/src/wireshark/epan/dissectors/packet-log3gpp.c
Line | Count | Source |
1 | | /* packet-log3gpp.c |
2 | | * Routines for dissecting phone logs containing 3GPP protocol messages. |
3 | | * Copyright 2008, Vincent Helfre |
4 | | * |
5 | | * Wireshark - Network traffic analyzer |
6 | | * By Gerald Combs <gerald@wireshark.org> |
7 | | * Copyright 1998 Gerald Combs |
8 | | * |
9 | | * SPDX-License-Identifier: GPL-2.0-or-later |
10 | | */ |
11 | | |
12 | | #include "config.h" |
13 | | |
14 | | #include <epan/packet.h> |
15 | | #include <epan/prefs.h> |
16 | | #include <epan/proto_data.h> |
17 | | #include <wiretap/wtap.h> |
18 | | #include <wsutil/strtoi.h> |
19 | | #include <wsutil/array.h> |
20 | | |
21 | | #include "packet-mac-lte.h" |
22 | | #include "packet-pdcp-lte.h" |
23 | | #include "packet-rlc-lte.h" |
24 | | |
25 | 0 | #define FD1 0 |
26 | 32 | #define REL8 1 |
27 | | |
28 | | void proto_register_log3gpp(void); |
29 | | void proto_reg_handoff_log3gpp(void); |
30 | | |
31 | | /* Protocol and registered fields. */ |
32 | | static int proto_log3gpp; |
33 | | |
34 | | |
35 | | static int hf_log3gpp_timestamp; |
36 | | static int hf_log3gpp_protocol; |
37 | | static int hf_log3gpp_direction; |
38 | | static int hf_log3gpp_dissector_option; |
39 | | static int hf_log3gpp_unparsed_data; |
40 | | static int hf_log3gpp_dissected_length; |
41 | | |
42 | | /* Protocol subtree. */ |
43 | | static int ett_log3gpp; |
44 | | |
45 | | /* Cached protocol identifiers */ |
46 | | static int proto_mac_lte; |
47 | | static int proto_rlc_lte; |
48 | | static int proto_pdcp_lte; |
49 | | |
50 | | |
51 | | /* Variables used to select a version for RRC and NAS */ |
52 | | static int lte_rrc_prot_version = REL8; |
53 | | static int nas_eps_prot_version = REL8; |
54 | | |
55 | | static const enum_val_t lte_rrc_dissector_version[] = { |
56 | | {"FD1", "FD1", FD1}, |
57 | | {"Rel8", "Rel8 dec 2008", REL8}, /* Add new dissector version after */ |
58 | | {NULL, NULL, -1} |
59 | | }; |
60 | | |
61 | | static const enum_val_t nas_eps_dissector_version[] = { |
62 | | {"FD1", "FD1", FD1}, |
63 | | {"Rel8", "Rel8 dec 2008", REL8}, /* Add new dissector version after */ |
64 | | {NULL, NULL, -1} |
65 | | }; |
66 | | |
67 | | typedef enum packet_direction_t |
68 | | { |
69 | | UPLINK, |
70 | | DOWNLINK |
71 | | } packet_direction_t; |
72 | | |
73 | | static const value_string direction_vals[] = { |
74 | | { 0, "Uplink" }, |
75 | | { 1, "Downlink" }, |
76 | | { 0, NULL }, |
77 | | }; |
78 | | /* Pseudo header functions*/ |
79 | | typedef bool (*pseudo_hdr_func_ptr_t) (char *, packet_info *pinfo, uint16_t, packet_direction_t); |
80 | | |
81 | | static bool lte_mac_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t); |
82 | | static bool lte_rlc_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t); |
83 | | static bool lte_pdcp_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t); |
84 | | |
85 | | typedef struct |
86 | | { |
87 | | const char * protocol_name; |
88 | | const char * ul_dissector_name; |
89 | | const char * dl_dissector_name; |
90 | | dissector_handle_t ul_dissector_handle; |
91 | | dissector_handle_t dl_dissector_handle; |
92 | | pseudo_hdr_func_ptr_t hdr_process; |
93 | | } lookup_dissector_element_t; |
94 | | |
95 | | /* Look up table for protocol name /dissector: should be in alphabetic order!!! |
96 | | the purpose is to match a protocol name with a dissector, |
97 | | and to store the dissector handle the first time to avoid looking it up every time. |
98 | | This table should contain all 3GPP specified protocols */ |
99 | | static lookup_dissector_element_t dissector_lookup_table[] = { |
100 | | {"DATA","data","data",0,0,NULL}, |
101 | | {"GAN.TCP","umatcp","umatcp",0,0,NULL}, |
102 | | {"GAN.UDP","umaudp","umaudp",0,0,NULL}, |
103 | | {"GSM.CCCH","gsm_a_ccch","gsm_a_ccch",0,0,NULL}, |
104 | | {"GSM.SACCH","gsm_a_sacch","gsm_a_sacch",0,0,NULL}, |
105 | | {"GTP","gtp","gtp",0,0,NULL}, |
106 | | {"LLC","llcgprs","llcgprs",0,0,NULL}, |
107 | | {"LTE-MAC","mac-lte","mac-lte",0,0, lte_mac_pseudo_hdr}, |
108 | | {"LTE-PDCP","pdcp-lte","pdcp-lte",0,0, lte_pdcp_pseudo_hdr}, |
109 | | {"LTE-RLC","rlc-lte","rlc-lte",0,0, lte_rlc_pseudo_hdr}, |
110 | | {"LTE-RRC.BCCH.BCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
111 | | {"LTE-RRC.BCCH.DL.SCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
112 | | {"LTE-RRC.CCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
113 | | {"LTE-RRC.DCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
114 | | {"LTE-RRC.PCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
115 | | {"NAS","gsm_a_dtap","gsm_a_dtap",0,0,NULL}, |
116 | | {"NAS-EPS",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */ |
117 | | {"RR","gsm_a_dtap","gsm_a_dtap",0,0,NULL}, |
118 | | {"RRC.BCCH.BCH","rrc.bcch.bch","rrc.bcch.bch",0,0,NULL}, |
119 | | {"RRC.BCCH.FACH","rrc.bcch.fach","rrc.bcch.fach",0,0,NULL}, |
120 | | {"RRC.CCCH","rrc.ul.ccch","rrc.dl.ccch",0,0,NULL}, |
121 | | {"RRC.DCCH","rrc.ul.dcch","rrc.dl.dcch",0,0,NULL}, |
122 | | {"RRC.MCCH","rrc.mcch","rrc.mcch",0,0,NULL}, |
123 | | {"RRC.MSCH","rrc.msch","rrc.msch",0,0,NULL}, |
124 | | {"RRC.PCCH","rrc.pcch","rrc.pcch",0,0,NULL}, |
125 | | {"RRC.SHCCH","rrc.ul.shcch","rrc.dl.shcch",0,0,NULL}, |
126 | | {"RRC.SI.MIB","rrc.si.mib","rrc.si.mib",0,0,NULL}, |
127 | | {"RRC.SI.SB1","rrc.sb1","rrc.sb1",0,0,NULL}, |
128 | | {"RRC.SI.SB2","rrc.sb2","rrc.sb2",0,0,NULL}, |
129 | | {"RRC.SI.SIB1","rrc.si.sib1","rrc.si.sib1",0,0,NULL}, |
130 | | {"RRC.SI.SIB10","rrc.si.sib10","rrc.si.sib10",0,0,NULL}, |
131 | | {"RRC.SI.SIB11","rrc.si.sib11","rrc.si.sib11",0,0,NULL}, |
132 | | {"RRC.SI.SIB11bis","rrc.si.sib11bis","rrc.si.sib11bis",0,0,NULL}, |
133 | | {"RRC.SI.SIB12","rrc.si.sib12","rrc.si.sib12",0,0,NULL}, |
134 | | {"RRC.SI.SIB13","rrc.si.sib13","rrc.si.sib13",0,0,NULL }, |
135 | | {"RRC.SI.SIB13-1","rrc.si.sib13-1","rrc.si.sib13-1",0,0,NULL}, |
136 | | {"RRC.SI.SIB13-2","rrc.si.sib13-2","rrc.si.sib13-2",0,0,NULL}, |
137 | | {"RRC.SI.SIB13-3","rrc.si.sib13-3","rrc.si.sib13-3",0,0,NULL }, |
138 | | {"RRC.SI.SIB13-4","rrc.si.sib13-4","rrc.si.sib13-4",0,0,NULL}, |
139 | | {"RRC.SI.SIB14","rrc.si.sib14","rrc.si.sib14",0,0,NULL}, |
140 | | {"RRC.SI.SIB15","rrc.si.sib15","rrc.si.sib15",0,0,NULL}, |
141 | | {"RRC.SI.SIB15bis","rrc.si.sib15bis","rrc.si.sib15bis",0,0,NULL}, |
142 | | {"RRC.SI.SIB15-1","rrc.si.sib15-1","rrc.si.sib15-1",0,0,NULL}, |
143 | | {"RRC.SI.SIB15-1bis","rrc.si.sib15-1bis","rrc.si.sib15-1bis",0,0,NULL }, |
144 | | {"RRC.SI.SIB15-2","rrc.si.sib15-2","rrc.si.sib15-2",0,0,NULL}, |
145 | | {"RRC.SI.SIB15-2bis","rrc.si.sib15-2bis","rrc.si.sib15-2bis",0,0,NULL}, |
146 | | {"RRC.SI.SIB15-3","rrc.si.sib15-3","rrc.si.sib15-3",0,0,NULL}, |
147 | | {"RRC.SI.SIB15-3bis","rrc.si.sib15-3bis","rrc.si.sib15-3bis",0,0,NULL}, |
148 | | {"RRC.SI.SIB15-4","rrc.si.sib15-4","rrc.si.sib15-4",0,0,NULL}, |
149 | | {"RRC.SI.SIB15-5","rrc.si.sib15-5","rrc.si.sib15-5",0,0,NULL}, |
150 | | {"RRC.SI.SIB15-6","rrc.si.sib15-6","rrc.si.sib15-6",0,0,NULL}, |
151 | | {"RRC.SI.SIB15-7","rrc.si.sib15-7","rrc.si.sib15-7",0,0,NULL}, |
152 | | {"RRC.SI.SIB15-8","rrc.si.sib15-8","rrc.si.sib15-8",0,0,NULL}, |
153 | | {"RRC.SI.SIB18","rrc.si.sib18","rrc.si.sib18",0,0,NULL}, |
154 | | {"RRC.SI.SIB17","rrc.si.sib17","rrc.si.sib17",0,0,NULL}, |
155 | | {"RRC.SI.SIB18","rrc.si.sib18","rrc.si.sib18",0,0,NULL}, |
156 | | {"RRC.SI.SIB2","rrc.si.sib2","rrc.si.sib2",0,0,NULL}, |
157 | | {"RRC.SI.SIB3","rrc.si.sib3","rrc.si.sib3",0,0,NULL}, |
158 | | {"RRC.SI.SIB4","rrc.si.sib4","rrc.si.sib4",0,0,NULL}, |
159 | | {"RRC.SI.SIB5","rrc.si.sib5","rrc.si.sib5",0,0,NULL}, |
160 | | {"RRC.SI.SIB5bis","rrc.si.sib5bis","rrc.si.sib5bis",0,0,NULL}, |
161 | | {"RRC.SI.SIB6","rrc.si.sib6","rrc.si.sib6",0,0,NULL}, |
162 | | {"RRC.SI.SIB7","rrc.si.sib7","rrc.si.sib7",0,0,NULL}, |
163 | | {"RRC.SI.SIB8","rrc.si.sib8","rrc.si.sib8",0,0,NULL}, |
164 | | {"RRC.SI.SIB9","rrc.si.sib9","rrc.si.sib9",0,0,NULL}, |
165 | | {"SNDCP","sndcp","sndcp",0,0,NULL}, |
166 | | {"SNDCPXID","sndcpxid","sndcpxid",0,0,NULL} |
167 | | }; |
168 | | |
169 | | |
170 | | static int |
171 | | dissector_element_compare(const void *protocol_name, const void *element) |
172 | 896 | { |
173 | 896 | return strcmp((const char *)protocol_name, ((const lookup_dissector_element_t *) element)->protocol_name); |
174 | 896 | } |
175 | | |
176 | | static dissector_handle_t |
177 | | look_for_dissector(char* protocol_name, packet_direction_t direction, pseudo_hdr_func_ptr_t* func_ptr _U_) |
178 | 0 | { |
179 | 0 | lookup_dissector_element_t* element_ptr; |
180 | 0 | dissector_handle_t dissector_handle = NULL; |
181 | |
|
182 | 0 | element_ptr = (lookup_dissector_element_t*)bsearch((void*)protocol_name, |
183 | 0 | (void*)dissector_lookup_table, |
184 | 0 | array_length(dissector_lookup_table), |
185 | 0 | sizeof dissector_lookup_table[0], |
186 | 0 | dissector_element_compare); |
187 | 0 | if (element_ptr != NULL) { |
188 | 0 | if (direction == UPLINK) |
189 | 0 | { |
190 | 0 | if (element_ptr->ul_dissector_handle == 0) |
191 | 0 | { |
192 | 0 | element_ptr->ul_dissector_handle = find_dissector(element_ptr->ul_dissector_name); |
193 | 0 | } |
194 | 0 | dissector_handle = element_ptr->ul_dissector_handle; |
195 | 0 | } |
196 | 0 | else |
197 | 0 | { |
198 | 0 | if (element_ptr->dl_dissector_handle == 0) |
199 | 0 | { |
200 | 0 | element_ptr->dl_dissector_handle = find_dissector(element_ptr->dl_dissector_name); |
201 | 0 | } |
202 | 0 | dissector_handle = element_ptr->dl_dissector_handle; |
203 | 0 | } |
204 | |
|
205 | 0 | } |
206 | |
|
207 | 0 | return dissector_handle; |
208 | 0 | } |
209 | | |
210 | | static void |
211 | | update_dissector_name(const char* protocol_name, packet_direction_t direction, const char* dissector_name) |
212 | 192 | { |
213 | 192 | lookup_dissector_element_t* element_ptr; |
214 | | |
215 | 192 | element_ptr = (lookup_dissector_element_t*)bsearch((void*)protocol_name, |
216 | 192 | (void*)dissector_lookup_table, |
217 | 192 | array_length(dissector_lookup_table), |
218 | 192 | sizeof dissector_lookup_table[0], |
219 | 192 | dissector_element_compare); |
220 | 192 | if (element_ptr != NULL) { |
221 | 192 | if (direction == UPLINK) |
222 | 96 | { |
223 | 96 | element_ptr->ul_dissector_handle = 0; |
224 | 96 | element_ptr->ul_dissector_name = dissector_name; |
225 | 96 | } |
226 | 96 | else |
227 | 96 | { |
228 | 96 | element_ptr->dl_dissector_handle = 0; |
229 | 96 | element_ptr->dl_dissector_name = dissector_name; |
230 | 96 | } |
231 | | |
232 | 192 | } |
233 | 192 | } |
234 | | |
235 | | /******************************************************************************/ |
236 | | /* pseudo header functions: used for the dissectors that needs pseudo headers */ |
237 | | /******************************************************************************/ |
238 | | |
239 | | |
240 | | /* In the optional string, MAC info should be set as follow (M = mandatory, O = optional): |
241 | | * Radio type (M): "FDD" or "TDD" |
242 | | * RNTI type (M): "NO_RNTI" or "P_RNTI" or "RA_RNTI" or "C_RNTI" or "SI_RNT" followed by rnti value in decimal format |
243 | | * subframe number (M): "SFN" followed by the subframe number in decimal format |
244 | | */ |
245 | | static bool |
246 | | lte_mac_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length, packet_direction_t direction) |
247 | 0 | { |
248 | 0 | struct mac_lte_info* p_mac_lte_info; |
249 | 0 | char* par_opt_field; |
250 | 0 | char option[30]; |
251 | | |
252 | | /* Need to copy the string in a local buffer since strtok will modify it */ |
253 | 0 | (void) g_strlcpy(option, option_str, 30); |
254 | | |
255 | | /* Only need to set info once per session. */ |
256 | 0 | p_mac_lte_info = (struct mac_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_mac_lte, 0); |
257 | 0 | if (p_mac_lte_info != NULL) |
258 | 0 | { |
259 | 0 | return 1; |
260 | 0 | } |
261 | | |
262 | | /* Allocate & zero struct */ |
263 | 0 | p_mac_lte_info = (struct mac_lte_info*) wmem_new0(pinfo->pool, mac_lte_info); |
264 | | |
265 | | /* First mandatory parameter */ |
266 | 0 | par_opt_field = strtok(option, " "); |
267 | 0 | if (par_opt_field == NULL) |
268 | 0 | { |
269 | 0 | return 0; |
270 | 0 | } |
271 | 0 | if (strcmp(par_opt_field, "FDD") == 0) |
272 | 0 | { |
273 | 0 | p_mac_lte_info->radioType = FDD_RADIO; |
274 | 0 | } |
275 | 0 | else if (strcmp(par_opt_field, "TDD") == 0) |
276 | 0 | { |
277 | 0 | p_mac_lte_info->radioType = TDD_RADIO; |
278 | 0 | } |
279 | 0 | else |
280 | 0 | { |
281 | 0 | return 0; |
282 | 0 | } |
283 | | |
284 | | /* Second mandatory parameter */ |
285 | 0 | par_opt_field = strtok(NULL, " "); |
286 | 0 | if (par_opt_field == NULL) |
287 | 0 | { |
288 | 0 | return 0; |
289 | 0 | } |
290 | 0 | if (strcmp(par_opt_field, "NO_RNTI") == 0) |
291 | 0 | { |
292 | 0 | p_mac_lte_info->rntiType = NO_RNTI; |
293 | 0 | } |
294 | 0 | else if (strcmp(par_opt_field, "P_RNTI") == 0) |
295 | 0 | { |
296 | 0 | p_mac_lte_info->rntiType = P_RNTI; |
297 | 0 | } |
298 | 0 | else if (strcmp(par_opt_field, "RA_RNTI") == 0) |
299 | 0 | { |
300 | 0 | p_mac_lte_info->rntiType = RA_RNTI; |
301 | 0 | } |
302 | 0 | else if (strcmp(par_opt_field, "C_RNTI") == 0) |
303 | 0 | { |
304 | 0 | p_mac_lte_info->rntiType = C_RNTI; |
305 | 0 | } |
306 | 0 | else if (strcmp(par_opt_field, "SI_RNTI") == 0) |
307 | 0 | { |
308 | 0 | p_mac_lte_info->rntiType = SI_RNTI; |
309 | 0 | } |
310 | 0 | else |
311 | 0 | { |
312 | 0 | return 0; |
313 | 0 | } |
314 | | /* Get the associated rnti value */ |
315 | 0 | par_opt_field = strtok(NULL, " "); |
316 | 0 | if (par_opt_field) |
317 | 0 | { |
318 | 0 | ws_strtou16(par_opt_field, NULL, &p_mac_lte_info->rnti); |
319 | 0 | } |
320 | 0 | else |
321 | 0 | { |
322 | 0 | return 0; |
323 | 0 | } |
324 | | |
325 | | /* First optional parameter */ |
326 | 0 | p_mac_lte_info->subframeNumber = 0; |
327 | 0 | par_opt_field = strtok(NULL, " "); |
328 | 0 | if (par_opt_field == NULL) |
329 | 0 | { |
330 | 0 | return 0; |
331 | 0 | } |
332 | 0 | if (strcmp(par_opt_field, "SFN") == 0) |
333 | 0 | { |
334 | 0 | par_opt_field = strtok(NULL, " "); |
335 | 0 | if (par_opt_field != NULL) |
336 | 0 | { |
337 | 0 | ws_strtou16(par_opt_field, NULL, &p_mac_lte_info->subframeNumber); |
338 | 0 | } |
339 | 0 | } |
340 | 0 | p_mac_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK; |
341 | 0 | p_mac_lte_info->length = length; |
342 | | |
343 | | /* Store info in packet */ |
344 | 0 | p_add_proto_data(wmem_file_scope(), pinfo, proto_mac_lte, 0, p_mac_lte_info); |
345 | |
|
346 | 0 | return 1; |
347 | 0 | } |
348 | | |
349 | | /* In the optional string, RLC info should be set as follow (M = mandatory, O = optional): |
350 | | * Channel type (M): "SRB" or "DRB" followed by the RB ID |
351 | | * RLC mode (M): "TM" or "UM" or "AM" or "NA" |
352 | | * UM Sequence nb length (O): "SN_5b" or "SN_10b" |
353 | | */ |
354 | | |
355 | | static bool |
356 | | lte_rlc_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length, packet_direction_t direction) |
357 | 0 | { |
358 | 0 | struct rlc_lte_info* p_rlc_lte_info; |
359 | 0 | char* par_opt_field; |
360 | 0 | char option[30]; |
361 | |
|
362 | 0 | (void) g_strlcpy(option, option_str, 30); |
363 | | |
364 | | /* Only need to set info once per session. */ |
365 | 0 | p_rlc_lte_info = (struct rlc_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_rlc_lte, 0); |
366 | 0 | if (p_rlc_lte_info != NULL) |
367 | 0 | { |
368 | 0 | return 1; |
369 | 0 | } |
370 | | |
371 | | /* Allocate & zero struct */ |
372 | 0 | p_rlc_lte_info = (struct rlc_lte_info*) wmem_new0(pinfo->pool, rlc_lte_info); |
373 | | /* First mandatory parameter */ |
374 | 0 | par_opt_field = strtok(option, " "); |
375 | 0 | if (par_opt_field == NULL) |
376 | 0 | { |
377 | 0 | return 0; |
378 | 0 | } |
379 | 0 | if (strcmp(par_opt_field, "SRB") == 0) |
380 | 0 | { |
381 | 0 | p_rlc_lte_info->channelType = CHANNEL_TYPE_SRB; |
382 | 0 | } |
383 | 0 | else if (strcmp(par_opt_field, "DRB") == 0) |
384 | 0 | { |
385 | 0 | p_rlc_lte_info->channelType = CHANNEL_TYPE_DRB; |
386 | 0 | } |
387 | 0 | else |
388 | 0 | { |
389 | 0 | return 0; |
390 | 0 | } |
391 | | /* Fill in the RB ID */ |
392 | 0 | par_opt_field = strtok(NULL, " "); |
393 | 0 | if (par_opt_field == NULL) |
394 | 0 | { |
395 | 0 | return 0; |
396 | 0 | } |
397 | 0 | ws_strtou16(par_opt_field, NULL, &p_rlc_lte_info->channelId); |
398 | | |
399 | | /* Second mandatory parameter */ |
400 | 0 | par_opt_field = strtok(NULL, " "); |
401 | 0 | if (par_opt_field == NULL) |
402 | 0 | { |
403 | 0 | return 0; |
404 | 0 | } |
405 | 0 | if (strcmp(par_opt_field, "TM") == 0) |
406 | 0 | { |
407 | 0 | p_rlc_lte_info->rlcMode = RLC_TM_MODE; |
408 | 0 | } |
409 | 0 | else if (strcmp(par_opt_field, "UM") == 0) |
410 | 0 | { |
411 | 0 | p_rlc_lte_info->rlcMode = RLC_UM_MODE; |
412 | 0 | } |
413 | 0 | else if (strcmp(par_opt_field, "AM") == 0) |
414 | 0 | { |
415 | 0 | p_rlc_lte_info->rlcMode = RLC_AM_MODE; |
416 | 0 | } |
417 | 0 | else if (strcmp(par_opt_field, "NA") == 0) |
418 | 0 | { |
419 | 0 | p_rlc_lte_info->rlcMode = RLC_PREDEF; |
420 | 0 | } |
421 | 0 | else |
422 | 0 | { |
423 | 0 | return 0; |
424 | 0 | } |
425 | | |
426 | | /* First optional parameter */ |
427 | 0 | par_opt_field = strtok(NULL, " "); |
428 | 0 | if (par_opt_field != NULL) |
429 | 0 | { |
430 | 0 | if (strcmp(par_opt_field, "SN_5b") == 0) |
431 | 0 | { |
432 | 0 | p_rlc_lte_info->sequenceNumberLength = UM_SN_LENGTH_5_BITS; |
433 | 0 | } |
434 | 0 | else if (strcmp(par_opt_field, "SN_10b") == 0) |
435 | 0 | { |
436 | 0 | p_rlc_lte_info->sequenceNumberLength = UM_SN_LENGTH_10_BITS; |
437 | 0 | } |
438 | 0 | } |
439 | 0 | p_rlc_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK; |
440 | 0 | p_rlc_lte_info->priority = 0; |
441 | 0 | p_rlc_lte_info->ueid = 0; |
442 | 0 | p_rlc_lte_info->pduLength = length; |
443 | | |
444 | | /* Store info in packet */ |
445 | 0 | p_add_proto_data(wmem_file_scope(), pinfo, proto_rlc_lte, 0, p_rlc_lte_info); |
446 | |
|
447 | 0 | return 1; |
448 | 0 | } |
449 | | |
450 | | /* In the optional string, PDCP info should be set as follow (M = mandatory, O = optional): |
451 | | * Plane: "SRB" or "DRB" |
452 | | * Sequence number length: "SN_7b" or "SN_12b" |
453 | | */ |
454 | | static bool |
455 | | lte_pdcp_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length _U_, packet_direction_t direction) |
456 | 0 | { |
457 | 0 | struct pdcp_lte_info* p_pdcp_lte_info; |
458 | 0 | char* par_opt_field; |
459 | 0 | char option[30]; |
460 | | |
461 | | /* look up for protocol handle */ |
462 | 0 | (void) g_strlcpy(option, option_str, 30); |
463 | | |
464 | | /* Only need to set info once per session. */ |
465 | 0 | p_pdcp_lte_info = (struct pdcp_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_pdcp_lte, 0); |
466 | 0 | if (p_pdcp_lte_info != NULL) |
467 | 0 | { |
468 | 0 | return 1; |
469 | 0 | } |
470 | | |
471 | | /* Allocate & zero struct */ |
472 | 0 | p_pdcp_lte_info = (struct pdcp_lte_info*) wmem_new0(pinfo->pool, pdcp_lte_info); |
473 | | /* First mandatory parameter */ |
474 | 0 | par_opt_field = strtok(option, " "); |
475 | 0 | if (par_opt_field == NULL) |
476 | 0 | { |
477 | 0 | return 0; |
478 | 0 | } |
479 | 0 | if (strcmp(par_opt_field, "SRB") == 0) |
480 | 0 | { |
481 | 0 | p_pdcp_lte_info->plane = SIGNALING_PLANE; |
482 | 0 | } |
483 | 0 | else if (strcmp(par_opt_field, "DRB") == 0) |
484 | 0 | { |
485 | 0 | p_pdcp_lte_info->plane = USER_PLANE; |
486 | 0 | } |
487 | 0 | else |
488 | 0 | { |
489 | 0 | return 0; |
490 | 0 | } |
491 | | /* Second mandatory parameter */ |
492 | 0 | par_opt_field = strtok(NULL, " "); |
493 | 0 | if (par_opt_field == NULL) |
494 | 0 | { |
495 | 0 | return 0; |
496 | 0 | } |
497 | 0 | if (strcmp(par_opt_field, "SN_7b") == 0) |
498 | 0 | { |
499 | 0 | p_pdcp_lte_info->seqnum_length = PDCP_SN_LENGTH_7_BITS; |
500 | 0 | } |
501 | 0 | else if (strcmp(par_opt_field, "SN_12b") == 0) |
502 | 0 | { |
503 | 0 | p_pdcp_lte_info->seqnum_length = PDCP_SN_LENGTH_12_BITS; |
504 | 0 | } |
505 | 0 | else |
506 | 0 | { |
507 | 0 | return 0; |
508 | 0 | } |
509 | 0 | p_pdcp_lte_info->no_header_pdu = 0; |
510 | 0 | p_pdcp_lte_info->rohc.rohc_compression = 0; |
511 | 0 | p_pdcp_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK; |
512 | | |
513 | | /* Store info in packet */ |
514 | 0 | p_add_proto_data(wmem_file_scope(), pinfo, proto_pdcp_lte, 0, p_pdcp_lte_info); |
515 | |
|
516 | 0 | return 1; |
517 | 0 | } |
518 | | |
519 | | |
520 | | /*****************************************/ |
521 | | /* Main dissection function. */ |
522 | | /*****************************************/ |
523 | | static int |
524 | | dissect_log3gpp(tvbuff_t* tvb, packet_info* pinfo, proto_tree* tree, void* data _U_) |
525 | 0 | { |
526 | 0 | proto_tree* prot3gpp_tree = NULL; |
527 | 0 | proto_item* ti = NULL; |
528 | 0 | int offset = 0; |
529 | 0 | int protocol_name_start; |
530 | 0 | int protocol_name_length; |
531 | 0 | int protocol_option_start; |
532 | 0 | int protocol_option_length; |
533 | 0 | int timestamp_start; |
534 | 0 | int timestamp_length; |
535 | 0 | packet_direction_t direction; |
536 | 0 | tvbuff_t* next_tvb; |
537 | 0 | dissector_handle_t protocol_handle = 0; |
538 | 0 | int sub_dissector_result = 0; |
539 | 0 | char* protocol_name; |
540 | 0 | char* protocol_option; |
541 | 0 | bool is_hex_data; |
542 | | |
543 | | /* Clear Info */ |
544 | 0 | col_clear(pinfo->cinfo, COL_INFO); |
545 | | |
546 | | /* Create root (protocol) tree. */ |
547 | 0 | ti = proto_tree_add_item(tree, proto_log3gpp, tvb, offset, -1, ENC_NA); |
548 | 0 | prot3gpp_tree = proto_item_add_subtree(ti, ett_log3gpp); |
549 | | |
550 | | /*********************************************************************/ |
551 | | /* Note that these are the fields of the stub header as written out */ |
552 | | /* by the wiretap module */ |
553 | | |
554 | | /* Timestamp in file */ |
555 | 0 | timestamp_start = offset; |
556 | 0 | timestamp_length = tvb_strsize(tvb, offset); |
557 | 0 | if (prot3gpp_tree) { |
558 | 0 | proto_tree_add_double_format_value(prot3gpp_tree, hf_log3gpp_timestamp, tvb, |
559 | 0 | offset, timestamp_length, |
560 | 0 | g_ascii_strtod(tvb_format_text(pinfo->pool, tvb, offset, timestamp_length), NULL), |
561 | 0 | "%s", tvb_format_text(pinfo->pool, tvb, offset, timestamp_length - 1)); |
562 | 0 | } |
563 | 0 | offset += timestamp_length; |
564 | | |
565 | | |
566 | | /* protocol name */ |
567 | 0 | protocol_name_start = offset; |
568 | 0 | protocol_name_length = tvb_strsize(tvb, offset); |
569 | 0 | if (prot3gpp_tree) { |
570 | 0 | proto_tree_add_item(prot3gpp_tree, hf_log3gpp_protocol, tvb, offset, protocol_name_length, ENC_ASCII); |
571 | 0 | } |
572 | 0 | offset += protocol_name_length; |
573 | | |
574 | | /* Direction */ |
575 | 0 | direction = (packet_direction_t)tvb_get_uint8(tvb, offset); |
576 | 0 | if (prot3gpp_tree) { |
577 | 0 | proto_tree_add_item(prot3gpp_tree, hf_log3gpp_direction, tvb, offset, 1, ENC_BIG_ENDIAN); |
578 | 0 | } |
579 | 0 | offset++; |
580 | | |
581 | | /* protocol option */ |
582 | 0 | protocol_option_start = offset; |
583 | 0 | protocol_option_length = tvb_strsize(tvb, offset); |
584 | 0 | if (prot3gpp_tree) { |
585 | 0 | proto_tree_add_item(prot3gpp_tree, hf_log3gpp_dissector_option, tvb, offset, protocol_option_length, ENC_ASCII); |
586 | 0 | } |
587 | 0 | offset += protocol_option_length; |
588 | |
|
589 | 0 | if (prot3gpp_tree) |
590 | 0 | { |
591 | | /* Set selection length of prot3gpp tree */ |
592 | 0 | proto_item_set_len(prot3gpp_tree, offset); |
593 | 0 | } |
594 | | |
595 | | /* Add useful details to protocol tree label */ |
596 | 0 | protocol_name = (char*)tvb_get_string_enc(pinfo->pool, tvb, protocol_name_start, protocol_name_length, ENC_UTF_8 | ENC_NA); |
597 | | /* Set Protocol */ |
598 | 0 | col_set_str(pinfo->cinfo, COL_PROTOCOL, protocol_name); |
599 | | /* To know whether the data following is row byte stream or text data */ |
600 | 0 | is_hex_data = strcmp(protocol_name, "TXT"); |
601 | |
|
602 | 0 | proto_item_append_text(ti, " t=%s %c prot=%s", |
603 | 0 | tvb_get_string_enc(pinfo->pool, tvb, timestamp_start, timestamp_length, ENC_UTF_8 | ENC_NA), |
604 | 0 | (direction == 0) ? 'U' : 'D', |
605 | 0 | protocol_name); |
606 | |
|
607 | 0 | if (is_hex_data) |
608 | 0 | { |
609 | | /* We might need to prepend pseudo header for the dissector */ |
610 | 0 | pseudo_hdr_func_ptr_t func_ptr = NULL; |
611 | | |
612 | | /* Look up for the optional information */ |
613 | 0 | protocol_option = (char*)tvb_get_string_enc(pinfo->pool, tvb, protocol_option_start, protocol_option_length, ENC_UTF_8 | ENC_NA); |
614 | | |
615 | | /* look up for the right dissector handle */ |
616 | 0 | protocol_handle = look_for_dissector(protocol_name, direction, &func_ptr); |
617 | | |
618 | | /***********************************************************************/ |
619 | | /* Now hand off to the dissector of intended packet encapsulation type */ |
620 | | |
621 | | /* Try appropriate dissector, if one has been selected */ |
622 | 0 | if (protocol_handle != 0) |
623 | 0 | { |
624 | | /* Dissect the remainder of the frame using chosen protocol handle */ |
625 | 0 | next_tvb = tvb_new_subset_remaining(tvb, offset); |
626 | | |
627 | | /* This part is optional, only for dissector that need pseudo header information */ |
628 | 0 | if (func_ptr != NULL && strlen(protocol_option) != 0) |
629 | 0 | { |
630 | 0 | if (func_ptr(protocol_option, pinfo, offset, direction) == 0) |
631 | 0 | { |
632 | | /* There was an error, return */ |
633 | 0 | return tvb_reported_length(tvb); |
634 | 0 | } |
635 | 0 | } |
636 | 0 | sub_dissector_result = call_dissector(protocol_handle, next_tvb, pinfo, tree); |
637 | 0 | } |
638 | 0 | } |
639 | | |
640 | 0 | if (protocol_handle == 0 || sub_dissector_result == 0) |
641 | 0 | { |
642 | | /* Could get here because: |
643 | | - desired protocol is unavailable (probably disabled), OR |
644 | | - protocol rejected our data |
645 | | Show remaining bytes as unparsed data */ |
646 | 0 | proto_tree_add_item(prot3gpp_tree, hf_log3gpp_unparsed_data, tvb, offset, -1, ENC_NA); |
647 | |
|
648 | 0 | if (!is_hex_data) |
649 | 0 | { |
650 | 0 | col_add_str(pinfo->cinfo, COL_INFO, |
651 | 0 | (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, tvb_reported_length_remaining(tvb, offset), ENC_UTF_8 | ENC_NA)); |
652 | 0 | } |
653 | 0 | else |
654 | 0 | { |
655 | 0 | col_add_fstr(pinfo->cinfo, COL_INFO, |
656 | 0 | "Not dissected ( t=%s %c prot=%s)", |
657 | 0 | tvb_get_string_enc(pinfo->pool, tvb, timestamp_start, timestamp_length, ENC_UTF_8 | ENC_NA), |
658 | 0 | (direction == 0) ? 'U' : 'D', |
659 | 0 | tvb_get_string_enc(pinfo->pool, tvb, protocol_name_start, protocol_name_length, ENC_UTF_8 | ENC_NA)); |
660 | 0 | } |
661 | 0 | } |
662 | 0 | else |
663 | 0 | { |
664 | | /* Show number of dissected bytes */ |
665 | 0 | proto_item* ti_local = proto_tree_add_uint(prot3gpp_tree, |
666 | 0 | hf_log3gpp_dissected_length, |
667 | 0 | tvb, 0, 0, tvb_reported_length(tvb) - offset); |
668 | 0 | proto_item_set_generated(ti_local); |
669 | 0 | } |
670 | 0 | return tvb_reported_length(tvb); |
671 | 0 | } |
672 | | |
673 | | /******************************************************************************/ |
674 | | /* Associate this protocol with the log3gpp file encapsulation type. */ |
675 | | /******************************************************************************/ |
676 | | void proto_reg_handoff_log3gpp(void) |
677 | 16 | { |
678 | 16 | static bool init = false; |
679 | | |
680 | 16 | if (init == false) |
681 | 16 | { |
682 | 16 | dissector_handle_t log3gpp_handle; |
683 | | |
684 | 16 | log3gpp_handle = find_dissector("prot3gpp"); |
685 | 16 | dissector_add_uint("wtap_encap", WTAP_ENCAP_LOG_3GPP, log3gpp_handle); |
686 | | |
687 | 16 | proto_mac_lte = proto_get_id_by_filter_name("mac-lte"); |
688 | 16 | proto_rlc_lte = proto_get_id_by_filter_name("rlc-lte"); |
689 | 16 | proto_pdcp_lte = proto_get_id_by_filter_name("pdcp-lte"); |
690 | | |
691 | 16 | init = true; |
692 | 16 | } |
693 | 16 | if (lte_rrc_prot_version == REL8) |
694 | 16 | { |
695 | 16 | update_dissector_name("LTE-RRC.BCCH.BCH", UPLINK, "lte-rrc.bcch.bch"); |
696 | 16 | update_dissector_name("LTE-RRC.BCCH.BCH", DOWNLINK, "lte-rrc.bcch.bch"); |
697 | 16 | update_dissector_name("LTE-RRC.BCCH.DL.SCH", UPLINK, "lte-rrc.bcch.dl.sch"); |
698 | 16 | update_dissector_name("LTE-RRC.BCCH.DL.SCH", DOWNLINK, "lte-rrc.bcch.dl.sch"); |
699 | 16 | update_dissector_name("LTE-RRC.CCCH", UPLINK, "lte-rrc.ul.ccch"); |
700 | 16 | update_dissector_name("LTE-RRC.CCCH", DOWNLINK, "lte-rrc.dl.ccch"); |
701 | 16 | update_dissector_name("LTE-RRC.DCCH", UPLINK, "lte-rrc.ul.dcch"); |
702 | 16 | update_dissector_name("LTE-RRC.DCCH", DOWNLINK, "lte-rrc.dl.dcch"); |
703 | 16 | update_dissector_name("LTE-RRC.PCCH", UPLINK, "lte-rrc.pcch"); |
704 | 16 | update_dissector_name("LTE-RRC.PCCH", DOWNLINK, "lte-rrc.pcch"); |
705 | 16 | } |
706 | 0 | else if (lte_rrc_prot_version == FD1) |
707 | 0 | { |
708 | 0 | update_dissector_name("LTE-RRC.BCCH.BCH", UPLINK, "lte-rrc-fd1.bcch.bch"); |
709 | 0 | update_dissector_name("LTE-RRC.BCCH.BCH", DOWNLINK, "lte-rrc-fd1.bcch.bch"); |
710 | 0 | update_dissector_name("LTE-RRC.BCCH.DL.SCH", UPLINK, "lte-rrc-fd1.bcch.dl.sch"); |
711 | 0 | update_dissector_name("LTE-RRC.BCCH.DL.SCH", DOWNLINK, "lte-rrc-fd1.bcch.dl.sch"); |
712 | 0 | update_dissector_name("LTE-RRC.CCCH", UPLINK, "lte-rrc-fd1.ul.ccch"); |
713 | 0 | update_dissector_name("LTE-RRC.CCCH", DOWNLINK, "lte-rrc-fd1.dl.ccch"); |
714 | 0 | update_dissector_name("LTE-RRC.DCCH", UPLINK, "lte-rrc-fd1.ul.dcch"); |
715 | 0 | update_dissector_name("LTE-RRC.DCCH", DOWNLINK, "lte-rrc-fd1.dl.dcch"); |
716 | 0 | update_dissector_name("LTE-RRC.PCCH", UPLINK, "lte-rrc-fd1.pcch"); |
717 | 0 | update_dissector_name("LTE-RRC.PCCH", DOWNLINK, "lte-rrc-fd1.pcch"); |
718 | 0 | } |
719 | 16 | if (nas_eps_prot_version == REL8) |
720 | 16 | { |
721 | 16 | update_dissector_name("NAS-EPS", UPLINK, "nas-eps"); |
722 | 16 | update_dissector_name("NAS-EPS", DOWNLINK, "nas-eps"); |
723 | 16 | } |
724 | 0 | else if (nas_eps_prot_version == FD1) |
725 | 0 | { |
726 | 0 | update_dissector_name("NAS-EPS", UPLINK, "nas-eps-fd1"); |
727 | 0 | update_dissector_name("NAS-EPS", DOWNLINK, "nas-eps-fd1"); |
728 | 0 | } |
729 | 16 | } |
730 | | |
731 | | /****************************************/ |
732 | | /* Register the protocol */ |
733 | | /****************************************/ |
734 | | void proto_register_log3gpp(void) |
735 | 16 | { |
736 | 16 | module_t *log3gpp_module; |
737 | 16 | static hf_register_info hf[] = |
738 | 16 | { |
739 | 16 | { &hf_log3gpp_timestamp, |
740 | 16 | { "Timestamp", |
741 | 16 | "log3gpp.timestamp", FT_DOUBLE, BASE_NONE, NULL, 0x0, |
742 | 16 | "File timestamp", HFILL |
743 | 16 | } |
744 | 16 | }, |
745 | 16 | { &hf_log3gpp_protocol, |
746 | 16 | { "3GPP protocol", |
747 | 16 | "log3gpp.protocol", FT_STRING, BASE_NONE, NULL, 0x0, |
748 | 16 | "Original 3GPP protocol name", HFILL |
749 | 16 | } |
750 | 16 | }, |
751 | 16 | { &hf_log3gpp_dissector_option, |
752 | 16 | { "option", |
753 | 16 | "log3gpp.option", FT_STRING, BASE_NONE, NULL, 0x0, |
754 | 16 | "Protocol option", HFILL |
755 | 16 | } |
756 | 16 | }, |
757 | 16 | { &hf_log3gpp_direction, |
758 | 16 | { "Direction", |
759 | 16 | "log3gpp.direction", FT_UINT8, BASE_DEC, VALS(direction_vals), 0x0, |
760 | 16 | "Frame direction (Uplink or Downlink)", HFILL |
761 | 16 | } |
762 | 16 | }, |
763 | 16 | { &hf_log3gpp_unparsed_data, |
764 | 16 | { "Unparsed protocol data", |
765 | 16 | "log3gpp.unparsed_data", FT_BYTES, BASE_NONE, NULL, 0x0, |
766 | 16 | "Unparsed 3GPP protocol data", HFILL |
767 | 16 | } |
768 | 16 | }, |
769 | 16 | { &hf_log3gpp_dissected_length, |
770 | 16 | { "Dissected length", |
771 | 16 | "log3gpp.dissected-length", FT_UINT16, BASE_DEC, NULL, 0x0, |
772 | 16 | "Number of bytes dissected by subdissector(s)", HFILL |
773 | 16 | } |
774 | 16 | }, |
775 | 16 | }; |
776 | | |
777 | 16 | static int *ett[] = |
778 | 16 | { |
779 | 16 | &ett_log3gpp |
780 | 16 | }; |
781 | | |
782 | | /* Register protocol. */ |
783 | 16 | proto_log3gpp = proto_register_protocol("3GPP log packet", |
784 | 16 | "LOG3GPP", |
785 | 16 | "log3gpp"); |
786 | 16 | proto_register_field_array(proto_log3gpp, hf, array_length(hf)); |
787 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
788 | | |
789 | 16 | log3gpp_module = prefs_register_protocol(proto_log3gpp, proto_reg_handoff_log3gpp); |
790 | 16 | prefs_register_enum_preference(log3gpp_module, |
791 | 16 | "rrc_release_version", |
792 | 16 | "Select the release version of LTE RRC protocol", |
793 | 16 | "There might be plugins corresponding to different version of the specification " |
794 | 16 | "If they are present they should be listed here.", |
795 | 16 | <e_rrc_prot_version, |
796 | 16 | lte_rrc_dissector_version, |
797 | 16 | false); |
798 | | |
799 | 16 | prefs_register_enum_preference(log3gpp_module, |
800 | 16 | "nas_eps_release_version", |
801 | 16 | "Select the release version of NAS EPS protocol", |
802 | 16 | "There might be plugins corresponding to different version of the specification " |
803 | 16 | "If they are present they should be listed here.", |
804 | 16 | &nas_eps_prot_version, |
805 | 16 | nas_eps_dissector_version, |
806 | 16 | false); |
807 | | |
808 | | /* Allow dissector to find be found by name. */ |
809 | 16 | register_dissector("prot3gpp", dissect_log3gpp, proto_log3gpp); |
810 | 16 | } |
811 | | |
812 | | /* |
813 | | * Editor modelines - https://www.wireshark.org/tools/modelines.html |
814 | | * |
815 | | * Local variables: |
816 | | * c-basic-offset: 4 |
817 | | * tab-width: 8 |
818 | | * indent-tabs-mode: nil |
819 | | * End: |
820 | | * |
821 | | * vi: set shiftwidth=4 tabstop=8 expandtab: |
822 | | * :indentSize=4:tabSize=8:noTabs=true: |
823 | | */ |