined in IETF draft |
969 | | * draft-ietf-cipso-ipsecurity-01.txt and FIPS 188, a copy of both documents |
970 | | * can be found at the NetLabel project page, http://netlabel.sf.net or at |
971 | | * https://tools.ietf.org/html/draft-ietf-cipso-ipsecurity-01 */ |
972 | | static const value_string cipso_tag_type_vals[] = { |
973 | | {0, "Padding"}, |
974 | | {1, "Restrictive Category Bitmap"}, |
975 | | {2, "Enumerated Categories"}, |
976 | | {5, "Ranged Categories"}, |
977 | | {6, "Permissive Categories"}, |
978 | | {7, "Free Form"}, |
979 | | |
980 | | { 0, NULL } |
981 | | }; |
982 | | |
983 | | static int |
984 | | dissect_ipopt_cipso(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
985 | 20 | { |
986 | 20 | proto_tree *field_tree; |
987 | 20 | proto_item *tf, *tag_item; |
988 | 20 | unsigned tagtype, taglen; |
989 | 20 | int offset = 2, |
990 | 20 | optlen = tvb_reported_length(tvb); |
991 | 20 | int offset_max = optlen; |
992 | | |
993 | 20 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_cipso, ett_ip_option_cipso, &tf, optlen); |
994 | | |
995 | 20 | proto_tree_add_item(field_tree, hf_ip_cipso_doi, tvb, offset, 4, ENC_BIG_ENDIAN); |
996 | 20 | offset += 4; |
997 | | |
998 | | /* loop through all of the tags in the CIPSO option */ |
999 | 70 | while (offset < offset_max) { |
1000 | 66 | tagtype = tvb_get_uint8(tvb, offset); |
1001 | 66 | tag_item = proto_tree_add_item(field_tree, hf_ip_cipso_tag_type, tvb, offset, 1, ENC_NA); |
1002 | | |
1003 | 66 | if ((offset + 1) < offset_max) |
1004 | 63 | taglen = tvb_get_uint8(tvb, offset + 1); |
1005 | 3 | else |
1006 | 3 | taglen = 1; |
1007 | | |
1008 | 66 | switch (tagtype) { |
1009 | 38 | case 0: |
1010 | | /* padding - skip this tag */ |
1011 | 38 | offset += 1; |
1012 | 38 | continue; |
1013 | 3 | case 1: |
1014 | | /* restrictive bitmap, see CIPSO draft section 3.4.2 for tag format */ |
1015 | 3 | if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) || |
1016 | 2 | ((offset + (int)taglen - 1) > offset_max)) { |
1017 | 2 | expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag); |
1018 | 2 | return offset; |
1019 | 2 | } |
1020 | | |
1021 | | /* skip past alignment octet */ |
1022 | 1 | offset += 3; |
1023 | | |
1024 | 1 | proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA); |
1025 | 1 | offset += 1; |
1026 | | |
1027 | 1 | if (taglen > 4) { |
1028 | 1 | unsigned bit_spot; |
1029 | 1 | unsigned byte_spot = 0; |
1030 | 1 | unsigned char bitmask; |
1031 | 1 | wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, ""); |
1032 | 1 | const uint8_t *val_ptr = tvb_get_ptr(tvb, offset, taglen - 4); |
1033 | | |
1034 | | /* we checked the length above so the highest category value |
1035 | | * possible here is 240 */ |
1036 | 3 | while (byte_spot < (taglen - 4)) { |
1037 | 2 | bitmask = 0x80; |
1038 | 2 | bit_spot = 0; |
1039 | 18 | while (bit_spot < 8) { |
1040 | 16 | if (val_ptr[byte_spot] & bitmask) { |
1041 | 10 | if (wmem_strbuf_get_len(cat_str_buf) > 0) |
1042 | 9 | wmem_strbuf_append_c(cat_str_buf, ','); |
1043 | | |
1044 | 10 | wmem_strbuf_append_printf(cat_str_buf, "%u", byte_spot * 8 + bit_spot); |
1045 | 10 | } |
1046 | 16 | bit_spot++; |
1047 | 16 | bitmask >>= 1; |
1048 | 16 | } |
1049 | 2 | byte_spot++; |
1050 | 2 | } |
1051 | | |
1052 | 1 | if (wmem_strbuf_get_len(cat_str_buf) > 0) |
1053 | 1 | proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset, taglen - 4, wmem_strbuf_get_str(cat_str_buf)); |
1054 | 0 | else |
1055 | 0 | proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset, taglen - 4, "ERROR PARSING CATEGORIES"); |
1056 | 1 | offset += taglen - 4; |
1057 | 1 | } |
1058 | 1 | break; |
1059 | 3 | case 2: |
1060 | | /* enumerated categories, see CIPSO draft section 3.4.3 for tag format */ |
1061 | 3 | if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) || |
1062 | 2 | ((offset + (int)taglen - 1) > offset_max)) { |
1063 | 2 | expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag); |
1064 | 2 | return offset; |
1065 | 2 | } |
1066 | | |
1067 | | /* skip past alignment octet */ |
1068 | 1 | offset += 3; |
1069 | | |
1070 | | /* sensitivity level */ |
1071 | 1 | proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA); |
1072 | 1 | offset += 1; |
1073 | | |
1074 | 1 | if (taglen > 4) { |
1075 | 1 | int offset_max_cat = offset + taglen - 4; |
1076 | 1 | wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, ""); |
1077 | | |
1078 | 3 | while ((offset + 2) <= offset_max_cat) { |
1079 | 2 | if (wmem_strbuf_get_len(cat_str_buf) > 0) |
1080 | 1 | wmem_strbuf_append_c(cat_str_buf, ','); |
1081 | | |
1082 | 2 | wmem_strbuf_append_printf(cat_str_buf, "%u", tvb_get_ntohs(tvb, offset)); |
1083 | 2 | offset += 2; |
1084 | 2 | } |
1085 | | |
1086 | 1 | proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset - taglen + 4, taglen - 4, wmem_strbuf_get_str(cat_str_buf)); |
1087 | 1 | } |
1088 | 1 | break; |
1089 | 5 | case 5: |
1090 | | /* ranged categories, see CIPSO draft section 3.4.4 for tag format */ |
1091 | 5 | if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) || |
1092 | 4 | ((offset + (int)taglen - 1) > offset_max)) { |
1093 | 2 | expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag); |
1094 | 2 | return offset; |
1095 | 2 | } |
1096 | | |
1097 | | /* skip past alignment octet */ |
1098 | 3 | offset += 3; |
1099 | | |
1100 | | /* sensitivity level */ |
1101 | 3 | proto_tree_add_item(field_tree, hf_ip_cipso_sensitivity_level, tvb, offset, 1, ENC_NA); |
1102 | 3 | offset += 1; |
1103 | | |
1104 | 3 | if (taglen > 4) { |
1105 | 3 | uint16_t cat_low, cat_high; |
1106 | 3 | int offset_max_cat = offset + taglen - 4; |
1107 | 3 | wmem_strbuf_t* cat_str_buf = wmem_strbuf_new(pinfo->pool, ""); |
1108 | | |
1109 | 7 | while ((offset + 2) <= offset_max_cat) { |
1110 | 4 | cat_high = tvb_get_ntohs(tvb, offset); |
1111 | 4 | if ((offset + 4) <= offset_max_cat) { |
1112 | 1 | cat_low = tvb_get_ntohs(tvb, offset + 2); |
1113 | 1 | offset += 4; |
1114 | 3 | } else { |
1115 | 3 | cat_low = 0; |
1116 | 3 | offset += 2; |
1117 | 3 | } |
1118 | 4 | if (wmem_strbuf_get_len(cat_str_buf) > 0) |
1119 | 1 | wmem_strbuf_append_c(cat_str_buf, ','); |
1120 | | |
1121 | 4 | if (cat_low != cat_high) |
1122 | 3 | wmem_strbuf_append_printf(cat_str_buf, "%u-%u", cat_high, cat_low); |
1123 | 1 | else |
1124 | 1 | wmem_strbuf_append_printf(cat_str_buf, "%u", cat_high); |
1125 | 4 | } |
1126 | | |
1127 | 3 | proto_tree_add_string(field_tree, hf_ip_cipso_categories, tvb, offset - taglen + 4, taglen - 4, wmem_strbuf_get_str(cat_str_buf)); |
1128 | 3 | } |
1129 | 3 | break; |
1130 | 6 | case 6: |
1131 | | /* permissive categories, see FIPS 188 section 6.9 for tag format */ |
1132 | 6 | if ((taglen < 4) || (taglen > CIPSO_TAG_LEN_MAX) || |
1133 | 5 | ((offset + (int)taglen - 1) > offset_max)) { |
1134 | 2 | expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag); |
1135 | 2 | return offset; |
1136 | 2 | } |
1137 | | |
1138 | 4 | proto_tree_add_item(field_tree, hf_ip_cipso_tag_data, tvb, offset + 2, taglen - 2, ENC_NA); |
1139 | 4 | offset += taglen; |
1140 | 4 | break; |
1141 | 4 | case 7: |
1142 | | /* free form, see FIPS 188 section 6.10 for tag format */ |
1143 | 4 | if ((taglen < 2) || (taglen > CIPSO_TAG_LEN_MAX) || |
1144 | 4 | ((offset + (int)taglen - 1) > offset_max)) { |
1145 | 0 | expert_add_info(pinfo, tag_item, &ei_ip_cipso_tag); |
1146 | 0 | return offset; |
1147 | 0 | } |
1148 | | |
1149 | 4 | proto_tree_add_item(field_tree, hf_ip_cipso_tag_data, tvb, offset + 2, taglen - 2, ENC_NA); |
1150 | 4 | offset += taglen; |
1151 | 4 | break; |
1152 | 7 | default: |
1153 | | /* unknown tag - stop parsing this IPv4 option */ |
1154 | 7 | if ((offset + 1) <= offset_max) { |
1155 | 7 | taglen = tvb_get_uint8(tvb, offset + 1); |
1156 | 7 | proto_item_append_text(tag_item, " (%u bytes)", taglen); |
1157 | 7 | return offset; |
1158 | 7 | } |
1159 | 0 | return offset; |
1160 | 66 | } |
1161 | 66 | } |
1162 | | |
1163 | 4 | return offset; |
1164 | 20 | } |
1165 | | |
1166 | | static void |
1167 | | dissect_option_route(proto_tree *tree, packet_info *pinfo, tvbuff_t *tvb, int offset, int hf, |
1168 | | int hf_host, bool next) |
1169 | 18 | { |
1170 | 18 | proto_item *ti; |
1171 | 18 | uint32_t route; |
1172 | | |
1173 | 18 | route = tvb_get_ipv4(tvb, offset); |
1174 | 18 | if (next) |
1175 | 1 | proto_tree_add_ipv4_format_value(tree, hf, tvb, offset, 4, route, |
1176 | 1 | "%s <- (next)", |
1177 | 1 | tvb_ip_to_str(pinfo->pool, tvb, offset)); |
1178 | 17 | else |
1179 | 17 | proto_tree_add_ipv4(tree, hf, tvb, offset, 4, route); |
1180 | | |
1181 | 18 | if (!proto_field_is_referenced(tree, hf_host)) { |
1182 | 15 | return; |
1183 | 15 | } |
1184 | | |
1185 | 3 | ti = proto_tree_add_string(tree, hf_host, tvb, offset, 4, get_hostname_wmem(pinfo->pool, route)); |
1186 | 3 | proto_item_set_generated(ti); |
1187 | 3 | proto_item_set_hidden(ti); |
1188 | 3 | } |
1189 | | |
1190 | | static int |
1191 | | dissect_ipopt_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, int proto, int optlen_min) |
1192 | 33 | { |
1193 | 33 | proto_tree *field_tree; |
1194 | 33 | proto_item *tf; |
1195 | 33 | uint8_t len, ptr; |
1196 | 33 | int optoffset = 0; |
1197 | 33 | int offset = 0, |
1198 | 33 | optlen = tvb_reported_length(tvb); |
1199 | | |
1200 | 33 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto, ett_ip_option_route, &tf, optlen); |
1201 | | |
1202 | 33 | tf = proto_tree_add_item_ret_uint8(field_tree, hf_ip_opt_ptr, tvb, offset + 2, 1, ENC_NA, &ptr); |
1203 | 33 | if ((ptr < (optlen_min + 1)) || (ptr & 3)) { |
1204 | 26 | if (ptr < (optlen_min + 1)) { |
1205 | 21 | expert_add_info(pinfo, tf, &ei_ip_opt_ptr_before_address); |
1206 | 21 | } |
1207 | 5 | else { |
1208 | 5 | expert_add_info(pinfo, tf, &ei_ip_opt_ptr_middle_address); |
1209 | 5 | } |
1210 | 26 | return optlen_min; |
1211 | 26 | } |
1212 | | |
1213 | 7 | len = optlen; |
1214 | 7 | optoffset = 3; /* skip past type, length and pointer */ |
1215 | 12 | for (optlen -= 3; optlen > 0; optlen -= 4, optoffset += 4) { |
1216 | 8 | if (optlen < 4) { |
1217 | 3 | expert_add_info(pinfo, tf, &ei_ip_subopt_too_long); |
1218 | 3 | break; |
1219 | 3 | } |
1220 | | |
1221 | 5 | if (ptr > len) { |
1222 | | /* This is a recorded route */ |
1223 | 3 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt, |
1224 | 3 | hf_ip_rec_rt_host, false); |
1225 | 3 | } else if (optoffset == (len - 4)) { |
1226 | | /* This is the destination */ |
1227 | 0 | proto_item *item; |
1228 | 0 | uint32_t addr; |
1229 | 0 | const char *dst_host; |
1230 | |
|
1231 | 0 | addr = tvb_get_ipv4(tvb, offset + optoffset); |
1232 | 0 | proto_tree_add_ipv4(field_tree, hf_ip_dst, tvb, |
1233 | 0 | offset + optoffset, 4, addr); |
1234 | 0 | item = proto_tree_add_ipv4(field_tree, hf_ip_addr, tvb, |
1235 | 0 | offset + optoffset, 4, addr); |
1236 | 0 | proto_item_set_hidden(item); |
1237 | 0 | if (proto_field_is_referenced(field_tree, hf_ip_dst_host) || proto_field_is_referenced(field_tree, hf_ip_host)) { |
1238 | 0 | dst_host = get_hostname_wmem(pinfo->pool, addr); |
1239 | 0 | item = proto_tree_add_string(field_tree, hf_ip_dst_host, tvb, |
1240 | 0 | offset + optoffset, 4, dst_host); |
1241 | 0 | proto_item_set_generated(item); |
1242 | 0 | proto_item_set_hidden(item); |
1243 | 0 | item = proto_tree_add_string(field_tree, hf_ip_host, tvb, |
1244 | 0 | offset + optoffset, 4, dst_host); |
1245 | 0 | proto_item_set_generated(item); |
1246 | 0 | proto_item_set_hidden(item); |
1247 | 0 | } |
1248 | 2 | } else if ((optoffset + 1) < ptr) { |
1249 | | /* This is also a recorded route */ |
1250 | 2 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt, |
1251 | 2 | hf_ip_rec_rt_host, false); |
1252 | 2 | } else if ((optoffset + 1) == ptr) { |
1253 | | /* This is the next source route. TODO: Should we use separate hf's |
1254 | | * for this, such as hf_ip_next_rt and hf_ip_next_rt_host and avoid |
1255 | | * having to pass true/false to dissect_option_route()? */ |
1256 | 0 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_src_rt, |
1257 | 0 | hf_ip_src_rt_host, true); |
1258 | 0 | } else { |
1259 | | /* This must be a source route */ |
1260 | 0 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_src_rt, |
1261 | 0 | hf_ip_src_rt_host, false); |
1262 | 0 | } |
1263 | 5 | } |
1264 | | |
1265 | 7 | return tvb_captured_length(tvb); |
1266 | 33 | } |
1267 | | |
1268 | | static int |
1269 | | dissect_ipopt_loose_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1270 | 29 | { |
1271 | 29 | return dissect_ipopt_route(tvb, pinfo, tree, proto_ip_option_route, IPOLEN_LSR_MIN); |
1272 | 29 | } |
1273 | | |
1274 | | static int |
1275 | | dissect_ipopt_source_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1276 | 4 | { |
1277 | 4 | return dissect_ipopt_route(tvb, pinfo, tree, proto_ip_option_source_route, IPOLEN_SSR_MIN); |
1278 | | |
1279 | 4 | } |
1280 | | |
1281 | | static int |
1282 | | dissect_ipopt_record_route(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1283 | 96 | { |
1284 | 96 | proto_tree *field_tree; |
1285 | 96 | proto_item *tf; |
1286 | 96 | uint8_t len, ptr; |
1287 | 96 | int optoffset = 0; |
1288 | 96 | int offset = 0, |
1289 | 96 | optlen = tvb_reported_length(tvb); |
1290 | | |
1291 | 96 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_record_route, ett_ip_option_route, &tf, optlen); |
1292 | | |
1293 | 96 | tf = proto_tree_add_item_ret_uint8(field_tree, hf_ip_opt_ptr, tvb, offset + 2, 1, ENC_NA, &ptr); |
1294 | | |
1295 | 96 | if ((ptr < (IPOLEN_RR_MIN + 1)) || (ptr & 3)) { |
1296 | 88 | if (ptr < (IPOLEN_RR_MIN + 1)) { |
1297 | 46 | expert_add_info(pinfo, tf, &ei_ip_opt_ptr_before_address); |
1298 | 46 | } |
1299 | 42 | else { |
1300 | 42 | expert_add_info(pinfo, tf, &ei_ip_opt_ptr_middle_address); |
1301 | 42 | } |
1302 | 88 | return IPOLEN_RR_MIN; |
1303 | 88 | } |
1304 | | |
1305 | 8 | len = optlen; |
1306 | 8 | optoffset = 3; /* skip past type, length and pointer */ |
1307 | 21 | for (optlen -= 3; optlen > 0; optlen -= 4, optoffset += 4) { |
1308 | 15 | if (optlen < 4) { |
1309 | 2 | expert_add_info(pinfo, tf, &ei_ip_subopt_too_long); |
1310 | 2 | break; |
1311 | 2 | } |
1312 | | |
1313 | 13 | if (ptr > len) { |
1314 | | /* The recorded route data area is full. */ |
1315 | 10 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt, |
1316 | 10 | hf_ip_rec_rt_host, false); |
1317 | 10 | } else if ((optoffset + 1) < ptr) { |
1318 | | /* This is a recorded route */ |
1319 | 2 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_rec_rt, |
1320 | 2 | hf_ip_rec_rt_host, false); |
1321 | 2 | } else if ((optoffset + 1) == ptr) { |
1322 | | /* This is the next available slot. TODO: Should we use separate hf's |
1323 | | * for this, such as hf_ip_next_rt and hf_ip_next_rt_host and avoid |
1324 | | * having to pass true/false to dissect_option_route()? */ |
1325 | 1 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_empty_rt, |
1326 | 1 | hf_ip_empty_rt_host, true); |
1327 | 1 | } else { |
1328 | | /* This must be an available slot too. */ |
1329 | 0 | dissect_option_route(field_tree, pinfo, tvb, offset + optoffset, hf_ip_empty_rt, |
1330 | 0 | hf_ip_empty_rt_host, false); |
1331 | 0 | } |
1332 | 13 | } |
1333 | | |
1334 | 8 | return tvb_captured_length(tvb); |
1335 | 96 | } |
1336 | | |
1337 | | /* Stream Identifier */ |
1338 | | static int |
1339 | | dissect_ipopt_sid(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1340 | 1 | { |
1341 | 1 | proto_tree *field_tree; |
1342 | 1 | proto_item *tf; |
1343 | | |
1344 | 1 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_sid, ett_ip_option_sid, &tf, IPOLEN_SID, tvb_reported_length(tvb)); |
1345 | 1 | expert_add_info(pinfo, tf, &ei_ip_opt_deprecated); |
1346 | | |
1347 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_sid, tvb, 2, 2, ENC_BIG_ENDIAN); |
1348 | 1 | return tvb_captured_length(tvb); |
1349 | 1 | } |
1350 | | |
1351 | | /* RFC 1063: MTU Probe and MTU Reply */ |
1352 | | static int |
1353 | | dissect_ipopt_mtu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, int proto) |
1354 | 30 | { |
1355 | 30 | proto_tree *field_tree; |
1356 | 30 | proto_item *tf; |
1357 | | |
1358 | 30 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto, ett_ip_option_mtu, &tf, IPOLEN_MTU, tvb_reported_length(tvb)); |
1359 | | |
1360 | 30 | proto_tree_add_item(field_tree, hf_ip_opt_mtu, tvb, 2, 2, ENC_BIG_ENDIAN); |
1361 | 30 | return tvb_captured_length(tvb); |
1362 | 30 | } |
1363 | | |
1364 | | static int |
1365 | | dissect_ipopt_mtu_probe(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_) |
1366 | 5 | { |
1367 | 5 | return dissect_ipopt_mtu(tvb, pinfo, tree, proto_ip_option_mtu_probe); |
1368 | 5 | } |
1369 | | |
1370 | | static int |
1371 | | dissect_ipopt_mtu_reply(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_) |
1372 | 25 | { |
1373 | 25 | return dissect_ipopt_mtu(tvb, pinfo, tree, proto_ip_option_mtu_reply); |
1374 | 25 | } |
1375 | | |
1376 | | /* RFC 1393: Traceroute */ |
1377 | | static int |
1378 | | dissect_ipopt_tr(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1379 | 1 | { |
1380 | 1 | proto_tree *field_tree; |
1381 | 1 | proto_item *tf; |
1382 | 1 | int offset = 2; |
1383 | | |
1384 | 1 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_traceroute, ett_ip_option_tr, &tf, IPOLEN_TR, tvb_reported_length(tvb)); |
1385 | 1 | expert_add_info(pinfo, tf, &ei_ip_opt_deprecated); |
1386 | | |
1387 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_id_number, tvb, offset, 2, ENC_BIG_ENDIAN); |
1388 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_ohc, tvb, offset + 2, 2, ENC_BIG_ENDIAN); |
1389 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_rhc, tvb, offset + 4, 2, ENC_BIG_ENDIAN); |
1390 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_originator, tvb, offset + 6, 4, ENC_BIG_ENDIAN); |
1391 | 1 | return tvb_captured_length(tvb); |
1392 | 1 | } |
1393 | | |
1394 | | static const value_string ipopt_timestamp_flag_vals[] = { |
1395 | | {IPOPT_TS_TSONLY, "Time stamps only" }, |
1396 | | {IPOPT_TS_TSANDADDR, "Time stamp and address" }, |
1397 | | {IPOPT_TS_PRESPEC, "Time stamps for prespecified addresses"}, |
1398 | | {0, NULL }}; |
1399 | | |
1400 | | static int |
1401 | | dissect_ipopt_timestamp(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1402 | 12 | { |
1403 | 12 | proto_tree *field_tree; |
1404 | 12 | proto_item *tf; |
1405 | 12 | int ptr; |
1406 | 12 | int optoffset = 0; |
1407 | 12 | int flg; |
1408 | 12 | uint32_t addr; |
1409 | 12 | int offset = 0, |
1410 | 12 | optlen = tvb_reported_length(tvb); |
1411 | | |
1412 | 12 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_timestamp, ett_ip_option_timestamp, &tf, optlen); |
1413 | | |
1414 | 12 | optoffset += 2; /* skip past type and length */ |
1415 | 12 | optlen -= 2; /* subtract size of type and length */ |
1416 | | |
1417 | 12 | ptr = tvb_get_uint8(tvb, offset + optoffset); |
1418 | 12 | proto_tree_add_uint_format_value(field_tree, hf_ip_opt_ptr, tvb, offset + optoffset, 1, ptr, "%d%s", |
1419 | 12 | ptr, ((ptr == 1) ? " (header is full)" : |
1420 | 12 | (ptr < 5) ? " (points before first address)" : |
1421 | 12 | (((ptr - 1) & 3) ? " (points to middle of field)" : ""))); |
1422 | 12 | optoffset++; |
1423 | 12 | optlen--; |
1424 | 12 | ptr--; /* ptr is 1-origin */ |
1425 | | |
1426 | 12 | flg = tvb_get_uint8(tvb, offset + optoffset); |
1427 | 12 | proto_tree_add_item(field_tree, hf_ip_opt_overflow, tvb, offset + optoffset, 1, ENC_NA); |
1428 | 12 | flg &= 0xF; |
1429 | 12 | proto_tree_add_item(field_tree, hf_ip_opt_flag, tvb, offset + optoffset, 1, ENC_NA); |
1430 | 12 | optoffset++; |
1431 | 12 | optlen--; |
1432 | | |
1433 | 31 | while (optlen > 0) { |
1434 | 26 | if (flg == IPOPT_TS_TSANDADDR || flg == IPOPT_TS_PRESPEC) { |
1435 | 4 | if (optlen < 8) { |
1436 | 4 | proto_tree_add_expert(field_tree, pinfo, &ei_ip_subopt_too_long, tvb, offset + optoffset, optlen); |
1437 | 4 | break; |
1438 | 4 | } |
1439 | 0 | addr = tvb_get_ipv4(tvb, offset + optoffset); |
1440 | 0 | if (proto_field_is_referenced(field_tree, hf_ip_opt_time_stamp_addr)) { |
1441 | 0 | proto_tree_add_ipv4_format_value(field_tree, hf_ip_opt_time_stamp_addr, tvb, offset + optoffset, 4, addr, |
1442 | 0 | "%s", ((addr == 0) ? "-" : get_hostname_wmem(pinfo->pool, addr))); |
1443 | 0 | } |
1444 | 0 | optoffset += 4; |
1445 | 0 | optlen -= 4; |
1446 | |
|
1447 | 0 | proto_tree_add_item(field_tree, hf_ip_opt_time_stamp, tvb, offset + optoffset, 4, ENC_BIG_ENDIAN); |
1448 | 0 | optoffset += 4; |
1449 | 0 | optlen -= 4; |
1450 | 22 | } else { |
1451 | 22 | if (optlen < 4) { |
1452 | 3 | proto_tree_add_expert(field_tree, pinfo, &ei_ip_subopt_too_long, tvb, offset + optoffset, optlen); |
1453 | 3 | break; |
1454 | 3 | } |
1455 | 19 | proto_tree_add_item(field_tree, hf_ip_opt_time_stamp, tvb, offset + optoffset, 4, ENC_BIG_ENDIAN); |
1456 | 19 | optoffset += 4; |
1457 | 19 | optlen -= 4; |
1458 | 19 | } |
1459 | 26 | } |
1460 | | |
1461 | 12 | return tvb_captured_length(tvb); |
1462 | 12 | } |
1463 | | |
1464 | | /* Router Alert */ |
1465 | | static const range_string ra_rvals[] = { |
1466 | | {0, 0, "Router shall examine packet"}, |
1467 | | {1, 65535, "Reserved"}, |
1468 | | {0, 0, NULL} |
1469 | | }; |
1470 | | |
1471 | | static int |
1472 | | dissect_ipopt_ra(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1473 | 2 | { |
1474 | | /* Router-Alert, as defined by RFC2113 */ |
1475 | 2 | proto_tree *field_tree; |
1476 | 2 | proto_item *tf; |
1477 | 2 | uint32_t value; |
1478 | | |
1479 | 2 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_routeralert, ett_ip_option_ra, &tf, IPOLEN_RA, tvb_reported_length(tvb)); |
1480 | | |
1481 | 2 | proto_tree_add_item_ret_uint(field_tree, hf_ip_opt_ra, tvb, 2, 2, ENC_BIG_ENDIAN, &value); |
1482 | 2 | proto_item_append_text(tf, ": %s (%u)", rval_to_str_wmem(pinfo->pool, value, ra_rvals, "Unknown (%u)"), value); |
1483 | 2 | return tvb_captured_length(tvb); |
1484 | 2 | } |
1485 | | |
1486 | | /* RFC 1770: Selective Directed Broadcast */ |
1487 | | static int |
1488 | | dissect_ipopt_sdb(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1489 | 6 | { |
1490 | 6 | proto_tree *field_tree; |
1491 | 6 | proto_item *tf; |
1492 | 6 | int offset = 0, |
1493 | 6 | optlen = tvb_reported_length(tvb); |
1494 | | |
1495 | 6 | field_tree = ip_var_option_header(tree, pinfo, tvb, proto_ip_option_sdb, ett_ip_option_sdb, &tf, optlen); |
1496 | 6 | expert_add_info(pinfo, tf, &ei_ip_opt_deprecated); |
1497 | | |
1498 | 7 | for (offset += 2, optlen -= 2; optlen >= 4; offset += 4, optlen -= 4) |
1499 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_addr, tvb, offset, 4, ENC_BIG_ENDIAN); |
1500 | | |
1501 | 6 | if (optlen > 0) |
1502 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_padding, tvb, offset, optlen, ENC_NA); |
1503 | | |
1504 | 6 | return tvb_captured_length(tvb); |
1505 | 6 | } |
1506 | | |
1507 | | const value_string qs_func_vals[] = { |
1508 | | {QS_RATE_REQUEST, "Rate request"}, |
1509 | | {QS_RATE_REPORT, "Rate report"}, |
1510 | | {0, NULL} |
1511 | | }; |
1512 | | |
1513 | | static const value_string qs_rate_vals[] = { |
1514 | | { 0, "0 bit/s"}, |
1515 | | { 1, "80 Kbit/s"}, |
1516 | | { 2, "160 Kbit/s"}, |
1517 | | { 3, "320 Kbit/s"}, |
1518 | | { 4, "640 Kbit/s"}, |
1519 | | { 5, "1.28 Mbit/s"}, |
1520 | | { 6, "2.56 Mbit/s"}, |
1521 | | { 7, "5.12 Mbit/s"}, |
1522 | | { 8, "10.24 Mbit/s"}, |
1523 | | { 9, "20.48 Mbit/s"}, |
1524 | | {10, "40.96 Mbit/s"}, |
1525 | | {11, "81.92 Mbit/s"}, |
1526 | | {12, "163.84 Mbit/s"}, |
1527 | | {13, "327.68 Mbit/s"}, |
1528 | | {14, "655.36 Mbit/s"}, |
1529 | | {15, "1.31072 Gbit/s"}, |
1530 | | {0, NULL} |
1531 | | }; |
1532 | | value_string_ext qs_rate_vals_ext = VALUE_STRING_EXT_INIT(qs_rate_vals); |
1533 | | |
1534 | | static int |
1535 | | dissect_ipopt_qs(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data) |
1536 | 5 | { |
1537 | 5 | proto_tree *field_tree; |
1538 | 5 | proto_item *tf; |
1539 | 5 | proto_item *ti; |
1540 | 5 | ws_ip4 *iph = (ws_ip4 *)data; |
1541 | 5 | int offset = 2; |
1542 | | |
1543 | 5 | uint8_t command = tvb_get_uint8(tvb, offset); |
1544 | 5 | uint8_t function = command >> 4; |
1545 | 5 | uint8_t rate = command & QS_RATE_MASK; |
1546 | 5 | uint8_t ttl_diff; |
1547 | | |
1548 | 5 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_qs, ett_ip_option_qs, &tf, IPOLEN_QS, tvb_reported_length(tvb)); |
1549 | 5 | proto_item_append_text(tf, ": %s (%u)", val_to_str(pinfo->pool, function, qs_func_vals, "Unknown (%u)"), function); |
1550 | | |
1551 | 5 | proto_tree_add_item(field_tree, hf_ip_opt_qs_func, tvb, offset, 1, ENC_NA); |
1552 | | |
1553 | 5 | if (function == QS_RATE_REQUEST) { |
1554 | 2 | proto_tree_add_item(field_tree, hf_ip_opt_qs_rate, tvb, offset, 1, ENC_NA); |
1555 | 2 | proto_tree_add_item(field_tree, hf_ip_opt_qs_ttl, tvb, offset + 1, 1, ENC_NA); |
1556 | 2 | ttl_diff = (iph->ip_ttl - tvb_get_uint8(tvb, offset + 1) % 256); |
1557 | 2 | ti = proto_tree_add_uint(field_tree, hf_ip_opt_qs_ttl_diff, |
1558 | 2 | tvb, offset + 1, 1, ttl_diff); |
1559 | 2 | proto_item_set_generated(ti); |
1560 | 2 | proto_item_append_text(tf, ", %s, QS TTL %u, QS TTL diff %u", |
1561 | 2 | val_to_str_ext(pinfo->pool, rate, &qs_rate_vals_ext, "Unknown (%u)"), |
1562 | 2 | tvb_get_uint8(tvb, offset + 1), ttl_diff); |
1563 | 2 | proto_tree_add_item(field_tree, hf_ip_opt_qs_nonce, tvb, offset + 2, 4, ENC_BIG_ENDIAN); |
1564 | 2 | proto_tree_add_item(field_tree, hf_ip_opt_qs_reserved, tvb, offset + 2, 4, ENC_BIG_ENDIAN); |
1565 | 3 | } else if (function == QS_RATE_REPORT) { |
1566 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_qs_rate, tvb, offset, 1, ENC_NA); |
1567 | 1 | proto_item_append_text(tf, ", %s", |
1568 | 1 | val_to_str_ext(pinfo->pool, rate, &qs_rate_vals_ext, "Unknown (%u)")); |
1569 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_qs_unused, tvb, offset + 1, 1, ENC_NA); |
1570 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_qs_nonce, tvb, offset + 2, 4, ENC_BIG_ENDIAN); |
1571 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_qs_reserved, tvb, offset + 2, 4, ENC_BIG_ENDIAN); |
1572 | 1 | } |
1573 | | |
1574 | 5 | return tvb_captured_length(tvb); |
1575 | 5 | } |
1576 | | |
1577 | | |
1578 | | static int |
1579 | | dissect_ipopt_cilium_dsr(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void * data _U_) |
1580 | 1 | { |
1581 | 1 | proto_tree *field_tree; |
1582 | 1 | proto_item *tf; |
1583 | 1 | int offset = 2; |
1584 | | |
1585 | 1 | field_tree = ip_fixed_option_header(tree, pinfo, tvb, proto_ip_option_dsr, ett_ip_option_dsr, &tf, IPOLEN_DSR, tvb_reported_length(tvb)); |
1586 | | |
1587 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_dsr_cilium_service_port, tvb, offset, 2, ENC_LITTLE_ENDIAN); |
1588 | 1 | offset += 2; |
1589 | | |
1590 | | /* Yes, it is encoded with little endian */ |
1591 | 1 | proto_tree_add_item(field_tree, hf_ip_opt_dsr_cilium_service_ip, tvb, offset, 4, ENC_LITTLE_ENDIAN); |
1592 | | |
1593 | 1 | return tvb_captured_length(tvb); |
1594 | 1 | } |
1595 | | |
1596 | | static void |
1597 | | dissect_ip_options(tvbuff_t *tvb, int offset, unsigned length, |
1598 | | packet_info *pinfo, proto_tree *opt_tree, |
1599 | | proto_item *opt_item, void * data) |
1600 | 55.6k | { |
1601 | 55.6k | unsigned char opt; |
1602 | 55.6k | unsigned int optlen; |
1603 | 55.6k | proto_tree *field_tree; |
1604 | 55.6k | const char *name; |
1605 | 55.6k | dissector_handle_t option_dissector; |
1606 | 55.6k | unsigned nop_count = 0; |
1607 | 55.6k | tvbuff_t *next_tvb; |
1608 | | |
1609 | 61.7k | while (length > 0) { |
1610 | 61.1k | opt = tvb_get_uint8(tvb, offset); |
1611 | 61.1k | --length; /* account for type byte */ |
1612 | | |
1613 | 61.1k | if ((opt == IPOPT_EOOL) || (opt == IPOPT_NOP)) { |
1614 | 14.6k | int local_proto; |
1615 | 14.6k | proto_item* field_item; |
1616 | | /* We assume that the only options with no length are EOL and NOP options, |
1617 | | so that we can treat unknown options as having a minimum length of 2, |
1618 | | and at least be able to move on to the next option by using the length in the option. */ |
1619 | | |
1620 | 14.6k | if (opt == IPOPT_EOOL) |
1621 | 12.6k | { |
1622 | 12.6k | local_proto = proto_ip_option_eol; |
1623 | 12.6k | } else { |
1624 | | /* i.e. opt is IPOPT_NOP */ |
1625 | 1.97k | local_proto = proto_ip_option_nop; |
1626 | | |
1627 | 1.97k | if (opt_item && (nop_count == 0 || offset % 4)) { |
1628 | | /* Count number of NOP in a row within a uint32 */ |
1629 | 1.94k | nop_count++; |
1630 | | |
1631 | 1.94k | if (nop_count == 4) { |
1632 | 38 | expert_add_info(pinfo, opt_item, &ei_ip_nop); |
1633 | 38 | } |
1634 | 1.94k | } else { |
1635 | 27 | nop_count = 0; |
1636 | 27 | } |
1637 | 1.97k | } |
1638 | | |
1639 | 14.6k | field_item = proto_tree_add_item(opt_tree, local_proto, tvb, offset, 1, ENC_NA); |
1640 | 14.6k | field_tree = proto_item_add_subtree(field_item, ett_ip_option_other); |
1641 | | |
1642 | 14.6k | dissect_ipopt_type(tvb, offset, field_tree); |
1643 | 14.6k | offset++; |
1644 | | |
1645 | 46.4k | } else { |
1646 | 46.4k | option_dissector = dissector_get_uint_handle(ip_option_table, opt); |
1647 | 46.4k | if (option_dissector == NULL) { |
1648 | 44.0k | name = wmem_strdup_printf(pinfo->pool, "Unknown (0x%02x)", opt); |
1649 | 44.0k | } else { |
1650 | 2.43k | name = dissector_handle_get_protocol_short_name(option_dissector); |
1651 | 2.43k | } |
1652 | | |
1653 | | /* Option has a length. Is it in the packet? */ |
1654 | 46.4k | if (length == 0) { |
1655 | | /* Bogus - packet must at least include option code byte and |
1656 | | length byte! */ |
1657 | 92 | proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, 1, |
1658 | 92 | "%s (length byte past end of options)", name); |
1659 | 92 | return; |
1660 | 92 | } |
1661 | | |
1662 | 46.3k | optlen = tvb_get_uint8(tvb, offset + 1); /* total including type, len */ |
1663 | 46.3k | --length; /* account for length byte */ |
1664 | | |
1665 | 46.3k | if (optlen < 2) { |
1666 | | /* Bogus - option length is too short to include option code and option length. */ |
1667 | 10.2k | proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, 2, |
1668 | 10.2k | "%s (with too-short option length = %u byte%s)", |
1669 | 10.2k | name, optlen, plurality(optlen, "", "s")); |
1670 | 10.2k | return; |
1671 | 36.1k | } else if (optlen - 2 > length) { |
1672 | | /* Bogus - option goes past the end of the header. */ |
1673 | 32.0k | proto_tree_add_expert_format(opt_tree, pinfo, &ei_ip_opt_len_invalid, tvb, offset, length, |
1674 | 32.0k | "%s (option length = %u byte%s says option goes past end of options)", |
1675 | 32.0k | name, optlen, plurality(optlen, "", "s")); |
1676 | 32.0k | return; |
1677 | 32.0k | } |
1678 | | |
1679 | 4.11k | if (option_dissector == NULL) { |
1680 | 3.88k | field_tree = proto_tree_add_subtree_format(opt_tree, tvb, offset, optlen, ett_ip_unknown_opt, NULL, "%s (%u byte%s)", |
1681 | 3.88k | name, optlen, plurality(optlen, "", "s")); |
1682 | 3.88k | dissect_ipopt_type(tvb, offset, field_tree); |
1683 | | |
1684 | 3.88k | proto_tree_add_item(field_tree, hf_ip_opt_len, tvb, offset+1, 1, ENC_NA); |
1685 | 3.88k | proto_tree_add_item(field_tree, hf_ip_opt_data, tvb, offset+2, optlen-2, ENC_NA); |
1686 | 3.88k | } else { |
1687 | 230 | next_tvb = tvb_new_subset_length(tvb, offset, optlen); |
1688 | 230 | call_dissector_with_data(option_dissector, next_tvb, pinfo, opt_tree, data); |
1689 | 230 | proto_item_append_text(proto_tree_get_parent(opt_tree), ", %s", name); |
1690 | 230 | } |
1691 | | |
1692 | 4.11k | offset += optlen; |
1693 | 4.11k | length -= (optlen-2); //already accounted for type and len bytes |
1694 | 4.11k | } |
1695 | | |
1696 | 18.7k | if (opt == IPOPT_EOOL) |
1697 | 12.6k | break; |
1698 | 18.7k | } |
1699 | 55.6k | } |
1700 | | |
1701 | | /* This function searches the IP options for either a loose or strict source |
1702 | | * route option, then returns the offset to the destination address if the |
1703 | | * pointer is still valid or zero if the pointer is greater than the length. |
1704 | | * |
1705 | | * The guts of this function was taken from dissect_ip_tcp_options(). |
1706 | | */ |
1707 | | static int |
1708 | | get_dst_offset(tvbuff_t *tvb, int offset, unsigned length) |
1709 | 55.7k | { |
1710 | 55.7k | unsigned char opt; |
1711 | 55.7k | unsigned len; |
1712 | 55.7k | int orig_offset = offset; |
1713 | | |
1714 | 61.9k | while (length > 0) { |
1715 | 61.2k | opt = tvb_get_uint8(tvb, offset); |
1716 | 61.2k | --length; /* account for type byte */ |
1717 | | |
1718 | 61.2k | if ((opt != IPOPT_EOOL) && (opt != IPOPT_NOP)) { |
1719 | | /* Option has a length. Is it in the packet? */ |
1720 | 46.4k | if (length == 0) { |
1721 | | /* Bogus - packet must at least include option code byte and |
1722 | | length byte! */ |
1723 | 91 | return 0; |
1724 | 91 | } |
1725 | 46.3k | len = tvb_get_uint8(tvb, offset + 1); /* total including type, len */ |
1726 | 46.3k | --length; /* account for length byte */ |
1727 | 46.3k | if (len < 2) { |
1728 | | /* Bogus - option length is too short to include option code and |
1729 | | option length. */ |
1730 | 10.2k | return 0; |
1731 | 36.1k | } else if (len - 2 > length) { |
1732 | | /* Bogus - option goes past the end of the header. */ |
1733 | 32.0k | return 0; |
1734 | 32.0k | } |
1735 | | |
1736 | 4.14k | if (opt == IPOPT_SSR || opt == IPOPT_LSR) { |
1737 | | /* Hmm, what if you have both options? */ |
1738 | 33 | uint8_t ptr; |
1739 | | |
1740 | 33 | ptr = tvb_get_uint8(tvb, offset + 2); |
1741 | 33 | if (ptr < 4 || (ptr & 3) || (ptr > len)) { |
1742 | 31 | return 0; |
1743 | 31 | } |
1744 | 2 | return (offset - orig_offset) + 4 + (len - 4); |
1745 | 33 | } |
1746 | | |
1747 | 4.10k | offset += len; |
1748 | 4.10k | length -= (len-2); /* subtract size of type and length */ |
1749 | 14.7k | } else { |
1750 | 14.7k | offset += 1; |
1751 | 14.7k | } |
1752 | 18.8k | if (opt == IPOPT_EOOL) |
1753 | 12.6k | return 0; |
1754 | 18.8k | } |
1755 | | |
1756 | 751 | return 0; |
1757 | 55.7k | } |
1758 | | |
1759 | | /* Returns the valid ttl for the group address */ |
1760 | | static uint16_t |
1761 | | local_network_control_block_addr_valid_ttl(uint32_t addr) |
1762 | 7 | { |
1763 | | /* An exception list, as some protocols seem to insist on |
1764 | | * doing differently: |
1765 | | */ |
1766 | | |
1767 | | /* IETF's VRRP (rfc3768) */ |
1768 | 7 | if (IPLOCAL_NETWRK_CTRL_BLK_VRRP_ADDR == addr) |
1769 | 0 | return IPLOCAL_NETWRK_CTRL_BLK_VRRP_TTL; |
1770 | | /* Cisco's GLPB */ |
1771 | 7 | if (IPLOCAL_NETWRK_CTRL_BLK_GLPB_ADDR == addr) |
1772 | 1 | return IPLOCAL_NETWRK_CTRL_BLK_GLPB_TTL; |
1773 | | /* mDNS (draft-cheshire-dnsext-multicastdns-07) */ |
1774 | 6 | if (IPLOCAL_NETWRK_CTRL_BLK_MDNS_ADDR == addr) |
1775 | 0 | return IPLOCAL_NETWRK_CTRL_BLK_MDNS_TTL; |
1776 | | /* LLMNR (rfc4795) */ |
1777 | 6 | if (IPLOCAL_NETWRK_CTRL_BLK_LLMNR_ADDR == addr) |
1778 | 0 | return IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL; |
1779 | 6 | return IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL; |
1780 | 6 | } |
1781 | | |
1782 | | static const value_string dscp_short_vals[] = { |
1783 | | { IPDSFIELD_DSCP_DEFAULT, "CS0" }, |
1784 | | { IPDSFIELD_DSCP_LE, "LE" }, |
1785 | | { IPDSFIELD_DSCP_CS1, "CS1" }, |
1786 | | { IPDSFIELD_DSCP_AF11, "AF11" }, |
1787 | | { IPDSFIELD_DSCP_AF12, "AF12" }, |
1788 | | { IPDSFIELD_DSCP_AF13, "AF13" }, |
1789 | | { IPDSFIELD_DSCP_CS2, "CS2" }, |
1790 | | { IPDSFIELD_DSCP_AF21, "AF21" }, |
1791 | | { IPDSFIELD_DSCP_AF22, "AF22" }, |
1792 | | { IPDSFIELD_DSCP_AF23, "AF23" }, |
1793 | | { IPDSFIELD_DSCP_CS3, "CS3" }, |
1794 | | { IPDSFIELD_DSCP_AF31, "AF31" }, |
1795 | | { IPDSFIELD_DSCP_AF32, "AF32" }, |
1796 | | { IPDSFIELD_DSCP_AF33, "AF33" }, |
1797 | | { IPDSFIELD_DSCP_CS4, "CS4" }, |
1798 | | { IPDSFIELD_DSCP_AF41, "AF41" }, |
1799 | | { IPDSFIELD_DSCP_AF42, "AF42" }, |
1800 | | { IPDSFIELD_DSCP_AF43, "AF43" }, |
1801 | | { IPDSFIELD_DSCP_CS5, "CS5" }, |
1802 | | { IPDSFIELD_VOICE_ADMIT, "VOICE-ADMIT" }, |
1803 | | { IPDSFIELD_DSCP_EF, "EF" }, |
1804 | | { IPDSFIELD_DSCP_CS6, "CS6" }, |
1805 | | { IPDSFIELD_DSCP_CS7, "CS7" }, |
1806 | | { 0, NULL }}; |
1807 | | value_string_ext dscp_short_vals_ext = VALUE_STRING_EXT_INIT(dscp_short_vals); |
1808 | | |
1809 | | |
1810 | | static const value_string dscp_vals[] = { |
1811 | | { IPDSFIELD_DSCP_DEFAULT, "Default" }, |
1812 | | { IPDSFIELD_DSCP_LE, "Lower Effort" }, |
1813 | | { IPDSFIELD_DSCP_CS1, "Class Selector 1" }, |
1814 | | { IPDSFIELD_DSCP_AF11, "Assured Forwarding 11" }, |
1815 | | { IPDSFIELD_DSCP_AF12, "Assured Forwarding 12" }, |
1816 | | { IPDSFIELD_DSCP_AF13, "Assured Forwarding 13" }, |
1817 | | { IPDSFIELD_DSCP_CS2, "Class Selector 2" }, |
1818 | | { IPDSFIELD_DSCP_AF21, "Assured Forwarding 21" }, |
1819 | | { IPDSFIELD_DSCP_AF22, "Assured Forwarding 22" }, |
1820 | | { IPDSFIELD_DSCP_AF23, "Assured Forwarding 23" }, |
1821 | | { IPDSFIELD_DSCP_CS3, "Class Selector 3" }, |
1822 | | { IPDSFIELD_DSCP_AF31, "Assured Forwarding 31" }, |
1823 | | { IPDSFIELD_DSCP_AF32, "Assured Forwarding 32" }, |
1824 | | { IPDSFIELD_DSCP_AF33, "Assured Forwarding 33" }, |
1825 | | { IPDSFIELD_DSCP_CS4, "Class Selector 4" }, |
1826 | | { IPDSFIELD_DSCP_AF41, "Assured Forwarding 41" }, |
1827 | | { IPDSFIELD_DSCP_AF42, "Assured Forwarding 42" }, |
1828 | | { IPDSFIELD_DSCP_AF43, "Assured Forwarding 43" }, |
1829 | | { IPDSFIELD_DSCP_CS5, "Class Selector 5" }, |
1830 | | { IPDSFIELD_VOICE_ADMIT, "Voice Admit" }, |
1831 | | { IPDSFIELD_DSCP_EF, "Expedited Forwarding" }, |
1832 | | { IPDSFIELD_DSCP_CS6, "Class Selector 6" }, |
1833 | | { IPDSFIELD_DSCP_CS7, "Class Selector 7" }, |
1834 | | { 0, NULL }}; |
1835 | | value_string_ext dscp_vals_ext = VALUE_STRING_EXT_INIT(dscp_vals); |
1836 | | |
1837 | | static const value_string ecn_short_vals[] = { |
1838 | | { IPDSFIELD_ECT_NOT, "Not-ECT" }, |
1839 | | { IPDSFIELD_ECT_1, "ECT(1)" }, |
1840 | | { IPDSFIELD_ECT_0, "ECT(0)" }, |
1841 | | { IPDSFIELD_CE, "CE" }, |
1842 | | { 0, NULL }}; |
1843 | | value_string_ext ecn_short_vals_ext = VALUE_STRING_EXT_INIT(ecn_short_vals); |
1844 | | |
1845 | | static const value_string ecn_vals[] = { |
1846 | | { IPDSFIELD_ECT_NOT, "Not ECN-Capable Transport" }, |
1847 | | { IPDSFIELD_ECT_1, "ECN-Capable Transport codepoint '01'" }, |
1848 | | { IPDSFIELD_ECT_0, "ECN-Capable Transport codepoint '10'" }, |
1849 | | { IPDSFIELD_CE, "Congestion Experienced" }, |
1850 | | { 0, NULL }}; |
1851 | | value_string_ext ecn_vals_ext = VALUE_STRING_EXT_INIT(ecn_vals); |
1852 | | |
1853 | | static const value_string precedence_vals[] = { |
1854 | | { IPTOS_PREC_ROUTINE, "routine" }, |
1855 | | { IPTOS_PREC_PRIORITY, "priority" }, |
1856 | | { IPTOS_PREC_IMMEDIATE, "immediate" }, |
1857 | | { IPTOS_PREC_FLASH, "flash" }, |
1858 | | { IPTOS_PREC_FLASHOVERRIDE, "flash override" }, |
1859 | | { IPTOS_PREC_CRITIC_ECP, "CRITIC/ECP" }, |
1860 | | { IPTOS_PREC_INTERNETCONTROL, "internetwork control" }, |
1861 | | { IPTOS_PREC_NETCONTROL, "network control" }, |
1862 | | { 0, NULL }}; |
1863 | | |
1864 | | static const value_string iptos_vals[] = { |
1865 | | { IPTOS_NONE, "None" }, |
1866 | | { IPTOS_LOWCOST, "Minimize cost" }, |
1867 | | { IPTOS_RELIABILITY, "Maximize reliability" }, |
1868 | | { IPTOS_THROUGHPUT, "Maximize throughput" }, |
1869 | | { IPTOS_LOWDELAY, "Minimize delay" }, |
1870 | | { IPTOS_SECURITY, "Maximize security" }, |
1871 | | { 0, NULL } |
1872 | | }; |
1873 | | |
1874 | | static const true_false_string flags_sf_set_evil = { |
1875 | | "Evil", |
1876 | | "Not evil" |
1877 | | }; |
1878 | | |
1879 | | bool |
1880 | | ip_try_dissect(bool heur_first, unsigned nxt, tvbuff_t *tvb, packet_info *pinfo, |
1881 | | proto_tree *tree, void *iph) |
1882 | 84.8k | { |
1883 | 84.8k | heur_dtbl_entry_t *hdtbl_entry; |
1884 | | |
1885 | 84.8k | if ((heur_first) && (dissector_try_heuristic(heur_subdissector_list, tvb, |
1886 | 0 | pinfo, tree, &hdtbl_entry, iph))) { |
1887 | 0 | return true; |
1888 | 0 | } |
1889 | | |
1890 | 84.8k | if (dissector_try_uint_with_data(ip_dissector_table, nxt, tvb, pinfo, |
1891 | 84.8k | tree, true, iph)) { |
1892 | 49.1k | return true; |
1893 | 49.1k | } |
1894 | | |
1895 | 35.7k | if ((!heur_first) && (dissector_try_heuristic(heur_subdissector_list, tvb, |
1896 | 573 | pinfo, tree, &hdtbl_entry, |
1897 | 573 | iph))) { |
1898 | 7 | return true; |
1899 | 7 | } |
1900 | | |
1901 | 35.7k | return false; |
1902 | 35.7k | } |
1903 | | |
1904 | | static void |
1905 | | export_pdu(tvbuff_t *tvb, packet_info *pinfo) |
1906 | 65.6k | { |
1907 | 65.6k | if (have_tap_listener(exported_pdu_tap)) { |
1908 | 0 | exp_pdu_data_t *exp_pdu_data = wmem_new0(pinfo->pool, exp_pdu_data_t); |
1909 | |
|
1910 | 0 | exp_pdu_data->tvb_captured_length = tvb_captured_length(tvb); |
1911 | 0 | exp_pdu_data->tvb_reported_length = tvb_reported_length(tvb); |
1912 | 0 | exp_pdu_data->pdu_tvb = tvb; |
1913 | 0 | tap_queue_packet(exported_pdu_tap, pinfo, exp_pdu_data); |
1914 | 0 | } |
1915 | 65.6k | } |
1916 | | |
1917 | | static struct ip_analysis * |
1918 | | init_ip_conversation_data(packet_info *pinfo) |
1919 | 14.6k | { |
1920 | 14.6k | struct ip_analysis *ipd; |
1921 | | |
1922 | | /* Initialize the ip protocol data structure to add to the ip conversation */ |
1923 | 14.6k | ipd=wmem_new0(wmem_file_scope(), struct ip_analysis); |
1924 | | |
1925 | 14.6k | ipd->initial_frame = pinfo->num; |
1926 | 14.6k | ipd->stream = 0; |
1927 | 14.6k | ipd->stream = ip_stream_count++; |
1928 | | |
1929 | 14.6k | return ipd; |
1930 | 14.6k | } |
1931 | | |
1932 | | struct ip_analysis * |
1933 | | get_ip_conversation_data(conversation_t *conv, packet_info *pinfo) |
1934 | 65.0k | { |
1935 | 65.0k | struct ip_analysis *ipd; |
1936 | | |
1937 | | /* Did the caller supply the conversation pointer? */ |
1938 | 65.0k | if( conv==NULL ) { |
1939 | 0 | return NULL; |
1940 | 0 | } |
1941 | | |
1942 | | /* Get the data for this conversation */ |
1943 | 65.0k | ipd=(struct ip_analysis *)conversation_get_proto_data(conv, proto_ip); |
1944 | | |
1945 | 65.0k | if (!ipd) { |
1946 | 14.6k | ipd = init_ip_conversation_data(pinfo); |
1947 | 14.6k | conversation_add_proto_data(conv, proto_ip, ipd); |
1948 | 14.6k | } |
1949 | | |
1950 | 65.0k | if (!ipd) { |
1951 | 0 | return NULL; |
1952 | 0 | } |
1953 | | |
1954 | 65.0k | return ipd; |
1955 | 65.0k | } |
1956 | | |
1957 | 2.84k | const char* ipprotostr(const int proto) { |
1958 | 2.84k | return val_to_str_ext_const(proto, &ipproto_val_ext, "Unknown"); |
1959 | 2.84k | } |
1960 | | |
1961 | | static int |
1962 | | dissect_ip_v4(tvbuff_t *tvb, packet_info *pinfo, proto_tree *parent_tree, void* data _U_) |
1963 | 65.7k | { |
1964 | 65.7k | proto_tree *ip_tree, *field_tree = NULL; |
1965 | 65.7k | proto_item *ti, *tf; |
1966 | 65.7k | uint32_t addr; |
1967 | 65.7k | int offset = 0, dst_off; |
1968 | 65.7k | unsigned hlen, optlen; |
1969 | 65.7k | uint16_t ipsum; |
1970 | 65.7k | fragment_head *ipfd_head = NULL; |
1971 | 65.7k | tvbuff_t *next_tvb; |
1972 | 65.7k | bool update_col_info = true; |
1973 | 65.7k | bool save_fragmented; |
1974 | 65.7k | ws_ip4 *iph; |
1975 | 65.7k | uint32_t src32, dst32; |
1976 | 65.7k | proto_tree *tree; |
1977 | 65.7k | proto_item *item = NULL, *ttl_item; |
1978 | 65.7k | uint16_t ttl_valid; |
1979 | 65.7k | struct ip_analysis *ipd=NULL; |
1980 | | |
1981 | 65.7k | tree = parent_tree; |
1982 | 65.7k | iph = wmem_new0(pinfo->pool, ws_ip4); |
1983 | | |
1984 | 65.7k | col_set_str(pinfo->cinfo, COL_PROTOCOL, "IPv4"); |
1985 | 65.7k | col_clear(pinfo->cinfo, COL_INFO); |
1986 | | |
1987 | 65.7k | iph->ip_ver = tvb_get_bits8(tvb, 0, 4); |
1988 | | |
1989 | 65.7k | hlen = tvb_get_bits8(tvb, 4, 4) * 4; /* IP header length, in bytes */ |
1990 | | |
1991 | 65.7k | ti = proto_tree_add_item(tree, proto_ip, tvb, offset, hlen, ENC_NA); |
1992 | 65.7k | ip_tree = proto_item_add_subtree(ti, ett_ip); |
1993 | | |
1994 | 65.7k | tf = proto_tree_add_bits_item(ip_tree, hf_ip_version, tvb, 0, 4, ENC_NA); |
1995 | 65.7k | if (iph->ip_ver != 4) { |
1996 | 30 | col_add_fstr(pinfo->cinfo, COL_INFO, |
1997 | 30 | "Bogus IPv4 version (%u, must be 4)", iph->ip_ver); |
1998 | 30 | expert_add_info_format(pinfo, tf, &ei_ip_bogus_ip_version, "Bogus IPv4 version"); |
1999 | | /* I have a Linux cooked capture with ethertype IPv4 containing an IPv6 packet, continue dissection in that case*/ |
2000 | 30 | if (iph->ip_ver == 6) { |
2001 | 13 | call_dissector(ipv6_handle, tvb, pinfo, tree); |
2002 | 13 | } |
2003 | | |
2004 | 30 | return tvb_captured_length(tvb); |
2005 | 30 | } |
2006 | | |
2007 | | /* if IP is not referenced from any filters we don't need to worry about |
2008 | | generating any tree items. We must do this after we created the actual |
2009 | | protocol above so that proto hier stat still works though. |
2010 | | XXX: Note that because of the following optimization expert items must |
2011 | | not be generated inside of an 'if (tree) ...' |
2012 | | so that Analyze ! Expert ... will work. |
2013 | | */ |
2014 | 65.7k | if (!proto_field_is_referenced(parent_tree, proto_ip)) { |
2015 | 10.0k | tree = NULL; |
2016 | 10.0k | } |
2017 | | |
2018 | 65.7k | if (hlen < IPH_MIN_LEN) { |
2019 | 87 | col_add_fstr(pinfo->cinfo, COL_INFO, |
2020 | 87 | "Bogus IP header length (%u, must be at least %u)", |
2021 | 87 | hlen, IPH_MIN_LEN); |
2022 | 87 | tf = proto_tree_add_uint_bits_format_value(ip_tree, hf_ip_hdr_len, tvb, (offset<<3)+4, 4, hlen, |
2023 | 87 | ENC_BIG_ENDIAN, "%u bytes (%u)", hlen, hlen>>2); |
2024 | 87 | expert_add_info_format(pinfo, tf, &ei_ip_bogus_header_length, |
2025 | 87 | "Bogus IP header length (%u, must be at least %u)", hlen, IPH_MIN_LEN); |
2026 | 87 | return tvb_captured_length(tvb); |
2027 | 87 | } |
2028 | | |
2029 | | // This should be consistent with tcp.hdr_len. |
2030 | 65.6k | proto_tree_add_uint_bits_format_value(ip_tree, hf_ip_hdr_len, tvb, (offset<<3)+4, 4, hlen, |
2031 | 65.6k | ENC_BIG_ENDIAN, "%u bytes (%u)", hlen, hlen>>2); |
2032 | | |
2033 | 65.6k | iph->ip_tos = tvb_get_uint8(tvb, offset + 1); |
2034 | 65.6k | if (g_ip_dscp_actif) { |
2035 | 65.6k | col_add_str(pinfo->cinfo, COL_DSCP_VALUE, |
2036 | 65.6k | val_to_str_ext(pinfo->pool, IPDSFIELD_DSCP(iph->ip_tos), &dscp_short_vals_ext, "%u")); |
2037 | 65.6k | } |
2038 | | |
2039 | 65.6k | if (tree) { |
2040 | 55.5k | if (g_ip_dscp_actif) { |
2041 | 55.5k | tf = proto_tree_add_item(ip_tree, hf_ip_dsfield, tvb, offset + 1, 1, ENC_NA); |
2042 | 55.5k | proto_item_append_text(tf, " (DSCP: %s, ECN: %s)", |
2043 | 55.5k | val_to_str_ext_const(IPDSFIELD_DSCP(iph->ip_tos), &dscp_short_vals_ext, "Unknown"), |
2044 | 55.5k | val_to_str_ext_const(IPDSFIELD_ECN(iph->ip_tos), &ecn_short_vals_ext, "Unknown")); |
2045 | | |
2046 | 55.5k | field_tree = proto_item_add_subtree(tf, ett_ip_dsfield); |
2047 | 55.5k | proto_tree_add_item(field_tree, hf_ip_dsfield_dscp, tvb, offset + 1, 1, ENC_NA); |
2048 | 55.5k | proto_tree_add_item(field_tree, hf_ip_dsfield_ecn, tvb, offset + 1, 1, ENC_NA); |
2049 | 55.5k | } else { |
2050 | 0 | tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_tos, tvb, offset + 1, 1, |
2051 | 0 | iph->ip_tos, |
2052 | 0 | "0x%02x (%s)", |
2053 | 0 | iph->ip_tos, |
2054 | 0 | val_to_str_const(IPTOS_TOS(iph->ip_tos), |
2055 | 0 | iptos_vals, "Unknown")); |
2056 | |
|
2057 | 0 | field_tree = proto_item_add_subtree(tf, ett_ip_tos); |
2058 | 0 | proto_tree_add_item(field_tree, hf_ip_tos_precedence, tvb, offset + 1, 1, ENC_NA); |
2059 | 0 | proto_tree_add_item(field_tree, hf_ip_tos_delay, tvb, offset + 1, 1, ENC_NA); |
2060 | 0 | proto_tree_add_item(field_tree, hf_ip_tos_throughput, tvb, offset + 1, 1, ENC_NA); |
2061 | 0 | proto_tree_add_item(field_tree, hf_ip_tos_reliability, tvb, offset + 1, 1, ENC_NA); |
2062 | 0 | proto_tree_add_item(field_tree, hf_ip_tos_cost, tvb, offset + 1, 1, ENC_NA); |
2063 | 0 | } |
2064 | 55.5k | } |
2065 | | |
2066 | | /* Length of IP datagram. |
2067 | | XXX - what if this is greater than the reported length of the |
2068 | | tvbuff? This could happen, for example, in an IP datagram |
2069 | | inside an ICMP datagram; we need to somehow let the |
2070 | | dissector we call know that, as it might want to avoid |
2071 | | doing its checksumming. */ |
2072 | 65.6k | iph->ip_len = tvb_get_ntohs(tvb, offset + 2); |
2073 | | |
2074 | 65.6k | if (iph->ip_len < hlen) { |
2075 | 10.8k | if (ip_tso_supported && !iph->ip_len) { |
2076 | | /* TSO support enabled, and zero length. Assume the zero length is |
2077 | | * the result of TSO, and use the reported length instead. Note that |
2078 | | * we need to use the frame/reported length instead of the actually- |
2079 | | * available length, just in case a snaplen was used on capture. */ |
2080 | 10.8k | iph->ip_len = tvb_reported_length(tvb); |
2081 | 10.8k | if (tree) { |
2082 | 9.05k | tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_len, tvb, offset + 2, 2, |
2083 | 9.05k | iph->ip_len, |
2084 | 9.05k | "%u bytes (reported as 0, presumed to be because of \"TCP segmentation offload\" (TSO))", |
2085 | 9.05k | iph->ip_len); |
2086 | 9.05k | proto_item_set_generated(tf); |
2087 | 9.05k | } |
2088 | 10.8k | } else { |
2089 | | /* TSO support not enabled, or non-zero length, so treat it as an error. */ |
2090 | 14 | col_add_fstr(pinfo->cinfo, COL_INFO, |
2091 | 14 | "Bogus IP length (%u, less than header length %u)", |
2092 | 14 | iph->ip_len, hlen); |
2093 | 14 | tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_len, tvb, offset + 2, 2, |
2094 | 14 | iph->ip_len, |
2095 | 14 | "%u bytes (bogus, less than header length %u)", |
2096 | 14 | iph->ip_len, hlen); |
2097 | 14 | expert_add_info(pinfo, tf, &ei_ip_bogus_ip_length); |
2098 | | /* Can't dissect any further */ |
2099 | 14 | return tvb_captured_length(tvb); |
2100 | 14 | } |
2101 | 54.8k | } else { |
2102 | 54.8k | tf = proto_tree_add_uint(ip_tree, hf_ip_len, tvb, offset + 2, 2, iph->ip_len); |
2103 | 54.8k | if (iph->ip_len > tvb_reported_length(tvb)) { |
2104 | | /* |
2105 | | * Length runs past the data we're given. |
2106 | | * Note that if not in a ICMP error packet. |
2107 | | */ |
2108 | 54.5k | if (!pinfo->flags.in_error_pkt) { |
2109 | 52.0k | expert_add_info_format(pinfo, tf, &ei_ip_bogus_ip_length, |
2110 | 52.0k | "IPv4 total length exceeds packet length (%u bytes)", |
2111 | 52.0k | tvb_reported_length(tvb)); |
2112 | 52.0k | } |
2113 | 54.5k | } else { |
2114 | 292 | if (iph->ip_len == hlen) { |
2115 | | /* IP header with no data. Let the user know */ |
2116 | 1 | expert_add_info(pinfo, tf, &ei_ip_zero_data_length); |
2117 | 1 | } |
2118 | | |
2119 | | /* |
2120 | | * Now that we know that the total length of this IP datagram isn't |
2121 | | * obviously bogus, adjust the length of this tvbuff to include only |
2122 | | * the IP datagram. |
2123 | | */ |
2124 | 292 | set_actual_length(tvb, iph->ip_len); |
2125 | 292 | } |
2126 | 54.8k | } |
2127 | | |
2128 | | /* Only export after adjusting the length */ |
2129 | 65.6k | export_pdu(tvb, pinfo); |
2130 | | |
2131 | 65.6k | iph->ip_id = tvb_get_ntohs(tvb, offset + 4); |
2132 | 65.6k | if (tree) |
2133 | 55.5k | proto_tree_add_uint(ip_tree, hf_ip_id, tvb, offset + 4, 2, iph->ip_id); |
2134 | | |
2135 | 65.6k | iph->ip_off = tvb_get_ntohs(tvb, offset + 6); |
2136 | | |
2137 | 65.6k | if (ip_security_flag) { |
2138 | | /* RFC 3514 - The Security Flag in the IPv4 Header (April Fool's joke) */ |
2139 | 0 | static int * const ip_flags_evil[] = { |
2140 | 0 | &hf_ip_flags_sf, |
2141 | 0 | &hf_ip_flags_df, |
2142 | 0 | &hf_ip_flags_mf, |
2143 | 0 | NULL |
2144 | 0 | }; |
2145 | |
|
2146 | 0 | tf = proto_tree_add_bitmask_with_flags(ip_tree, tvb, offset + 6, hf_ip_flags, |
2147 | 0 | ett_ip_flags, ip_flags_evil, ENC_BIG_ENDIAN, BMT_NO_FALSE | BMT_NO_TFS | BMT_NO_INT); |
2148 | 0 | if (iph->ip_off & IP_RF) { |
2149 | 0 | expert_add_info(pinfo, tf, &ei_ip_evil_packet); |
2150 | 0 | } |
2151 | 65.6k | } else { |
2152 | 65.6k | static int * const ip_flags[] = { |
2153 | 65.6k | &hf_ip_flags_rf, |
2154 | 65.6k | &hf_ip_flags_df, |
2155 | 65.6k | &hf_ip_flags_mf, |
2156 | 65.6k | NULL |
2157 | 65.6k | }; |
2158 | 65.6k | tf = proto_tree_add_bitmask_with_flags(ip_tree, tvb, offset + 6, hf_ip_flags, |
2159 | 65.6k | ett_ip_flags, ip_flags, ENC_BIG_ENDIAN, BMT_NO_FALSE | BMT_NO_TFS | BMT_NO_INT); |
2160 | 65.6k | if (iph->ip_off & IP_RF) { |
2161 | 6.06k | expert_add_info(pinfo, tf, &ei_ip_reserved_bit_set); |
2162 | 6.06k | } |
2163 | 65.6k | } |
2164 | | |
2165 | 65.6k | tf = proto_tree_add_uint_format_value(ip_tree, hf_ip_frag_offset, tvb, offset + 6, 2, |
2166 | 65.6k | iph->ip_off, "%u", (iph->ip_off & IP_OFFSET) * 8); |
2167 | | |
2168 | 65.6k | iph->ip_ttl = tvb_get_uint8(tvb, offset + 8); |
2169 | 65.6k | ttl_item = proto_tree_add_item(ip_tree, hf_ip_ttl, tvb, offset + 8, 1, ENC_BIG_ENDIAN); |
2170 | | |
2171 | 65.6k | iph->ip_proto = tvb_get_uint8(tvb, offset + 9); |
2172 | 65.6k | if (tree) { |
2173 | 55.5k | proto_tree_add_item(ip_tree, hf_ip_proto, tvb, offset + 9, 1, ENC_BIG_ENDIAN); |
2174 | 55.5k | } |
2175 | | |
2176 | 65.6k | iph->ip_sum = tvb_get_ntohs(tvb, offset + 10); |
2177 | | |
2178 | | /* |
2179 | | * If checksum checking is enabled, and we have the entire IP header |
2180 | | * available, check the checksum. |
2181 | | */ |
2182 | 65.6k | if (ip_check_checksum && tvb_bytes_exist(tvb, offset, hlen)) { |
2183 | 0 | ipsum = ip_checksum_tvb(tvb, offset, hlen); |
2184 | 0 | item = proto_tree_add_checksum(ip_tree, tvb, offset + 10, hf_ip_checksum, hf_ip_checksum_status, &ei_ip_checksum_bad, pinfo, ipsum, |
2185 | 0 | ENC_BIG_ENDIAN, PROTO_CHECKSUM_VERIFY|PROTO_CHECKSUM_IN_CKSUM); |
2186 | | /* |
2187 | | * ip_checksum_tvb() should never return 0xFFFF here, because, to |
2188 | | * quote RFC 1624 section 3 "Discussion": |
2189 | | * |
2190 | | * In one's complement, there are two representations of |
2191 | | * zero: the all zero and the all one bit values, often |
2192 | | * referred to as +0 and -0. One's complement addition |
2193 | | * of non-zero inputs can produce -0 as a result, but |
2194 | | * never +0. Since there is guaranteed to be at least |
2195 | | * one non-zero field in the IP header, and the checksum |
2196 | | * field in the protocol header is the complement of the |
2197 | | * sum, the checksum field can never contain ~(+0), which |
2198 | | * is -0 (0xFFFF). It can, however, contain ~(-0), which |
2199 | | * is +0 (0x0000). |
2200 | | * |
2201 | | * ip_checksum_tvb() checksums the IPv4 header, where the "version" |
2202 | | * field is 4, ensuring that, in a valid IPv4 header, there is at |
2203 | | * least one non-zero field. We've already verified that the |
2204 | | * version is 4. |
2205 | | * |
2206 | | * ip_checksum_tvb() returns the negation of the one's-complement |
2207 | | * sum of all the data handed to it, and that data won't be |
2208 | | * all zero, so the sum won't be 0 (+0), and thus the negation |
2209 | | * won't be -0, i.e. won't be 0xFFFF. |
2210 | | */ |
2211 | 0 | if (ipsum == 0) { |
2212 | | /* XXX - Keeping hf_ip_checksum_calculated field for now. Doesn't fit into the |
2213 | | proto_tree_add_checksum design, but IP is a popular enough dissector that somebody |
2214 | | may have a legitimate reason for wanting it filtered */ |
2215 | 0 | item = proto_tree_add_uint(ip_tree, hf_ip_checksum_calculated, tvb, |
2216 | 0 | offset + 10, 2, iph->ip_sum); |
2217 | 0 | proto_item_set_generated(item); |
2218 | 0 | } else { |
2219 | 0 | proto_item_append_text(item, "(may be caused by \"IP checksum offload\"?)"); |
2220 | |
|
2221 | 0 | item = proto_tree_add_uint(ip_tree, hf_ip_checksum_calculated, tvb, |
2222 | 0 | offset + 10, 2, in_cksum_shouldbe(iph->ip_sum, ipsum)); |
2223 | 0 | proto_item_set_generated(item); |
2224 | 0 | } |
2225 | 65.6k | } else { |
2226 | 65.6k | ipsum = 0; |
2227 | 65.6k | proto_tree_add_uint_format_value(ip_tree, hf_ip_checksum, tvb, |
2228 | 65.6k | offset + 10, 2, iph->ip_sum, |
2229 | 65.6k | "0x%04x [%s]", |
2230 | 65.6k | iph->ip_sum, |
2231 | 65.6k | ip_check_checksum ? |
2232 | 0 | "not all data available" : |
2233 | 65.6k | "validation disabled"); |
2234 | 65.6k | item = proto_tree_add_uint(ip_tree, hf_ip_checksum_status, tvb, |
2235 | 65.6k | offset + 10, 0, PROTO_CHECKSUM_E_UNVERIFIED); |
2236 | 65.6k | proto_item_set_generated(item); |
2237 | 65.6k | } |
2238 | 65.6k | src32 = tvb_get_ntohl(tvb, offset + IPH_SRC); |
2239 | 65.6k | set_address_tvb(&pinfo->net_src, AT_IPv4, 4, tvb, offset + IPH_SRC); |
2240 | 65.6k | copy_address_shallow(&pinfo->src, &pinfo->net_src); |
2241 | 65.6k | copy_address_shallow(&iph->ip_src, &pinfo->src); |
2242 | 65.6k | if (tree) { |
2243 | 55.2k | const char *src_host; |
2244 | | |
2245 | 55.2k | memcpy(&addr, iph->ip_src.data, 4); |
2246 | 55.2k | if (ip_summary_in_tree) { |
2247 | 55.2k | proto_item_append_text(ti, ", Src: %s", address_with_resolution_to_str(pinfo->pool, &iph->ip_src)); |
2248 | 55.2k | } |
2249 | 55.2k | proto_tree_add_ipv4(ip_tree, hf_ip_src, tvb, offset + 12, 4, addr); |
2250 | 55.2k | item = proto_tree_add_ipv4(ip_tree, hf_ip_addr, tvb, offset + 12, 4, addr); |
2251 | 55.2k | proto_item_set_hidden(item); |
2252 | 55.2k | if (proto_field_is_referenced(ip_tree, hf_ip_src_host) || proto_field_is_referenced(ip_tree, hf_ip_host)) { |
2253 | 55.2k | src_host = get_hostname_wmem(pinfo->pool, addr); |
2254 | 55.2k | item = proto_tree_add_string(ip_tree, hf_ip_src_host, tvb, offset + 12, 4, |
2255 | 55.2k | src_host); |
2256 | 55.2k | proto_item_set_generated(item); |
2257 | 55.2k | proto_item_set_hidden(item); |
2258 | 55.2k | item = proto_tree_add_string(ip_tree, hf_ip_host, tvb, offset + 12, 4, |
2259 | 55.2k | src_host); |
2260 | 55.2k | proto_item_set_generated(item); |
2261 | 55.2k | proto_item_set_hidden(item); |
2262 | 55.2k | } |
2263 | 55.2k | } |
2264 | | |
2265 | | /* If there's an IP strict or loose source routing option, then the final |
2266 | | * L3 IP destination address will be the last entry in the routing header |
2267 | | * EXCEPT when the table is exhausted (pointer is greater than the length). |
2268 | | * In this case, the final L3 IP destination address is the one in the L3 |
2269 | | * header. (REF: https://tools.ietf.org/html/rfc791#section-3.1) |
2270 | | */ |
2271 | 65.6k | if (hlen > IPH_MIN_LEN) { |
2272 | | /* There's more than just the fixed-length header. See if we've got |
2273 | | * either a strict or loose source route option and if so, return the |
2274 | | * offset into the tvb to where the real destination IP address is located. |
2275 | | */ |
2276 | 55.7k | dst_off = get_dst_offset(tvb, offset + 20, hlen - IPH_MIN_LEN); |
2277 | 55.7k | } |
2278 | 9.84k | else |
2279 | 9.84k | dst_off = 0; |
2280 | | |
2281 | 65.6k | dst32 = tvb_get_ntohl(tvb, offset + IPH_DST + dst_off); |
2282 | 65.6k | set_address_tvb(&pinfo->net_dst, AT_IPv4, 4, tvb, offset + IPH_DST + dst_off); |
2283 | 65.6k | copy_address_shallow(&pinfo->dst, &pinfo->net_dst); |
2284 | 65.6k | copy_address_shallow(&iph->ip_dst, &pinfo->net_dst); |
2285 | | |
2286 | | /* XXX - We do not want pinfo->conv_elements, if set, to be used to find the |
2287 | | * default conversation after this, or else subdissectors will set the |
2288 | | * wrong dissector. This is a bit of a hack, it should be solved more |
2289 | | * generally. */ |
2290 | 65.6k | pinfo->conv_elements = NULL; |
2291 | | |
2292 | | /* If an IP is destined for an IP address in the Local Network Control Block |
2293 | | * (e.g. 224.0.0.0/24), the packet should never be routed and the TTL would |
2294 | | * be expected to be 1. (see RFC 3171) Flag a TTL greater than 1. |
2295 | | * |
2296 | | * Flag a low TTL if the packet is not destined for a multicast address |
2297 | | * (e.g. 224.0.0.0/4) ... and the payload isn't protocol 103 (PIM). |
2298 | | * (see https://tools.ietf.org/html/rfc3973#section-4.7). |
2299 | | */ |
2300 | 65.6k | if (in4_addr_is_local_network_control_block(dst32)) { |
2301 | 8 | if (iph->ip_proto == IP_PROTO_IGMP) |
2302 | 1 | ttl_valid = IPLOCAL_NETWRK_CTRL_BLK_DEFAULT_TTL; |
2303 | 7 | else |
2304 | 7 | ttl_valid = local_network_control_block_addr_valid_ttl(dst32); |
2305 | 8 | if (iph->ip_ttl != ttl_valid && ttl_valid != IPLOCAL_NETWRK_CTRL_BLK_ANY_TTL) { |
2306 | 6 | expert_add_info_format(pinfo, ttl_item, &ei_ip_ttl_lncb, "\"Time To Live\" != %d for a packet sent to the " |
2307 | 6 | "Local Network Control Block (see RFC 3171)", |
2308 | 6 | ttl_valid); |
2309 | 6 | } |
2310 | 65.6k | } else if (iph->ip_ttl < 5 && !in4_addr_is_multicast(dst32) && |
2311 | | /* At least BGP should appear here as well */ |
2312 | 16.8k | iph->ip_proto != IP_PROTO_PIM && |
2313 | 16.7k | iph->ip_proto != IP_PROTO_OSPFIGP) { |
2314 | 16.7k | expert_add_info_format(pinfo, ttl_item, &ei_ip_ttl_too_small, "\"Time To Live\" only %u", iph->ip_ttl); |
2315 | 16.7k | } |
2316 | | |
2317 | 65.6k | if (tree) { |
2318 | 55.1k | const char *dst_host; |
2319 | | |
2320 | 55.1k | memcpy(&addr, iph->ip_dst.data, 4); |
2321 | 55.1k | if (ip_summary_in_tree) { |
2322 | 55.1k | proto_item_append_text(ti, ", Dst: %s", address_with_resolution_to_str(pinfo->pool, &iph->ip_dst)); |
2323 | 55.1k | } |
2324 | | |
2325 | 55.1k | if (dst_off) { |
2326 | 1 | uint32_t cur_rt; |
2327 | | |
2328 | 1 | cur_rt = tvb_get_ipv4(tvb, offset + 16); |
2329 | 1 | if (ip_summary_in_tree) { |
2330 | 1 | proto_item_append_text(ti, ", Via: %s", |
2331 | 1 | tvb_address_with_resolution_to_str(pinfo->pool, tvb, AT_IPv4, offset + 16)); |
2332 | 1 | } |
2333 | 1 | proto_tree_add_ipv4(ip_tree, hf_ip_cur_rt, tvb, offset + 16, 4, cur_rt); |
2334 | 1 | if (proto_field_is_referenced(ip_tree, hf_ip_cur_rt_host)) { |
2335 | 1 | item = proto_tree_add_string(ip_tree, hf_ip_cur_rt_host, tvb, |
2336 | 1 | offset + 16, 4, get_hostname_wmem(pinfo->pool, cur_rt)); |
2337 | 1 | proto_item_set_generated(item); |
2338 | 1 | proto_item_set_hidden(item); |
2339 | 1 | } |
2340 | 1 | } |
2341 | 55.1k | else { |
2342 | 55.1k | proto_tree_add_ipv4(ip_tree, hf_ip_dst, tvb, offset + 16, 4, addr); |
2343 | 55.1k | item = proto_tree_add_ipv4(ip_tree, hf_ip_addr, tvb, offset + 16, 4, |
2344 | 55.1k | addr); |
2345 | 55.1k | proto_item_set_hidden(item); |
2346 | 55.1k | if (proto_field_is_referenced(ip_tree, hf_ip_dst_host) || proto_field_is_referenced(ip_tree, hf_ip_host)) { |
2347 | 55.1k | dst_host = get_hostname_wmem(pinfo->pool, addr); |
2348 | 55.1k | item = proto_tree_add_string(ip_tree, hf_ip_dst_host, tvb, offset + 16, |
2349 | 55.1k | 4, dst_host); |
2350 | 55.1k | proto_item_set_generated(item); |
2351 | 55.1k | proto_item_set_hidden(item); |
2352 | 55.1k | item = proto_tree_add_string(ip_tree, hf_ip_host, tvb, |
2353 | 55.1k | offset + 16 + dst_off, 4, dst_host); |
2354 | 55.1k | proto_item_set_generated(item); |
2355 | 55.1k | proto_item_set_hidden(item); |
2356 | 55.1k | } |
2357 | 55.1k | } |
2358 | | |
2359 | 55.1k | if (gbl_resolv_flags.maxmind_geoip) { |
2360 | 55.1k | add_geoip_info(ip_tree, pinfo, tvb, offset, src32, dst32); |
2361 | 55.1k | } |
2362 | 55.1k | } |
2363 | | |
2364 | | /* Decode IP options, if any. */ |
2365 | 65.6k | if (hlen > IPH_MIN_LEN) { |
2366 | | /* There's more than just the fixed-length header. Decode the options. */ |
2367 | 55.6k | optlen = hlen - IPH_MIN_LEN; /* length of options, in bytes */ |
2368 | 55.6k | field_tree = proto_tree_add_subtree_format(ip_tree, tvb, offset + 20, optlen, |
2369 | 55.6k | ett_ip_options, &tf, "Options: (%u bytes)", optlen); |
2370 | 55.6k | dissect_ip_options(tvb, offset + 20, optlen, pinfo, field_tree, tf, iph); |
2371 | 55.6k | } |
2372 | | |
2373 | 65.6k | p_add_proto_data(pinfo->pool, pinfo, proto_ip, pinfo->curr_layer_num, iph); |
2374 | 65.6k | tap_queue_packet(ip_tap, pinfo, iph); |
2375 | | |
2376 | | /* Skip over header + options */ |
2377 | 65.6k | offset += hlen; |
2378 | | |
2379 | | /* If ip_defragment is on, this is a fragment, we have all the data |
2380 | | * in the fragment, and the header checksum is valid, then just add |
2381 | | * the fragment to the hashtable. |
2382 | | */ |
2383 | 65.6k | save_fragmented = pinfo->fragmented; |
2384 | 65.6k | if (ip_defragment && (iph->ip_off & (IP_MF|IP_OFFSET)) && |
2385 | 0 | iph->ip_len >= hlen && |
2386 | 0 | tvb_bytes_exist(tvb, offset, iph->ip_len - hlen) && |
2387 | 0 | ipsum == 0) { |
2388 | 0 | uint32_t frag_id; |
2389 | 0 | frag_id = iph->ip_proto ^ iph->ip_id ^ src32 ^ dst32; |
2390 | | /* XXX: Should there be a way to force the VLAN ID not to |
2391 | | * be taken into account for reassembly even with non publicly |
2392 | | * routable IP addresses? |
2393 | | */ |
2394 | 0 | if (in4_addr_is_private(dst32) || in4_addr_is_private(src32) || |
2395 | 0 | in4_addr_is_link_local(dst32) || in4_addr_is_link_local(src32) || |
2396 | 0 | prefs.strict_conversation_tracking_heuristics) { |
2397 | 0 | frag_id ^= pinfo->vlan_id; |
2398 | 0 | } |
2399 | 0 | ipfd_head = fragment_add_check(&ip_reassembly_table, tvb, offset, |
2400 | 0 | pinfo, |
2401 | 0 | frag_id, |
2402 | 0 | NULL, |
2403 | 0 | (iph->ip_off & IP_OFFSET) * 8, |
2404 | 0 | iph->ip_len - hlen, |
2405 | 0 | iph->ip_off & IP_MF); |
2406 | |
|
2407 | 0 | next_tvb = process_reassembled_data(tvb, offset, pinfo, "Reassembled IPv4", |
2408 | 0 | ipfd_head, &ip_frag_items, |
2409 | 0 | &update_col_info, ip_tree); |
2410 | 65.6k | } else { |
2411 | | /* If this is the first fragment, dissect its contents, otherwise |
2412 | | just show it as a fragment. |
2413 | | |
2414 | | XXX - if we eventually don't save the reassembled contents of all |
2415 | | fragmented datagrams, we may want to always reassemble. */ |
2416 | 65.6k | if (iph->ip_off & IP_OFFSET) { |
2417 | | /* Not the first fragment - don't dissect it. */ |
2418 | 414 | next_tvb = NULL; |
2419 | 65.2k | } else { |
2420 | | /* First fragment, or not fragmented. Dissect what we have here. */ |
2421 | | |
2422 | | /* Get a tvbuff for the payload. */ |
2423 | 65.2k | next_tvb = tvb_new_subset_remaining(tvb, offset); |
2424 | | |
2425 | | /* |
2426 | | * If this is the first fragment, but not the only fragment, |
2427 | | * tell the next protocol that. |
2428 | | */ |
2429 | 65.2k | if (iph->ip_off & IP_MF) |
2430 | 30.1k | pinfo->fragmented = true; |
2431 | 35.0k | else |
2432 | 35.0k | pinfo->fragmented = false; |
2433 | 65.2k | } |
2434 | 65.6k | } |
2435 | | |
2436 | | #if 0 |
2437 | | /* This would be automatic, but have the side effect that the stream IDs |
2438 | | * would depend on the order in which packets were dissected with a visible |
2439 | | * tree (e.g., clicking on them in Wireshark) instead of always being the |
2440 | | * same for a given file, which is probably unexpected. |
2441 | | */ |
2442 | | if (proto_field_is_referenced(tree, hf_stream_id) || have_tap_listener(ip_tap)) { |
2443 | | #endif |
2444 | 65.6k | if (ip_track_conv_id) { |
2445 | 65.0k | conversation_t *conv; |
2446 | | |
2447 | | /* find (and extend) an existing conversation, or create a new one */ |
2448 | 65.0k | conv = find_conversation_strat(pinfo, CONVERSATION_IP, NO_PORT_X, false); |
2449 | 65.0k | if(!conv) { |
2450 | 14.6k | conv=conversation_new_strat(pinfo, CONVERSATION_IP, NO_PORTS); |
2451 | 14.6k | } |
2452 | 50.4k | else { |
2453 | | /* |
2454 | | * while not strictly necessary because there is only 1 |
2455 | | * conversation between 2 IPs, we still move the last frame |
2456 | | * indicator as being a usual practice. |
2457 | | */ |
2458 | 50.4k | if (!(pinfo->fd->visited)) { |
2459 | 50.4k | if (pinfo->num > conv->last_frame) { |
2460 | 48.1k | conv->last_frame = pinfo->num; |
2461 | 48.1k | } |
2462 | 50.4k | } |
2463 | 50.4k | } |
2464 | | |
2465 | 65.0k | ipd = get_ip_conversation_data(conv, pinfo); |
2466 | 65.0k | if(ipd) { |
2467 | 65.0k | iph->ip_stream = ipd->stream; |
2468 | | |
2469 | 65.0k | item = proto_tree_add_uint(ip_tree, hf_ip_stream, tvb, offset, 0, ipd->stream); |
2470 | 65.0k | proto_item_set_generated(item); |
2471 | 65.0k | } |
2472 | 65.0k | } |
2473 | | |
2474 | 65.6k | if (next_tvb == NULL) { |
2475 | | /* Just show this as a fragment. */ |
2476 | 414 | col_add_fstr(pinfo->cinfo, COL_INFO, |
2477 | 414 | "Fragmented IP protocol (proto=%s %u, off=%u, ID=%04x)", |
2478 | 414 | ipprotostr(iph->ip_proto), iph->ip_proto, |
2479 | 414 | (iph->ip_off & IP_OFFSET) * 8, iph->ip_id); |
2480 | 414 | if ( ipfd_head && ipfd_head->reassembled_in != pinfo->num ) { |
2481 | 0 | col_append_frame_number(pinfo, COL_INFO, " [Reassembled in #%u]", |
2482 | 0 | ipfd_head->reassembled_in); |
2483 | 0 | } |
2484 | | |
2485 | 414 | call_data_dissector(tvb_new_subset_remaining(tvb, offset), pinfo, |
2486 | 414 | parent_tree); |
2487 | 414 | pinfo->fragmented = save_fragmented; |
2488 | 414 | return tvb_captured_length(tvb); |
2489 | 414 | } |
2490 | | |
2491 | 65.2k | if (tvb_reported_length(next_tvb) > 0) { |
2492 | | /* Hand off to the next protocol. |
2493 | | |
2494 | | XXX - setting the columns only after trying various dissectors means |
2495 | | that if one of those dissectors throws an exception, the frame won't |
2496 | | even be labeled as an IP frame; ideally, if a frame being dissected |
2497 | | throws an exception, it'll be labeled as a mangled frame of the |
2498 | | type in question. */ |
2499 | 64.6k | if (!ip_try_dissect(try_heuristic_first, iph->ip_proto, next_tvb, pinfo, |
2500 | 64.6k | parent_tree, iph)) { |
2501 | | /* Unknown protocol */ |
2502 | 148 | if (update_col_info) { |
2503 | 148 | col_add_fstr(pinfo->cinfo, COL_INFO, "%s (%u)", |
2504 | 148 | ipprotostr(iph->ip_proto), iph->ip_proto); |
2505 | 148 | } |
2506 | 148 | call_data_dissector(next_tvb, pinfo, parent_tree); |
2507 | 148 | } |
2508 | 64.6k | } |
2509 | 65.2k | pinfo->fragmented = save_fragmented; |
2510 | 65.2k | return tvb_captured_length(tvb); |
2511 | 65.6k | } |
2512 | | |
2513 | | /* |
2514 | | * Dissector that doesn't assume the packet is IPv4, it looks at the |
2515 | | * upper 4 bits of the first octet and: |
2516 | | * |
2517 | | * if they're 4, dissects the packet as IPv4; |
2518 | | * |
2519 | | * if they're 6, dissects the packet as IPv6; |
2520 | | * |
2521 | | * otherwise, reports it as an error. |
2522 | | * |
2523 | | * This handles some strange cases where IPv6 packets are encapsulated |
2524 | | * with a header that indicates an IPv4 packet (see commit |
2525 | | * a784b121502575a8930de9a34accb85c29ce9b80, which, as I remember, was |
2526 | | * done to handle such a case), as well as cases where there is no |
2527 | | * header to distinguish between IPv4 and IPv6 (e.g., LINKTYPE_RAW |
2528 | | * packets in pcap and pcapng files). |
2529 | | */ |
2530 | | static int |
2531 | | dissect_ip(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void* data _U_) |
2532 | 77.9k | { |
2533 | 77.9k | proto_tree *ip_tree; |
2534 | 77.9k | proto_item *ti, *tf; |
2535 | 77.9k | uint8_t version; |
2536 | | |
2537 | 77.9k | version = tvb_get_uint8(tvb, 0) >> 4; |
2538 | | |
2539 | 77.9k | if(version == 4){ |
2540 | 65.7k | return dissect_ip_v4(tvb, pinfo, tree, data); |
2541 | 65.7k | } |
2542 | 12.2k | if(version == 6){ |
2543 | 11.7k | return call_dissector(ipv6_handle, tvb, pinfo, tree); |
2544 | 11.7k | } |
2545 | | |
2546 | | /* Bogus IP version */ |
2547 | 509 | ti = proto_tree_add_protocol_format(tree, proto_ip, tvb, 0, 1, "Internet Protocol, bogus version (%u)", version); |
2548 | 509 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "IP"); |
2549 | 509 | col_clear(pinfo->cinfo, COL_INFO); |
2550 | 509 | col_add_fstr(pinfo->cinfo, COL_INFO, "Bogus IP version (%u)", version); |
2551 | 509 | ip_tree = proto_item_add_subtree(ti, ett_ip); |
2552 | 509 | tf = proto_tree_add_bits_item(ip_tree, hf_ip_version, tvb, 0, 4, ENC_NA); |
2553 | 509 | expert_add_info(pinfo, tf, &ei_ip_bogus_ip_version); |
2554 | 509 | return 1; |
2555 | 12.2k | } |
2556 | | |
2557 | | static bool |
2558 | | dissect_ip_heur(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data) |
2559 | 46 | { |
2560 | 46 | unsigned length, tot_length; |
2561 | 46 | uint8_t oct, version, ihl; |
2562 | 46 | bool ipv4_good = false; |
2563 | | |
2564 | | /* |
2565 | | * IPv4 Header Format |
2566 | | * |
2567 | | * 0 1 2 3 |
2568 | | * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 |
2569 | | * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |
2570 | | * |Version| IHL |Type of Service| Total Length | |
2571 | | * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+ |
2572 | | */ |
2573 | | |
2574 | 46 | length = tvb_captured_length(tvb); |
2575 | 46 | if (length < 4) { |
2576 | | /* Need at least 4 bytes to make some sort of decision */ |
2577 | 3 | return false; |
2578 | 3 | } |
2579 | | |
2580 | 43 | oct = tvb_get_uint8(tvb,0); |
2581 | 43 | ihl = oct & 0x0f; |
2582 | 43 | version = oct >> 4; |
2583 | | |
2584 | 43 | if (version == 6) { |
2585 | 2 | return dissect_ipv6_heur(tvb, pinfo, tree, data); |
2586 | 2 | } |
2587 | | |
2588 | | /* version == IPv4, the minimum value for a correct header is 5 */ |
2589 | 41 | if ((version != 4) || (ihl < 5)) { |
2590 | 40 | return false; |
2591 | 40 | } |
2592 | | |
2593 | | /* Total Length is the length of the datagram, measured in octets, |
2594 | | * including internet header and data. |
2595 | | */ |
2596 | 1 | tot_length = tvb_get_ntohs(tvb, 2); |
2597 | 1 | if (tot_length == tvb_reported_length(tvb)) { |
2598 | 0 | ipv4_good = true; |
2599 | 1 | } else if (ip_check_checksum && tvb_bytes_exist(tvb, 0, ihl * 4)) { |
2600 | 0 | if (ip_checksum_tvb(tvb, 0, ihl * 4) == 0) { |
2601 | 0 | ipv4_good = true; |
2602 | 0 | } |
2603 | 0 | } |
2604 | | |
2605 | 1 | if (ipv4_good) |
2606 | 0 | dissect_ip_v4(tvb, pinfo, tree, data); |
2607 | 1 | return ipv4_good; |
2608 | 41 | } |
2609 | | |
2610 | | static void |
2611 | | ip_init(void) |
2612 | 16 | { |
2613 | 16 | ip_stream_count = 0; |
2614 | 16 | } |
2615 | | |
2616 | | void |
2617 | | proto_register_ip(void) |
2618 | 16 | { |
2619 | 16 | static hf_register_info hf[] = { |
2620 | 16 | { &hf_ip_version, |
2621 | 16 | { "Version", "ip.version", FT_UINT8, BASE_DEC, |
2622 | 16 | NULL, 0x00, NULL, HFILL }}, |
2623 | | |
2624 | | // "IHL" in https://tools.ietf.org/html/rfc791#section-3.1 and |
2625 | | // https://en.wikipedia.org/wiki/IPv4#Header |
2626 | 16 | { &hf_ip_hdr_len, |
2627 | 16 | { "Header Length", "ip.hdr_len", FT_UINT8, BASE_DEC, |
2628 | 16 | NULL, 0x0, "Header length in 32-bit words", HFILL }}, |
2629 | | |
2630 | 16 | { &hf_ip_dsfield, |
2631 | 16 | { "Differentiated Services Field", "ip.dsfield", FT_UINT8, BASE_HEX, |
2632 | 16 | NULL, 0x0, NULL, HFILL }}, |
2633 | | |
2634 | 16 | { &hf_ip_dsfield_dscp, |
2635 | 16 | { "Differentiated Services Codepoint", "ip.dsfield.dscp", FT_UINT8, BASE_DEC | BASE_EXT_STRING, |
2636 | 16 | &dscp_vals_ext, IPDSFIELD_DSCP_MASK, NULL, HFILL }}, |
2637 | | |
2638 | 16 | { &hf_ip_dsfield_ecn, |
2639 | 16 | { "Explicit Congestion Notification", "ip.dsfield.ecn", FT_UINT8, BASE_DEC | BASE_EXT_STRING, |
2640 | 16 | &ecn_vals_ext, IPDSFIELD_ECN_MASK, NULL, HFILL }}, |
2641 | | |
2642 | 16 | { &hf_ip_tos, |
2643 | 16 | { "Type of Service", "ip.tos", FT_UINT8, BASE_DEC, |
2644 | 16 | NULL, 0x0, NULL, HFILL }}, |
2645 | | |
2646 | 16 | { &hf_ip_tos_precedence, |
2647 | 16 | { "Precedence", "ip.tos.precedence", FT_UINT8, BASE_DEC, |
2648 | 16 | VALS(precedence_vals), IPTOS_PREC_MASK, NULL, HFILL }}, |
2649 | | |
2650 | 16 | { &hf_ip_tos_delay, |
2651 | 16 | { "Delay", "ip.tos.delay", FT_BOOLEAN, 8, |
2652 | 16 | TFS(&tfs_low_normal), IPTOS_LOWDELAY, NULL, HFILL }}, |
2653 | | |
2654 | 16 | { &hf_ip_tos_throughput, |
2655 | 16 | { "Throughput", "ip.tos.throughput", FT_BOOLEAN, 8, |
2656 | 16 | TFS(&tfs_high_normal), IPTOS_THROUGHPUT, NULL, HFILL }}, |
2657 | | |
2658 | 16 | { &hf_ip_tos_reliability, |
2659 | 16 | { "Reliability", "ip.tos.reliability", FT_BOOLEAN, 8, |
2660 | 16 | TFS(&tfs_high_normal), IPTOS_RELIABILITY, NULL, HFILL }}, |
2661 | | |
2662 | 16 | { &hf_ip_tos_cost, |
2663 | 16 | { "Cost", "ip.tos.cost", FT_BOOLEAN, 8, |
2664 | 16 | TFS(&tfs_low_normal), IPTOS_LOWCOST, NULL, HFILL }}, |
2665 | | |
2666 | 16 | { &hf_ip_len, |
2667 | 16 | { "Total Length", "ip.len", FT_UINT16, BASE_DEC, |
2668 | 16 | NULL, 0x0, NULL, HFILL }}, |
2669 | | |
2670 | 16 | { &hf_ip_id, |
2671 | 16 | { "Identification", "ip.id", FT_UINT16, BASE_HEX_DEC, |
2672 | 16 | NULL, 0x0, NULL, HFILL }}, |
2673 | | |
2674 | 16 | { &hf_ip_dst, |
2675 | 16 | { "Destination Address", "ip.dst", FT_IPv4, BASE_NONE, |
2676 | 16 | NULL, 0x0, NULL, HFILL }}, |
2677 | | |
2678 | 16 | { &hf_ip_dst_host, |
2679 | 16 | { "Destination Host", "ip.dst_host", FT_STRING, BASE_NONE, |
2680 | 16 | NULL, 0x0, NULL, HFILL }}, |
2681 | | |
2682 | 16 | { &hf_ip_src, |
2683 | 16 | { "Source Address", "ip.src", FT_IPv4, BASE_NONE, |
2684 | 16 | NULL, 0x0, NULL, HFILL }}, |
2685 | | |
2686 | 16 | { &hf_ip_src_host, |
2687 | 16 | { "Source Host", "ip.src_host", FT_STRING, BASE_NONE, |
2688 | 16 | NULL, 0x0, NULL, HFILL }}, |
2689 | | |
2690 | 16 | { &hf_ip_addr, |
2691 | 16 | { "Source or Destination Address", "ip.addr", FT_IPv4, BASE_NONE, |
2692 | 16 | NULL, 0x0, NULL, HFILL }}, |
2693 | | |
2694 | 16 | { &hf_ip_host, |
2695 | 16 | { "Source or Destination Host", "ip.host", FT_STRING, BASE_NONE, |
2696 | 16 | NULL, 0x0, NULL, HFILL }}, |
2697 | | |
2698 | 16 | { &hf_ip_stream, |
2699 | 16 | { "Stream index", "ip.stream", FT_UINT32, BASE_DEC, |
2700 | 16 | NULL, 0x0, NULL, HFILL }}, |
2701 | | |
2702 | 16 | { &hf_geoip_country, |
2703 | 16 | { "Source or Destination GeoIP Country", "ip.geoip.country", |
2704 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2705 | 16 | { &hf_geoip_country_iso, |
2706 | 16 | { "Source or Destination GeoIP ISO Two Letter Country Code", "ip.geoip.country_iso", |
2707 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2708 | 16 | { &hf_geoip_city, |
2709 | 16 | { "Source or Destination GeoIP City", "ip.geoip.city", |
2710 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2711 | 16 | { &hf_geoip_as_number, |
2712 | 16 | { "Source or Destination GeoIP AS Number", "ip.geoip.asnum", |
2713 | 16 | FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
2714 | 16 | { &hf_geoip_as_org, |
2715 | 16 | { "Source or Destination GeoIP AS Organization", "ip.geoip.org", |
2716 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2717 | 16 | { &hf_geoip_latitude, |
2718 | 16 | { "Source or Destination GeoIP Latitude", "ip.geoip.lat", |
2719 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2720 | 16 | { &hf_geoip_longitude, |
2721 | 16 | { "Source or Destination GeoIP Longitude", "ip.geoip.lon", |
2722 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2723 | 16 | { &hf_geoip_src_summary, |
2724 | 16 | { "Source GeoIP", "ip.geoip.src_summary", |
2725 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2726 | 16 | { &hf_geoip_src_country, |
2727 | 16 | { "Source GeoIP Country", "ip.geoip.src_country", |
2728 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2729 | 16 | { &hf_geoip_src_country_iso, |
2730 | 16 | { "Source GeoIP ISO Two Letter Country Code", "ip.geoip.src_country_iso", |
2731 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2732 | 16 | { &hf_geoip_src_city, |
2733 | 16 | { "Source GeoIP City", "ip.geoip.src_city", |
2734 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2735 | 16 | { &hf_geoip_src_as_number, |
2736 | 16 | { "Source GeoIP AS Number", "ip.geoip.src_asnum", |
2737 | 16 | FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
2738 | 16 | { &hf_geoip_src_as_org, |
2739 | 16 | { "Source GeoIP AS Organization", "ip.geoip.src_org", |
2740 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2741 | 16 | { &hf_geoip_src_latitude, |
2742 | 16 | { "Source GeoIP Latitude", "ip.geoip.src_lat", |
2743 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2744 | 16 | { &hf_geoip_src_longitude, |
2745 | 16 | { "Source GeoIP Longitude", "ip.geoip.src_lon", |
2746 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2747 | 16 | { &hf_geoip_dst_summary, |
2748 | 16 | { "Destination GeoIP", "ip.geoip.dst_summary", |
2749 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2750 | 16 | { &hf_geoip_dst_country, |
2751 | 16 | { "Destination GeoIP Country", "ip.geoip.dst_country", |
2752 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2753 | 16 | { &hf_geoip_dst_country_iso, |
2754 | 16 | { "Destination GeoIP ISO Two Letter Country Code", "ip.geoip.dst_country_iso", |
2755 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2756 | 16 | { &hf_geoip_dst_city, |
2757 | 16 | { "Destination GeoIP City", "ip.geoip.dst_city", |
2758 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2759 | 16 | { &hf_geoip_dst_as_number, |
2760 | 16 | { "Destination GeoIP AS Number", "ip.geoip.dst_asnum", |
2761 | 16 | FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
2762 | 16 | { &hf_geoip_dst_as_org, |
2763 | 16 | { "Destination GeoIP AS Organization", "ip.geoip.dst_org", |
2764 | 16 | FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2765 | 16 | { &hf_geoip_dst_latitude, |
2766 | 16 | { "Destination GeoIP Latitude", "ip.geoip.dst_lat", |
2767 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2768 | 16 | { &hf_geoip_dst_longitude, |
2769 | 16 | { "Destination GeoIP Longitude", "ip.geoip.dst_lon", |
2770 | 16 | FT_DOUBLE, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
2771 | | |
2772 | 16 | { &hf_ip_flags, |
2773 | 16 | { "Flags", "ip.flags", FT_UINT8, BASE_HEX, |
2774 | 16 | NULL, 0xE0, NULL, HFILL }}, |
2775 | | |
2776 | 16 | { &hf_ip_flags_sf, |
2777 | 16 | { "Security flag", "ip.flags.sf", FT_BOOLEAN, 8, |
2778 | 16 | TFS(&flags_sf_set_evil), 0x80, "Security flag (RFC 3514)", HFILL }}, |
2779 | | |
2780 | 16 | { &hf_ip_flags_rf, |
2781 | 16 | { "Reserved bit", "ip.flags.rb", FT_BOOLEAN, 8, |
2782 | 16 | TFS(&tfs_set_notset), 0x80, "Reserved bit (must be zero; RFC 791)", HFILL } }, |
2783 | | |
2784 | 16 | { &hf_ip_flags_df, |
2785 | 16 | { "Don't fragment", "ip.flags.df", FT_BOOLEAN, 8, |
2786 | 16 | TFS(&tfs_set_notset), 0x40, NULL, HFILL }}, |
2787 | | |
2788 | 16 | { &hf_ip_flags_mf, |
2789 | 16 | { "More fragments", "ip.flags.mf", FT_BOOLEAN, 8, |
2790 | 16 | TFS(&tfs_set_notset), 0x20, NULL, HFILL }}, |
2791 | | |
2792 | 16 | { &hf_ip_frag_offset, |
2793 | 16 | { "Fragment Offset", "ip.frag_offset", FT_UINT16, BASE_DEC, |
2794 | 16 | NULL, IP_OFFSET, NULL, HFILL }}, |
2795 | | |
2796 | 16 | { &hf_ip_ttl, |
2797 | 16 | { "Time to Live", "ip.ttl", FT_UINT8, BASE_DEC, |
2798 | 16 | NULL, 0x0, NULL, HFILL }}, |
2799 | | |
2800 | 16 | { &hf_ip_proto, |
2801 | 16 | { "Protocol", "ip.proto", FT_UINT8, BASE_DEC | BASE_EXT_STRING, |
2802 | 16 | &ipproto_val_ext, 0x0, NULL, HFILL }}, |
2803 | | |
2804 | 16 | { &hf_ip_checksum, |
2805 | 16 | { "Header Checksum", "ip.checksum", FT_UINT16, BASE_HEX, |
2806 | 16 | NULL, 0x0, NULL, HFILL }}, |
2807 | | |
2808 | 16 | { &hf_ip_checksum_calculated, |
2809 | 16 | { "Calculated Checksum", "ip.checksum_calculated", FT_UINT16, BASE_HEX, NULL, 0x0, |
2810 | 16 | "The expected IP checksum field as calculated from the IP datagram", HFILL }}, |
2811 | | |
2812 | 16 | { &hf_ip_checksum_status, |
2813 | 16 | { "Header checksum status", "ip.checksum.status", FT_UINT8, BASE_NONE, VALS(proto_checksum_vals), 0x0, |
2814 | 16 | NULL, HFILL }}, |
2815 | | |
2816 | | /* IP options related fields */ |
2817 | 16 | { &hf_ip_opt_type, |
2818 | 16 | { "Type", "ip.opt.type", FT_UINT8, BASE_DEC, |
2819 | 16 | NULL, 0x0, NULL, HFILL }}, |
2820 | | |
2821 | 16 | { &hf_ip_opt_type_copy, |
2822 | 16 | { "Copy on fragmentation", "ip.opt.type.copy", FT_BOOLEAN, 8, |
2823 | 16 | TFS(&tfs_yes_no), IPOPT_COPY_MASK, NULL, HFILL }}, |
2824 | | |
2825 | 16 | { &hf_ip_opt_type_class, |
2826 | 16 | { "Class", "ip.opt.type.class", FT_UINT8, BASE_DEC, |
2827 | 16 | VALS(ipopt_type_class_vals), IPOPT_CLASS_MASK, NULL, HFILL }}, |
2828 | | |
2829 | 16 | { &hf_ip_opt_type_number, |
2830 | 16 | { "Number", "ip.opt.type.number", FT_UINT8, BASE_DEC, |
2831 | 16 | VALS(ipopt_type_number_vals), IPOPT_NUMBER_MASK, NULL, HFILL }}, |
2832 | | |
2833 | 16 | { &hf_ip_opt_len, |
2834 | 16 | { "Length", "ip.opt.len", FT_UINT8, BASE_DEC, |
2835 | 16 | NULL, 0x0, NULL, HFILL }}, |
2836 | | |
2837 | 16 | { &hf_ip_opt_data, |
2838 | 16 | { "Data", "ip.opt.data", FT_BYTES, BASE_NONE, |
2839 | 16 | NULL, 0x0, NULL, HFILL }}, |
2840 | | |
2841 | 16 | { &hf_ip_opt_ptr, |
2842 | 16 | { "Pointer", "ip.opt.ptr", FT_UINT8, BASE_DEC, |
2843 | 16 | NULL, 0x0, NULL, HFILL }}, |
2844 | | |
2845 | 16 | { &hf_ip_opt_sid, |
2846 | 16 | { "Stream Identifier", "ip.opt.sid", FT_UINT16, BASE_DEC, |
2847 | 16 | NULL, 0x0, "SATNET stream identifier", HFILL }}, |
2848 | | |
2849 | 16 | { &hf_ip_opt_mtu, |
2850 | 16 | { "MTU", "ip.opt.mtu", FT_UINT16, BASE_DEC, |
2851 | 16 | NULL, 0x0, NULL, HFILL }}, |
2852 | | |
2853 | 16 | { &hf_ip_opt_id_number, |
2854 | 16 | { "ID Number", "ip.opt.id_number", FT_UINT16, BASE_DEC, |
2855 | 16 | NULL, 0x0, NULL, HFILL }}, |
2856 | | |
2857 | 16 | { &hf_ip_opt_ohc, |
2858 | 16 | { "Outbound Hop Count", "ip.opt.ohc", FT_UINT16, BASE_DEC, |
2859 | 16 | NULL, 0x0, NULL, HFILL }}, |
2860 | | |
2861 | 16 | { &hf_ip_opt_rhc, |
2862 | 16 | { "Return Hop Count", "ip.opt.rhc", FT_UINT16, BASE_DEC, |
2863 | 16 | NULL, 0x0, NULL, HFILL }}, |
2864 | | |
2865 | 16 | { &hf_ip_opt_originator, |
2866 | 16 | { "Originator IP Address", "ip.opt.originator", FT_IPv4, BASE_NONE, |
2867 | 16 | NULL, 0x0, NULL, HFILL }}, |
2868 | | |
2869 | 16 | { &hf_ip_opt_ra, |
2870 | 16 | { "Router Alert", "ip.opt.ra", FT_UINT16, BASE_DEC | BASE_RANGE_STRING, |
2871 | 16 | RVALS(ra_rvals), 0x0, NULL, HFILL }}, |
2872 | | |
2873 | 16 | { &hf_ip_opt_addr, |
2874 | 16 | { "IP Address", "ip.opt.addr", FT_IPv4, BASE_NONE, |
2875 | 16 | NULL, 0x0, NULL, HFILL }}, |
2876 | | |
2877 | 16 | { &hf_ip_opt_padding, |
2878 | 16 | { "Padding", "ip.opt.padding", FT_BYTES, BASE_NONE, |
2879 | 16 | NULL, 0x0, NULL, HFILL }}, |
2880 | | |
2881 | 16 | { &hf_ip_opt_qs_func, |
2882 | 16 | { "Function", "ip.opt.qs_func", FT_UINT8, BASE_DEC, |
2883 | 16 | VALS(qs_func_vals), QS_FUNC_MASK, NULL, HFILL }}, |
2884 | | |
2885 | 16 | { &hf_ip_opt_qs_rate, |
2886 | 16 | { "Rate", "ip.opt.qs_rate", FT_UINT8, BASE_DEC | BASE_EXT_STRING, |
2887 | 16 | &qs_rate_vals_ext, QS_RATE_MASK, NULL, HFILL }}, |
2888 | | |
2889 | 16 | { &hf_ip_opt_qs_ttl, |
2890 | 16 | { "QS TTL", "ip.opt.qs_ttl", FT_UINT8, BASE_DEC, |
2891 | 16 | NULL, 0x0, NULL, HFILL }}, |
2892 | | |
2893 | 16 | { &hf_ip_opt_qs_ttl_diff, |
2894 | 16 | { "TTL Diff", "ip.opt.qs_ttl_diff", FT_UINT8, BASE_DEC, |
2895 | 16 | NULL, 0x0, NULL, HFILL }}, |
2896 | | |
2897 | 16 | { &hf_ip_opt_qs_unused, |
2898 | 16 | { "Not Used", "ip.opt.qs_unused", FT_UINT8, BASE_DEC, |
2899 | 16 | NULL, 0x0, NULL, HFILL }}, |
2900 | | |
2901 | 16 | { &hf_ip_opt_qs_nonce, |
2902 | 16 | { "QS Nonce", "ip.opt.qs_nonce", FT_UINT32, BASE_HEX, |
2903 | 16 | NULL, 0xFFFFFFFC, NULL, HFILL }}, |
2904 | | |
2905 | 16 | { &hf_ip_opt_qs_reserved, |
2906 | 16 | { "Reserved", "ip.opt.qs_reserved", FT_UINT32, BASE_HEX, |
2907 | 16 | NULL, 0x00000003, NULL, HFILL }}, |
2908 | | |
2909 | 16 | { &hf_ip_opt_sec_rfc791_sec, |
2910 | 16 | { "Security", "ip.opt.sec_rfc791_sec", FT_UINT16, BASE_HEX, |
2911 | 16 | VALS(secl_rfc791_vals), 0x0, NULL, HFILL }}, |
2912 | | |
2913 | 16 | { &hf_ip_opt_sec_rfc791_comp, |
2914 | 16 | { "Compartments", "ip.opt.sec_rfc791_comp", FT_UINT16, BASE_DEC, |
2915 | 16 | NULL, 0x0, NULL, HFILL }}, |
2916 | | |
2917 | 16 | { &hf_ip_opt_sec_rfc791_hr, |
2918 | 16 | { "Handling Restrictions", "ip.opt.sec_rfc791_hr", FT_STRING, BASE_NONE, |
2919 | 16 | NULL, 0x0, NULL, HFILL }}, |
2920 | | |
2921 | 16 | { &hf_ip_opt_sec_rfc791_tcc, |
2922 | 16 | { "Transmission Control Code", "ip.opt.sec_rfc791_tcc", FT_STRING, BASE_NONE, |
2923 | 16 | NULL, 0x0, NULL, HFILL }}, |
2924 | | |
2925 | 16 | { &hf_ip_opt_sec_cl, |
2926 | 16 | { "Classification Level", "ip.opt.sec_cl", FT_UINT8, BASE_HEX, |
2927 | 16 | VALS(sec_cl_vals), 0x0, NULL, HFILL }}, |
2928 | | |
2929 | 16 | { &hf_ip_opt_sec_prot_auth_flags, |
2930 | 16 | { "Protection Authority Flags", "ip.opt.sec_prot_auth_flags", FT_UINT8, BASE_HEX, |
2931 | 16 | NULL, 0x0, NULL, HFILL }}, |
2932 | | |
2933 | 16 | { &hf_ip_opt_sec_prot_auth_genser, |
2934 | 16 | { "GENSER", "ip.opt.sec_prot_auth_genser", FT_BOOLEAN, 8, |
2935 | 16 | TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x80, NULL, HFILL }}, |
2936 | | |
2937 | 16 | { &hf_ip_opt_sec_prot_auth_siop_esi, |
2938 | 16 | { "SIOP-ESI", "ip.opt.sec_prot_auth_siop_esi", FT_BOOLEAN, 8, |
2939 | 16 | TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x40, NULL, HFILL }}, |
2940 | | |
2941 | 16 | { &hf_ip_opt_sec_prot_auth_sci, |
2942 | 16 | { "SCI", "ip.opt.sec_prot_auth_sci", FT_BOOLEAN, 8, |
2943 | 16 | TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x20, NULL, HFILL }}, |
2944 | | |
2945 | 16 | { &hf_ip_opt_sec_prot_auth_nsa, |
2946 | 16 | { "NSA", "ip.opt.sec_prot_auth_nsa", FT_BOOLEAN, 8, |
2947 | 16 | TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x10, NULL, HFILL }}, |
2948 | | |
2949 | 16 | { &hf_ip_opt_sec_prot_auth_doe, |
2950 | 16 | { "DOE", "ip.opt.sec_prot_auth_doe", FT_BOOLEAN, 8, |
2951 | 16 | TFS(&ip_opt_sec_prot_auth_flag_tfs), 0x08, NULL, HFILL }}, |
2952 | | |
2953 | 16 | { &hf_ip_opt_sec_prot_auth_unassigned, |
2954 | 16 | { "Unassigned", "ip.opt.sec_prot_auth_unassigned", FT_UINT8, BASE_HEX, |
2955 | 16 | NULL, 0x06, NULL, HFILL }}, |
2956 | | |
2957 | 16 | { &hf_ip_opt_sec_prot_auth_unassigned2, |
2958 | 16 | { "Unassigned", "ip.opt.sec_prot_auth_unassigned", FT_UINT8, BASE_HEX, |
2959 | 16 | NULL, 0xFE, NULL, HFILL }}, |
2960 | | |
2961 | 16 | { &hf_ip_opt_sec_prot_auth_fti, |
2962 | 16 | { "Field Termination Indicator", "ip.opt.sec_prot_auth_fti", FT_BOOLEAN, 8, |
2963 | 16 | TFS(&ip_opt_sec_prot_auth_fti_tfs), 0x01, NULL, HFILL }}, |
2964 | | |
2965 | 16 | { &hf_ip_opt_ext_sec_add_sec_info_format_code, |
2966 | 16 | { "Additional Security Info Format Code", "ip.opt.ext_sec_add_sec_info_format_code", FT_UINT8, BASE_HEX, |
2967 | 16 | NULL, 0x0, NULL, HFILL }}, |
2968 | | |
2969 | 16 | { &hf_ip_opt_ext_sec_add_sec_info, |
2970 | 16 | { "Additional Security Info", "ip.opt.ext_sec_add_sec_info", FT_BYTES, BASE_NONE, |
2971 | 16 | NULL, 0x0, NULL, HFILL }}, |
2972 | | |
2973 | | /* Cilum DSR */ |
2974 | 16 | { &hf_ip_opt_dsr_cilium_service_port, |
2975 | 16 | { "Service Port", "ip.opt.dsr.cilium.service_port", FT_UINT16, BASE_DEC, |
2976 | 16 | NULL, 0x0, NULL, HFILL }}, |
2977 | | |
2978 | 16 | { &hf_ip_opt_dsr_cilium_service_ip, |
2979 | 16 | { "Service IPv4", "ip.opt.dsr.cilium.service_ip", FT_IPv4, BASE_NONE, |
2980 | 16 | NULL, 0x0, NULL, HFILL }}, |
2981 | | |
2982 | 16 | { &hf_ip_rec_rt, |
2983 | 16 | { "Recorded Route", "ip.rec_rt", FT_IPv4, BASE_NONE, NULL, 0x0, |
2984 | 16 | NULL, HFILL }}, |
2985 | | |
2986 | 16 | { &hf_ip_rec_rt_host, |
2987 | 16 | { "Recorded Route Host", "ip.rec_rt_host", FT_STRING, BASE_NONE, |
2988 | 16 | NULL, 0x0, NULL, HFILL }}, |
2989 | | |
2990 | 16 | { &hf_ip_cur_rt, |
2991 | 16 | { "Current Route", "ip.cur_rt", FT_IPv4, BASE_NONE, NULL, 0x0, |
2992 | 16 | NULL, HFILL }}, |
2993 | | |
2994 | 16 | { &hf_ip_cur_rt_host, |
2995 | 16 | { "Current Route Host", "ip.cur_rt_host", FT_STRING, BASE_NONE, |
2996 | 16 | NULL, 0x0, NULL, HFILL }}, |
2997 | | |
2998 | 16 | { &hf_ip_src_rt, |
2999 | 16 | { "Source Route", "ip.src_rt", FT_IPv4, BASE_NONE, NULL, 0x0, |
3000 | 16 | NULL, HFILL }}, |
3001 | | |
3002 | 16 | { &hf_ip_src_rt_host, |
3003 | 16 | { "Source Route Host", "ip.src_rt_host", FT_STRING, BASE_NONE, |
3004 | 16 | NULL, 0x0, NULL, HFILL }}, |
3005 | | |
3006 | 16 | { &hf_ip_empty_rt, |
3007 | 16 | { "Empty Route", "ip.empty_rt", FT_IPv4, BASE_NONE, NULL, 0x0, |
3008 | 16 | NULL, HFILL }}, |
3009 | | |
3010 | 16 | { &hf_ip_empty_rt_host, |
3011 | 16 | { "Empty Route Host", "ip.empty_rt_host", FT_STRING, BASE_NONE, |
3012 | 16 | NULL, 0x0, NULL, HFILL }}, |
3013 | | |
3014 | 16 | { &hf_ip_cipso_tag_type, |
3015 | 16 | { "Tag Type", "ip.cipso.tag_type", FT_UINT8, BASE_DEC, |
3016 | 16 | VALS(cipso_tag_type_vals), 0x0, NULL, HFILL }}, |
3017 | | |
3018 | | |
3019 | 16 | { &hf_ip_fragment_overlap, |
3020 | 16 | { "Fragment overlap", "ip.fragment.overlap", FT_BOOLEAN, BASE_NONE, |
3021 | 16 | NULL, 0x0, "Fragment overlaps with other fragments", HFILL }}, |
3022 | | |
3023 | 16 | { &hf_ip_fragment_overlap_conflict, |
3024 | 16 | { "Conflicting data in fragment overlap", "ip.fragment.overlap.conflict", |
3025 | 16 | FT_BOOLEAN, BASE_NONE, NULL, 0x0, |
3026 | 16 | "Overlapping fragments contained conflicting data", HFILL }}, |
3027 | | |
3028 | 16 | { &hf_ip_fragment_multiple_tails, |
3029 | 16 | { "Multiple tail fragments found", "ip.fragment.multipletails", |
3030 | 16 | FT_BOOLEAN, BASE_NONE, NULL, 0x0, |
3031 | 16 | "Several tails were found when defragmenting the packet", HFILL }}, |
3032 | | |
3033 | 16 | { &hf_ip_fragment_too_long_fragment, |
3034 | 16 | { "Fragment too long", "ip.fragment.toolongfragment", |
3035 | 16 | FT_BOOLEAN, BASE_NONE, NULL, 0x0, |
3036 | 16 | "Fragment contained data past end of packet", HFILL }}, |
3037 | | |
3038 | 16 | { &hf_ip_fragment_error, |
3039 | 16 | { "Defragmentation error", "ip.fragment.error", FT_FRAMENUM, BASE_NONE, |
3040 | 16 | NULL, 0x0, "Defragmentation error due to illegal fragments", HFILL }}, |
3041 | | |
3042 | 16 | { &hf_ip_fragment_count, |
3043 | 16 | { "Fragment count", "ip.fragment.count", FT_UINT32, BASE_DEC, |
3044 | 16 | NULL, 0x0, NULL, HFILL }}, |
3045 | | |
3046 | 16 | { &hf_ip_fragment, |
3047 | 16 | { "IPv4 Fragment", "ip.fragment", FT_FRAMENUM, BASE_NONE, |
3048 | 16 | NULL, 0x0, NULL, HFILL }}, |
3049 | | |
3050 | 16 | { &hf_ip_fragments, |
3051 | 16 | { "IPv4 Fragments", "ip.fragments", FT_BYTES, BASE_NONE, |
3052 | 16 | NULL, 0x0, NULL, HFILL }}, |
3053 | | |
3054 | 16 | { &hf_ip_reassembled_in, |
3055 | 16 | { "Reassembled IPv4 in frame", "ip.reassembled_in", FT_FRAMENUM, BASE_NONE, |
3056 | 16 | NULL, 0x0, "This IPv4 packet is reassembled in this frame", HFILL }}, |
3057 | | |
3058 | 16 | { &hf_ip_reassembled_length, |
3059 | 16 | { "Reassembled IPv4 length", "ip.reassembled.length", FT_UINT32, BASE_DEC, |
3060 | 16 | NULL, 0x0, "The total length of the reassembled payload", HFILL }}, |
3061 | | |
3062 | 16 | { &hf_ip_reassembled_data, |
3063 | 16 | { "Reassembled IPv4 data", "ip.reassembled.data", FT_BYTES, BASE_NONE, |
3064 | 16 | NULL, 0x0, "The reassembled payload", HFILL }}, |
3065 | | |
3066 | | /* Generated from convert_proto_tree_add_text.pl */ |
3067 | 16 | { &hf_ip_cipso_doi, { "DOI", "ip.cipso.doi", FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
3068 | 16 | { &hf_ip_cipso_sensitivity_level, { "Sensitivity Level", "ip.cipso.sensitivity_level", FT_UINT8, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
3069 | 16 | { &hf_ip_cipso_categories, { "Categories", "ip.cipso.categories", FT_STRING, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
3070 | 16 | { &hf_ip_cipso_tag_data, { "Tag data", "ip.cipso.tag_data", FT_BYTES, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
3071 | 16 | { &hf_ip_opt_overflow, { "Overflow", "ip.opt.overflow", FT_UINT8, BASE_DEC, NULL, 0xF0, NULL, HFILL }}, |
3072 | 16 | { &hf_ip_opt_flag, { "Flag", "ip.opt.flag", FT_UINT8, BASE_HEX, VALS(ipopt_timestamp_flag_vals), 0x0F, NULL, HFILL }}, |
3073 | 16 | { &hf_ip_opt_time_stamp, { "Time stamp", "ip.opt.time_stamp", FT_UINT32, BASE_DEC, NULL, 0x0, NULL, HFILL }}, |
3074 | 16 | { &hf_ip_opt_time_stamp_addr, { "Address", "ip.opt.time_stamp_addr", FT_IPv4, BASE_NONE, NULL, 0x0, NULL, HFILL }}, |
3075 | | |
3076 | 16 | }; |
3077 | | |
3078 | 16 | static int *ett[] = { |
3079 | 16 | &ett_ip, |
3080 | 16 | &ett_ip_dsfield, |
3081 | 16 | &ett_ip_tos, |
3082 | 16 | &ett_ip_flags, |
3083 | 16 | &ett_ip_options, |
3084 | 16 | &ett_ip_option_eool, |
3085 | 16 | &ett_ip_option_nop, |
3086 | 16 | &ett_ip_option_sec, |
3087 | 16 | &ett_ip_option_route, |
3088 | 16 | &ett_ip_option_timestamp, |
3089 | 16 | &ett_ip_option_ext_security, |
3090 | 16 | &ett_ip_option_cipso, |
3091 | 16 | &ett_ip_option_sid, |
3092 | 16 | &ett_ip_option_mtu, |
3093 | 16 | &ett_ip_option_tr, |
3094 | 16 | &ett_ip_option_ra, |
3095 | 16 | &ett_ip_option_sdb, |
3096 | 16 | &ett_ip_option_qs, |
3097 | 16 | &ett_ip_option_dsr, |
3098 | 16 | &ett_ip_option_other, |
3099 | 16 | &ett_ip_fragments, |
3100 | 16 | &ett_ip_fragment, |
3101 | 16 | &ett_ip_opt_type, |
3102 | 16 | &ett_ip_opt_sec_prot_auth_flags, |
3103 | 16 | &ett_ip_unknown_opt, |
3104 | 16 | &ett_geoip_info |
3105 | 16 | }; |
3106 | 16 | static ei_register_info ei[] = { |
3107 | 16 | { &ei_ip_opt_len_invalid, { "ip.opt.len.invalid", PI_PROTOCOL, PI_WARN, "Invalid length for option", EXPFILL }}, |
3108 | 16 | { &ei_ip_opt_deprecated, { "ip.opt.deprecated", PI_DEPRECATED, PI_NOTE, "Option type is deprecated", EXPFILL }}, |
3109 | 16 | { &ei_ip_opt_sec_prot_auth_fti, { "ip.opt.fti_1_last_byte", PI_PROTOCOL, PI_WARN, "Field Termination Indicator set to 1 for last byte of option", EXPFILL }}, |
3110 | 16 | { &ei_ip_extraneous_data, { "ip.opt.len.extra_found", PI_PROTOCOL, PI_WARN, "Extraneous data in option", EXPFILL }}, |
3111 | 16 | { &ei_ip_opt_ptr_before_address, { "ip.opt.ptr.before_address", PI_PROTOCOL, PI_WARN, "Pointer points before first address", EXPFILL }}, |
3112 | 16 | { &ei_ip_opt_ptr_middle_address, { "ip.opt.ptr.middle_address", PI_PROTOCOL, PI_WARN, "Pointer points to middle of address", EXPFILL }}, |
3113 | 16 | { &ei_ip_subopt_too_long, { "ip.subopt_too_long", PI_PROTOCOL, PI_WARN, "Suboption would go past end of option", EXPFILL }}, |
3114 | 16 | { &ei_ip_nop, { "ip.nop", PI_PROTOCOL, PI_WARN, "4 NOP in a row - a router may have removed some options", EXPFILL }}, |
3115 | 16 | { &ei_ip_bogus_ip_length, { "ip.bogus_ip_length", PI_PROTOCOL, PI_ERROR, "Bogus IP length", EXPFILL }}, |
3116 | 16 | { &ei_ip_zero_data_length, { "ip.zero_data_length", PI_PROTOCOL, PI_NOTE, "Empty data packet", EXPFILL }}, |
3117 | 16 | { &ei_ip_evil_packet, { "ip.evil_packet", PI_PROTOCOL, PI_WARN, "Packet has evil intent", EXPFILL }}, |
3118 | 16 | { &ei_ip_checksum_bad, { "ip.checksum_bad.expert", PI_CHECKSUM, PI_ERROR, "Bad checksum", EXPFILL }}, |
3119 | 16 | { &ei_ip_ttl_lncb, { "ip.ttl.lncb", PI_SEQUENCE, PI_NOTE, "Time To Live", EXPFILL }}, |
3120 | 16 | { &ei_ip_ttl_too_small, { "ip.ttl.too_small", PI_SEQUENCE, PI_NOTE, "Time To Live too small", EXPFILL }}, |
3121 | 16 | { &ei_ip_cipso_tag, { "ip.cipso.malformed", PI_SEQUENCE, PI_ERROR, "Malformed CIPSO tag", EXPFILL }}, |
3122 | 16 | { &ei_ip_bogus_ip_version, { "ip.bogus_ip_version", PI_PROTOCOL, PI_ERROR, "Bogus IP version", EXPFILL }}, |
3123 | 16 | { &ei_ip_bogus_header_length, { "ip.bogus_header_length", PI_PROTOCOL, PI_ERROR, "Bogus IP header length", EXPFILL }}, |
3124 | 16 | { &ei_ip_reserved_bit_set, { "ip.flags.rb.set", PI_PROTOCOL, PI_WARN, "Reserved bit is set (must be zero)", EXPFILL }}, |
3125 | 16 | }; |
3126 | | |
3127 | | /* Decode As handling */ |
3128 | 16 | static build_valid_func ip_da_build_value[1] = {ip_value}; |
3129 | 16 | static decode_as_value_t ip_da_values = {ip_prompt, 1, ip_da_build_value}; |
3130 | 16 | static decode_as_t ip_da = {"ip", "ip.proto", 1, 0, &ip_da_values, NULL, NULL, |
3131 | 16 | decode_as_default_populate_list, decode_as_default_reset, decode_as_default_change, NULL, NULL, NULL }; |
3132 | | |
3133 | 16 | module_t *ip_module; |
3134 | 16 | expert_module_t* expert_ip; |
3135 | | |
3136 | 16 | proto_ip = proto_register_protocol("Internet Protocol Version 4", "IPv4", "ip"); |
3137 | 16 | proto_register_field_array(proto_ip, hf, array_length(hf)); |
3138 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
3139 | 16 | expert_ip = expert_register_protocol(proto_ip); |
3140 | 16 | expert_register_field_array(expert_ip, ei, array_length(ei)); |
3141 | | |
3142 | | /* subdissector code */ |
3143 | 16 | ip_dissector_table = register_dissector_table("ip.proto", "IP protocol", |
3144 | 16 | proto_ip, FT_UINT8, BASE_DEC); |
3145 | 16 | ip_option_table = register_dissector_table("ip.option", "IP Options", |
3146 | 16 | proto_ip, FT_UINT8, BASE_DEC); |
3147 | 16 | heur_subdissector_list = register_heur_dissector_list_with_description("ip", "IPv4 heuristic", proto_ip); |
3148 | 16 | register_capture_dissector_table("ip.proto", "IP protocol"); |
3149 | | |
3150 | | /* Register configuration options */ |
3151 | 16 | ip_module = prefs_register_protocol(proto_ip, NULL); |
3152 | 16 | prefs_register_bool_preference(ip_module, "decode_tos_as_diffserv", |
3153 | 16 | "Decode IPv4 TOS field as DiffServ field", |
3154 | 16 | "Whether the IPv4 type-of-service field should be decoded as a " |
3155 | 16 | "Differentiated Services field (see RFC2474/RFC2475)", &g_ip_dscp_actif); |
3156 | 16 | prefs_register_bool_preference(ip_module, "defragment", |
3157 | 16 | "Reassemble fragmented IPv4 datagrams", |
3158 | 16 | "Whether fragmented IPv4 datagrams should be reassembled", &ip_defragment); |
3159 | 16 | prefs_register_bool_preference(ip_module, "summary_in_tree", |
3160 | 16 | "Show IPv4 summary in protocol tree", |
3161 | 16 | "Whether the IPv4 summary line should be shown in the protocol tree", |
3162 | 16 | &ip_summary_in_tree); |
3163 | 16 | prefs_register_bool_preference(ip_module, "check_checksum", |
3164 | 16 | "Validate the IPv4 checksum if possible", |
3165 | 16 | "Whether to validate the IPv4 checksum", &ip_check_checksum); |
3166 | 16 | prefs_register_bool_preference(ip_module, "tso_support", |
3167 | 16 | "Support packet-capture from IP TSO-enabled hardware", |
3168 | 16 | "Whether to correct for TSO-enabled (TCP segmentation offload) hardware " |
3169 | 16 | "captures, such as spoofing the IP packet length", &ip_tso_supported); |
3170 | | |
3171 | 16 | prefs_register_obsolete_preference(ip_module, "use_geoip"); |
3172 | 16 | prefs_register_bool_preference(ip_module, "security_flag" , |
3173 | 16 | "Interpret Reserved flag as Security flag (RFC 3514)", |
3174 | 16 | "Whether to interpret the originally reserved flag as security flag", |
3175 | 16 | &ip_security_flag); |
3176 | 16 | prefs_register_bool_preference(ip_module, "try_heuristic_first", |
3177 | 16 | "Try heuristic sub-dissectors first", |
3178 | 16 | "Try to decode a packet using an heuristic sub-dissector before using a sub-dissector registered to a specific port", |
3179 | 16 | &try_heuristic_first); |
3180 | | |
3181 | 16 | prefs_register_bool_preference(ip_module, "conv_id", |
3182 | 16 | "Assign IPv4 conversation IDs", |
3183 | 16 | "Whether to assign unique numbers to each IPv4 conversation (increases resource consumption)", |
3184 | 16 | &ip_track_conv_id); |
3185 | | |
3186 | 16 | prefs_register_bool_preference(ip_module, "conv_agg_flag" , |
3187 | 16 | "Aggregate subnets in Statistics Dialogs", |
3188 | 16 | "Whether to group conversations based on the subnets file; requires \"Assign IPv4 conversation IDs\"", |
3189 | 16 | &ip_conv_agg_flag); |
3190 | | |
3191 | 16 | prefs_register_static_text_preference(ip_module, "text_use_geoip", |
3192 | 16 | "IP geolocation settings can be changed in the Name Resolution preferences", |
3193 | 16 | "IP geolocation settings can be changed in the Name Resolution preferences"); |
3194 | | |
3195 | 16 | register_init_routine(ip_init); |
3196 | | |
3197 | 16 | ip_handle = register_dissector("ip", dissect_ip, proto_ip); |
3198 | 16 | ipv4_handle = register_dissector("ipv4", dissect_ip_v4, proto_ip); |
3199 | 16 | reassembly_table_register(&ip_reassembly_table, |
3200 | 16 | &addresses_reassembly_table_functions); |
3201 | 16 | ip_tap = register_tap("ip"); |
3202 | | |
3203 | | /* This needs a different (& more user-friendly) name than the other tap */ |
3204 | 16 | exported_pdu_tap = register_export_pdu_tap_with_encap("IP", WTAP_ENCAP_RAW_IP); |
3205 | | |
3206 | 16 | register_decode_as(&ip_da); |
3207 | 16 | register_conversation_table(proto_ip, true, ip_conversation_packet, ip_endpoint_packet); |
3208 | 16 | register_conversation_filter("ip", "IPv4", ip_filter_valid, ip_build_filter, NULL); |
3209 | | |
3210 | 16 | ip_cap_handle = register_capture_dissector("ip", capture_ip, proto_ip); |
3211 | | |
3212 | | /* Register IP options as their own protocols so we can get the name of the option */ |
3213 | 16 | proto_ip_option_eol = proto_register_protocol_in_name_only("IP Option - End of Options List (EOL)", "End of Options List (EOL)", "ip.options.eol", proto_ip, FT_BYTES); |
3214 | 16 | proto_ip_option_nop = proto_register_protocol_in_name_only("IP Option - No-Operation (NOP)", "No Operation (NOP)", "ip.options.nop", proto_ip, FT_BYTES); |
3215 | 16 | proto_ip_option_security = proto_register_protocol_in_name_only("IP Option - Security", "Security", "ip.options.security", proto_ip, FT_BYTES); |
3216 | 16 | proto_ip_option_route = proto_register_protocol_in_name_only("IP Option - Loose Source Route", "Loose Source Route", "ip.options.route", proto_ip, FT_BYTES); |
3217 | 16 | proto_ip_option_timestamp = proto_register_protocol_in_name_only("IP Option - Time Stamp", "Time Stamp", "ip.options.timestamp", proto_ip, FT_BYTES); |
3218 | 16 | proto_ip_option_ext_security = proto_register_protocol_in_name_only("IP Option - Extended Security", "Extended Security", "ip.options.ext_security", proto_ip, FT_BYTES); |
3219 | 16 | proto_ip_option_cipso = proto_register_protocol_in_name_only("IP Option - Commercial Security", "Commercial Security", "ip.options.cipso", proto_ip, FT_BYTES); |
3220 | 16 | proto_ip_option_record_route = proto_register_protocol_in_name_only("IP Option - Record Route", "Record Route", "ip.options.record_route", proto_ip, FT_BYTES); |
3221 | 16 | proto_ip_option_sid = proto_register_protocol_in_name_only("IP Option - Stream ID", "Stream ID", "ip.options.sid", proto_ip, FT_BYTES); |
3222 | 16 | proto_ip_option_source_route = proto_register_protocol_in_name_only("IP Option - Strict Source Route", "Strict Source Route", "ip.options.source_route", proto_ip, FT_BYTES); |
3223 | 16 | proto_ip_option_mtu_probe = proto_register_protocol_in_name_only("IP Option - MTU Probe", "MTU Probe", "ip.options.mtu_probe", proto_ip, FT_BYTES); |
3224 | 16 | proto_ip_option_mtu_reply = proto_register_protocol_in_name_only("IP Option - MTU Reply", "MTU Reply", "ip.options.mtu_reply", proto_ip, FT_BYTES); |
3225 | 16 | proto_ip_option_traceroute = proto_register_protocol_in_name_only("IP Option - Traceroute", "Traceroute", "ip.options.traceroute", proto_ip, FT_BYTES); |
3226 | 16 | proto_ip_option_routeralert = proto_register_protocol_in_name_only("IP Option - Router Alert", "Router Alert", "ip.options.routeralert", proto_ip, FT_BYTES); |
3227 | 16 | proto_ip_option_sdb = proto_register_protocol_in_name_only("IP Option - Selective Directed Broadcast", "Selective Directed Broadcast", "ip.options.sdb", proto_ip, FT_BYTES); |
3228 | 16 | proto_ip_option_qs = proto_register_protocol_in_name_only("IP Option - Quick-Start", "Quick-Start", "ip.options.qs", proto_ip, FT_BYTES); |
3229 | 16 | proto_ip_option_dsr = proto_register_protocol_in_name_only("IP Option - Cilium DSR", "Cilium DSR", "ip.options.dsr", proto_ip, FT_BYTES); |
3230 | 16 | } |
3231 | | |
3232 | | void |
3233 | | proto_reg_handoff_ip(void) |
3234 | 16 | { |
3235 | 16 | capture_dissector_handle_t clip_cap_handle; |
3236 | 16 | int proto_clip; |
3237 | | |
3238 | 16 | ipv6_handle = find_dissector("ipv6"); |
3239 | | |
3240 | 16 | dissector_add_uint("ethertype", ETHERTYPE_IP, ipv4_handle); |
3241 | 16 | dissector_add_uint("erf.types.type", ERF_TYPE_IPV4, ip_handle); |
3242 | 16 | dissector_add_uint("ppp.protocol", PPP_IP, ip_handle); |
3243 | 16 | dissector_add_uint("ppp.protocol", ETHERTYPE_IP, ip_handle); |
3244 | 16 | dissector_add_uint("gre.proto", ETHERTYPE_IP, ip_handle); |
3245 | 16 | dissector_add_uint("gre.proto", GRE_WCCP, ip_handle); |
3246 | 16 | dissector_add_uint("llc.dsap", SAP_IP, ip_handle); |
3247 | 16 | dissector_add_uint("ip.proto", IP_PROTO_IPV4, ip_handle); |
3248 | 16 | dissector_add_uint("null.type", BSD_AF_INET, ip_handle); |
3249 | 16 | dissector_add_uint("chdlc.protocol", ETHERTYPE_IP, ip_handle); |
3250 | 16 | dissector_add_uint("osinl.excl", NLPID_IP, ip_handle); |
3251 | 16 | dissector_add_uint("fr.nlpid", NLPID_IP, ip_handle); |
3252 | 16 | dissector_add_uint("x.25.spi", NLPID_IP, ip_handle); |
3253 | 16 | dissector_add_uint("arcnet.protocol_id", ARCNET_PROTO_IP_1051, ip_handle); |
3254 | 16 | dissector_add_uint("arcnet.protocol_id", ARCNET_PROTO_IP_1201, ip_handle); |
3255 | 16 | dissector_add_uint("ax25.pid", AX25_P_IP, ip_handle); |
3256 | 16 | dissector_add_uint("juniper.proto", JUNIPER_PROTO_IP, ip_handle); |
3257 | 16 | dissector_add_uint("juniper.proto", JUNIPER_PROTO_MPLS_IP, ip_handle); |
3258 | 16 | dissector_add_uint("pwach.channel_type", PW_ACH_TYPE_IPV4, ip_handle); |
3259 | 16 | dissector_add_uint("mcc.proto", PW_ACH_TYPE_IPV4, ip_handle); |
3260 | 16 | dissector_add_uint("sflow_245.header_protocol", SFLOW_245_HEADER_IPv4, ip_handle); |
3261 | 16 | dissector_add_uint("l2tp.pw_type", L2TPv3_PW_IP, ip_handle); |
3262 | 16 | dissector_add_for_decode_as_with_preference("udp.port", ip_handle); |
3263 | 16 | dissector_add_for_decode_as("pcli.payload", ip_handle); |
3264 | 16 | dissector_add_uint("enc", BSD_AF_INET, ip_handle); |
3265 | 16 | dissector_add_uint("vxlan.next_proto", VXLAN_IPV4, ip_handle); |
3266 | 16 | dissector_add_uint("nsh.next_proto", NSH_IPV4, ip_handle); |
3267 | | |
3268 | 16 | heur_dissector_add("tipc", dissect_ip_heur, "IP over TIPC", "ip_tipc", proto_ip, HEURISTIC_ENABLE); |
3269 | 16 | heur_dissector_add("zbee_zcl_se.tun", dissect_ip_heur, "IP over ZigBee SE Tunneling", "ip_zbee_zcl_se.tun", proto_ip, HEURISTIC_ENABLE); |
3270 | 16 | heur_dissector_add("gtp.tpdu", dissect_ip_heur, "IP over GTP", "ip_gtp.tpdu", proto_ip, HEURISTIC_ENABLE); |
3271 | | |
3272 | 16 | capture_dissector_add_uint("ethertype", ETHERTYPE_IP, ip_cap_handle); |
3273 | 16 | capture_dissector_add_uint("ax25.pid", AX25_P_IP, ip_cap_handle); |
3274 | 16 | capture_dissector_add_uint("enc", BSD_AF_INET, ip_cap_handle); |
3275 | 16 | capture_dissector_add_uint("ppp_hdlc", PPP_IP, ip_cap_handle); |
3276 | 16 | capture_dissector_add_uint("llc.dsap", SAP_IP, ip_cap_handle); |
3277 | 16 | capture_dissector_add_uint("null.bsd", BSD_AF_INET, ip_cap_handle); |
3278 | 16 | capture_dissector_add_uint("fr.nlpid", NLPID_IP, ip_cap_handle); |
3279 | | |
3280 | | /* Create dissection function handles for all IP options */ |
3281 | 16 | dissector_add_uint("ip.option", IPOPT_SEC, create_dissector_handle( dissect_ipopt_security, proto_ip_option_security )); |
3282 | 16 | dissector_add_uint("ip.option", IPOPT_LSR, create_dissector_handle( dissect_ipopt_loose_route, proto_ip_option_route )); |
3283 | 16 | dissector_add_uint("ip.option", IPOPT_TS, create_dissector_handle( dissect_ipopt_timestamp, proto_ip_option_timestamp )); |
3284 | 16 | dissector_add_uint("ip.option", IPOPT_ESEC, create_dissector_handle( dissect_ipopt_ext_security, proto_ip_option_ext_security )); |
3285 | 16 | dissector_add_uint("ip.option", IPOPT_CIPSO, create_dissector_handle( dissect_ipopt_cipso, proto_ip_option_cipso )); |
3286 | 16 | dissector_add_uint("ip.option", IPOPT_RR, create_dissector_handle( dissect_ipopt_record_route, proto_ip_option_record_route )); |
3287 | 16 | dissector_add_uint("ip.option", IPOPT_SID, create_dissector_handle( dissect_ipopt_sid, proto_ip_option_sid )); |
3288 | 16 | dissector_add_uint("ip.option", IPOPT_SSR, create_dissector_handle( dissect_ipopt_source_route, proto_ip_option_source_route )); |
3289 | 16 | dissector_add_uint("ip.option", IPOPT_MTUP, create_dissector_handle( dissect_ipopt_mtu_probe, proto_ip_option_mtu_probe )); |
3290 | 16 | dissector_add_uint("ip.option", IPOPT_MTUR, create_dissector_handle( dissect_ipopt_mtu_reply, proto_ip_option_mtu_reply )); |
3291 | 16 | dissector_add_uint("ip.option", IPOPT_TR, create_dissector_handle( dissect_ipopt_tr, proto_ip_option_traceroute )); |
3292 | 16 | dissector_add_uint("ip.option", IPOPT_RTRALT, create_dissector_handle( dissect_ipopt_ra, proto_ip_option_routeralert )); |
3293 | 16 | dissector_add_uint("ip.option", IPOPT_SDB, create_dissector_handle( dissect_ipopt_sdb, proto_ip_option_sdb )); |
3294 | 16 | dissector_add_uint("ip.option", IPOPT_QS, create_dissector_handle( dissect_ipopt_qs, proto_ip_option_qs )); |
3295 | 16 | dissector_add_uint("ip.option", IPOPT_DSR, create_dissector_handle( dissect_ipopt_cilium_dsr, proto_ip_option_dsr )); |
3296 | | |
3297 | | /* Classic IP uses the same capture function, but wants its own |
3298 | | protocol associated with it. To eliminate linking dependencies, |
3299 | | just add it here */ |
3300 | 16 | proto_clip = proto_get_id_by_filter_name( "clip" ); |
3301 | 16 | clip_cap_handle = register_capture_dissector("clip", capture_ip, proto_clip); |
3302 | 16 | capture_dissector_add_uint("wtap_encap", WTAP_ENCAP_LINUX_ATM_CLIP, clip_cap_handle); |
3303 | 16 | } |
3304 | | |
3305 | | /* |
3306 | | * Editor modelines - https://www.wireshark.org/tools/modelines.html |
3307 | | * |
3308 | | * Local variables: |
3309 | | * c-basic-offset: 2 |
3310 | | * tab-width: 8 |
3311 | | * indent-tabs-mode: nil |
3312 | | * End: |
3313 | | * |
3314 | | * vi: set shiftwidth=2 tabstop=8 expandtab: |
3315 | | * :indentSize=2:tabSize=8:noTabs=true: |
3316 | | */ |