Coverage Report

Created: 2026-09-28 06:52

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-log3gpp.c
Line
Count
Source
1
/* packet-log3gpp.c
2
 * Routines for dissecting phone logs containing 3GPP protocol messages.
3
 * Copyright 2008, Vincent Helfre
4
 *
5
 * Wireshark - Network traffic analyzer
6
 * By Gerald Combs <gerald@wireshark.org>
7
 * Copyright 1998 Gerald Combs
8
 *
9
 * SPDX-License-Identifier: GPL-2.0-or-later
10
 */
11
12
#include "config.h"
13
14
#include <epan/packet.h>
15
#include <epan/prefs.h>
16
#include <epan/proto_data.h>
17
#include <wiretap/wtap.h>
18
#include <wsutil/strtoi.h>
19
#include <wsutil/array.h>
20
21
#include "packet-mac-lte.h"
22
#include "packet-pdcp-lte.h"
23
#include "packet-rlc-lte.h"
24
25
0
#define FD1 0
26
32
#define REL8 1
27
28
void proto_register_log3gpp(void);
29
void proto_reg_handoff_log3gpp(void);
30
31
/* Protocol and registered fields. */
32
static int proto_log3gpp;
33
34
35
static int hf_log3gpp_timestamp;
36
static int hf_log3gpp_protocol;
37
static int hf_log3gpp_direction;
38
static int hf_log3gpp_dissector_option;
39
static int hf_log3gpp_unparsed_data;
40
static int hf_log3gpp_dissected_length;
41
42
/* Protocol subtree. */
43
static int ett_log3gpp;
44
45
/* Cached protocol identifiers */
46
static int proto_mac_lte;
47
static int proto_rlc_lte;
48
static int proto_pdcp_lte;
49
50
51
/* Variables used to select a version for RRC and NAS */
52
static int lte_rrc_prot_version = REL8;
53
static int nas_eps_prot_version = REL8;
54
55
static const enum_val_t lte_rrc_dissector_version[] = {
56
  {"FD1", "FD1", FD1},
57
  {"Rel8", "Rel8 dec 2008", REL8}, /* Add new dissector version after */
58
  {NULL, NULL, -1}
59
};
60
61
static const enum_val_t nas_eps_dissector_version[] = {
62
  {"FD1", "FD1", FD1},
63
  {"Rel8", "Rel8 dec 2008", REL8}, /* Add new dissector version after */
64
  {NULL, NULL, -1}
65
};
66
67
typedef enum packet_direction_t
68
{
69
    UPLINK,
70
    DOWNLINK
71
} packet_direction_t;
72
73
static const value_string direction_vals[] = {
74
    { 0,   "Uplink" },
75
    { 1,   "Downlink" },
76
    { 0,   NULL },
77
};
78
/* Pseudo header functions*/
79
typedef bool (*pseudo_hdr_func_ptr_t) (char *, packet_info *pinfo, uint16_t, packet_direction_t);
80
81
static bool lte_mac_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t);
82
static bool lte_rlc_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t);
83
static bool lte_pdcp_pseudo_hdr(char *, packet_info *pinfo, uint16_t, packet_direction_t);
84
85
typedef struct
86
{
87
  const char * protocol_name;
88
  const char * ul_dissector_name;
89
  const char * dl_dissector_name;
90
  dissector_handle_t ul_dissector_handle;
91
  dissector_handle_t dl_dissector_handle;
92
  pseudo_hdr_func_ptr_t hdr_process;
93
} lookup_dissector_element_t;
94
95
/* Look up table for protocol name /dissector: should be in alphabetic order!!!
96
   the purpose is to match a protocol name with a dissector,
97
   and to store the dissector handle the first time to avoid looking it up every time.
98
   This table should contain all 3GPP specified protocols */
99
static lookup_dissector_element_t dissector_lookup_table[] = {
100
  {"DATA","data","data",0,0,NULL},
101
  {"GAN.TCP","umatcp","umatcp",0,0,NULL},
102
  {"GAN.UDP","umaudp","umaudp",0,0,NULL},
103
  {"GSM.CCCH","gsm_a_ccch","gsm_a_ccch",0,0,NULL},
104
  {"GSM.SACCH","gsm_a_sacch","gsm_a_sacch",0,0,NULL},
105
  {"GTP","gtp","gtp",0,0,NULL},
106
  {"LLC","llcgprs","llcgprs",0,0,NULL},
107
  {"LTE-MAC","mac-lte","mac-lte",0,0, lte_mac_pseudo_hdr},
108
  {"LTE-PDCP","pdcp-lte","pdcp-lte",0,0, lte_pdcp_pseudo_hdr},
109
  {"LTE-RLC","rlc-lte","rlc-lte",0,0, lte_rlc_pseudo_hdr},
110
  {"LTE-RRC.BCCH.BCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
111
  {"LTE-RRC.BCCH.DL.SCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
112
  {"LTE-RRC.CCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
113
  {"LTE-RRC.DCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
114
  {"LTE-RRC.PCCH",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
115
  {"NAS","gsm_a_dtap","gsm_a_dtap",0,0,NULL},
116
  {"NAS-EPS",0,0,0,0,NULL}, /* Dissector set according to preferences (depending on the release) */
117
  {"RR","gsm_a_dtap","gsm_a_dtap",0,0,NULL},
118
  {"RRC.BCCH.BCH","rrc.bcch.bch","rrc.bcch.bch",0,0,NULL},
119
  {"RRC.BCCH.FACH","rrc.bcch.fach","rrc.bcch.fach",0,0,NULL},
120
  {"RRC.CCCH","rrc.ul.ccch","rrc.dl.ccch",0,0,NULL},
121
  {"RRC.DCCH","rrc.ul.dcch","rrc.dl.dcch",0,0,NULL},
122
  {"RRC.MCCH","rrc.mcch","rrc.mcch",0,0,NULL},
123
  {"RRC.MSCH","rrc.msch","rrc.msch",0,0,NULL},
124
  {"RRC.PCCH","rrc.pcch","rrc.pcch",0,0,NULL},
125
  {"RRC.SHCCH","rrc.ul.shcch","rrc.dl.shcch",0,0,NULL},
126
  {"RRC.SI.MIB","rrc.si.mib","rrc.si.mib",0,0,NULL},
127
  {"RRC.SI.SB1","rrc.sb1","rrc.sb1",0,0,NULL},
128
  {"RRC.SI.SB2","rrc.sb2","rrc.sb2",0,0,NULL},
129
  {"RRC.SI.SIB1","rrc.si.sib1","rrc.si.sib1",0,0,NULL},
130
  {"RRC.SI.SIB10","rrc.si.sib10","rrc.si.sib10",0,0,NULL},
131
  {"RRC.SI.SIB11","rrc.si.sib11","rrc.si.sib11",0,0,NULL},
132
  {"RRC.SI.SIB11bis","rrc.si.sib11bis","rrc.si.sib11bis",0,0,NULL},
133
  {"RRC.SI.SIB12","rrc.si.sib12","rrc.si.sib12",0,0,NULL},
134
  {"RRC.SI.SIB13","rrc.si.sib13","rrc.si.sib13",0,0,NULL },
135
  {"RRC.SI.SIB13-1","rrc.si.sib13-1","rrc.si.sib13-1",0,0,NULL},
136
  {"RRC.SI.SIB13-2","rrc.si.sib13-2","rrc.si.sib13-2",0,0,NULL},
137
  {"RRC.SI.SIB13-3","rrc.si.sib13-3","rrc.si.sib13-3",0,0,NULL },
138
  {"RRC.SI.SIB13-4","rrc.si.sib13-4","rrc.si.sib13-4",0,0,NULL},
139
  {"RRC.SI.SIB14","rrc.si.sib14","rrc.si.sib14",0,0,NULL},
140
  {"RRC.SI.SIB15","rrc.si.sib15","rrc.si.sib15",0,0,NULL},
141
  {"RRC.SI.SIB15bis","rrc.si.sib15bis","rrc.si.sib15bis",0,0,NULL},
142
  {"RRC.SI.SIB15-1","rrc.si.sib15-1","rrc.si.sib15-1",0,0,NULL},
143
  {"RRC.SI.SIB15-1bis","rrc.si.sib15-1bis","rrc.si.sib15-1bis",0,0,NULL },
144
  {"RRC.SI.SIB15-2","rrc.si.sib15-2","rrc.si.sib15-2",0,0,NULL},
145
  {"RRC.SI.SIB15-2bis","rrc.si.sib15-2bis","rrc.si.sib15-2bis",0,0,NULL},
146
  {"RRC.SI.SIB15-3","rrc.si.sib15-3","rrc.si.sib15-3",0,0,NULL},
147
  {"RRC.SI.SIB15-3bis","rrc.si.sib15-3bis","rrc.si.sib15-3bis",0,0,NULL},
148
  {"RRC.SI.SIB15-4","rrc.si.sib15-4","rrc.si.sib15-4",0,0,NULL},
149
  {"RRC.SI.SIB15-5","rrc.si.sib15-5","rrc.si.sib15-5",0,0,NULL},
150
  {"RRC.SI.SIB15-6","rrc.si.sib15-6","rrc.si.sib15-6",0,0,NULL},
151
  {"RRC.SI.SIB15-7","rrc.si.sib15-7","rrc.si.sib15-7",0,0,NULL},
152
  {"RRC.SI.SIB15-8","rrc.si.sib15-8","rrc.si.sib15-8",0,0,NULL},
153
  {"RRC.SI.SIB18","rrc.si.sib18","rrc.si.sib18",0,0,NULL},
154
  {"RRC.SI.SIB17","rrc.si.sib17","rrc.si.sib17",0,0,NULL},
155
  {"RRC.SI.SIB18","rrc.si.sib18","rrc.si.sib18",0,0,NULL},
156
  {"RRC.SI.SIB2","rrc.si.sib2","rrc.si.sib2",0,0,NULL},
157
  {"RRC.SI.SIB3","rrc.si.sib3","rrc.si.sib3",0,0,NULL},
158
  {"RRC.SI.SIB4","rrc.si.sib4","rrc.si.sib4",0,0,NULL},
159
  {"RRC.SI.SIB5","rrc.si.sib5","rrc.si.sib5",0,0,NULL},
160
  {"RRC.SI.SIB5bis","rrc.si.sib5bis","rrc.si.sib5bis",0,0,NULL},
161
  {"RRC.SI.SIB6","rrc.si.sib6","rrc.si.sib6",0,0,NULL},
162
  {"RRC.SI.SIB7","rrc.si.sib7","rrc.si.sib7",0,0,NULL},
163
  {"RRC.SI.SIB8","rrc.si.sib8","rrc.si.sib8",0,0,NULL},
164
  {"RRC.SI.SIB9","rrc.si.sib9","rrc.si.sib9",0,0,NULL},
165
  {"SNDCP","sndcp","sndcp",0,0,NULL},
166
  {"SNDCPXID","sndcpxid","sndcpxid",0,0,NULL}
167
};
168
169
170
static int
171
dissector_element_compare(const void *protocol_name, const void *element)
172
896
{
173
896
  return strcmp((const char *)protocol_name, ((const lookup_dissector_element_t *) element)->protocol_name);
174
896
}
175
176
static dissector_handle_t
177
look_for_dissector(char* protocol_name, packet_direction_t direction, pseudo_hdr_func_ptr_t* func_ptr _U_)
178
0
{
179
0
    lookup_dissector_element_t* element_ptr;
180
0
    dissector_handle_t dissector_handle = NULL;
181
182
0
    element_ptr = (lookup_dissector_element_t*)bsearch((void*)protocol_name,
183
0
        (void*)dissector_lookup_table,
184
0
        array_length(dissector_lookup_table),
185
0
        sizeof dissector_lookup_table[0],
186
0
        dissector_element_compare);
187
0
    if (element_ptr != NULL) {
188
0
        if (direction == UPLINK)
189
0
        {
190
0
            if (element_ptr->ul_dissector_handle == 0)
191
0
            {
192
0
                element_ptr->ul_dissector_handle = find_dissector(element_ptr->ul_dissector_name);
193
0
            }
194
0
            dissector_handle = element_ptr->ul_dissector_handle;
195
0
        }
196
0
        else
197
0
        {
198
0
            if (element_ptr->dl_dissector_handle == 0)
199
0
            {
200
0
                element_ptr->dl_dissector_handle = find_dissector(element_ptr->dl_dissector_name);
201
0
            }
202
0
            dissector_handle = element_ptr->dl_dissector_handle;
203
0
        }
204
205
0
    }
206
207
0
    return dissector_handle;
208
0
}
209
210
static void
211
update_dissector_name(const char* protocol_name, packet_direction_t direction, const char* dissector_name)
212
192
{
213
192
    lookup_dissector_element_t* element_ptr;
214
215
192
    element_ptr = (lookup_dissector_element_t*)bsearch((void*)protocol_name,
216
192
        (void*)dissector_lookup_table,
217
192
        array_length(dissector_lookup_table),
218
192
        sizeof dissector_lookup_table[0],
219
192
        dissector_element_compare);
220
192
    if (element_ptr != NULL) {
221
192
        if (direction == UPLINK)
222
96
        {
223
96
            element_ptr->ul_dissector_handle = 0;
224
96
            element_ptr->ul_dissector_name = dissector_name;
225
96
        }
226
96
        else
227
96
        {
228
96
            element_ptr->dl_dissector_handle = 0;
229
96
            element_ptr->dl_dissector_name = dissector_name;
230
96
        }
231
232
192
    }
233
192
}
234
235
/******************************************************************************/
236
/* pseudo header functions: used for the dissectors that needs pseudo headers */
237
/******************************************************************************/
238
239
240
/* In the optional string, MAC info should be set as follow (M = mandatory, O = optional):
241
 * Radio type (M):  "FDD" or "TDD"
242
 * RNTI type (M): "NO_RNTI" or "P_RNTI" or "RA_RNTI" or "C_RNTI" or "SI_RNT" followed by rnti value in decimal format
243
 * subframe number (M): "SFN" followed by the subframe number in decimal format
244
 */
245
static bool
246
lte_mac_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length, packet_direction_t direction)
247
0
{
248
0
    struct mac_lte_info* p_mac_lte_info;
249
0
    char* par_opt_field;
250
0
    char option[30];
251
252
    /* Need to copy the string in a local buffer since strtok will modify it */
253
0
    (void) g_strlcpy(option, option_str, 30);
254
255
    /* Only need to set info once per session. */
256
0
    p_mac_lte_info = (struct mac_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_mac_lte, 0);
257
0
    if (p_mac_lte_info != NULL)
258
0
    {
259
0
        return 1;
260
0
    }
261
262
    /* Allocate & zero struct */
263
0
    p_mac_lte_info = (struct mac_lte_info*) wmem_new0(pinfo->pool, mac_lte_info);
264
265
    /* First mandatory parameter */
266
0
    par_opt_field = strtok(option, " ");
267
0
    if (par_opt_field == NULL)
268
0
    {
269
0
        return 0;
270
0
    }
271
0
    if (strcmp(par_opt_field, "FDD") == 0)
272
0
    {
273
0
        p_mac_lte_info->radioType = FDD_RADIO;
274
0
    }
275
0
    else if (strcmp(par_opt_field, "TDD") == 0)
276
0
    {
277
0
        p_mac_lte_info->radioType = TDD_RADIO;
278
0
    }
279
0
    else
280
0
    {
281
0
        return 0;
282
0
    }
283
284
    /* Second mandatory parameter */
285
0
    par_opt_field = strtok(NULL, " ");
286
0
    if (par_opt_field == NULL)
287
0
    {
288
0
        return 0;
289
0
    }
290
0
    if (strcmp(par_opt_field, "NO_RNTI") == 0)
291
0
    {
292
0
        p_mac_lte_info->rntiType = NO_RNTI;
293
0
    }
294
0
    else if (strcmp(par_opt_field, "P_RNTI") == 0)
295
0
    {
296
0
        p_mac_lte_info->rntiType = P_RNTI;
297
0
    }
298
0
    else if (strcmp(par_opt_field, "RA_RNTI") == 0)
299
0
    {
300
0
        p_mac_lte_info->rntiType = RA_RNTI;
301
0
    }
302
0
    else if (strcmp(par_opt_field, "C_RNTI") == 0)
303
0
    {
304
0
        p_mac_lte_info->rntiType = C_RNTI;
305
0
    }
306
0
    else if (strcmp(par_opt_field, "SI_RNTI") == 0)
307
0
    {
308
0
        p_mac_lte_info->rntiType = SI_RNTI;
309
0
    }
310
0
    else
311
0
    {
312
0
        return 0;
313
0
    }
314
    /* Get the associated rnti value */
315
0
    par_opt_field = strtok(NULL, " ");
316
0
    if (par_opt_field)
317
0
    {
318
0
        ws_strtou16(par_opt_field, NULL, &p_mac_lte_info->rnti);
319
0
    }
320
0
    else
321
0
    {
322
0
        return 0;
323
0
    }
324
325
    /* First optional parameter */
326
0
    p_mac_lte_info->subframeNumber = 0;
327
0
    par_opt_field = strtok(NULL, " ");
328
0
    if (par_opt_field == NULL)
329
0
    {
330
0
        return 0;
331
0
    }
332
0
    if (strcmp(par_opt_field, "SFN") == 0)
333
0
    {
334
0
        par_opt_field = strtok(NULL, " ");
335
0
        if (par_opt_field != NULL)
336
0
        {
337
0
            ws_strtou16(par_opt_field, NULL, &p_mac_lte_info->subframeNumber);
338
0
        }
339
0
    }
340
0
    p_mac_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK;
341
0
    p_mac_lte_info->length = length;
342
343
    /* Store info in packet */
344
0
    p_add_proto_data(wmem_file_scope(), pinfo, proto_mac_lte, 0, p_mac_lte_info);
345
346
0
    return 1;
347
0
}
348
349
/* In the optional string, RLC info should be set as follow (M = mandatory, O = optional):
350
 * Channel type (M): "SRB" or "DRB" followed by the RB ID
351
 * RLC mode (M): "TM" or  "UM" or "AM" or "NA"
352
 * UM Sequence nb length (O): "SN_5b" or "SN_10b"
353
 */
354
355
static bool
356
lte_rlc_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length, packet_direction_t direction)
357
0
{
358
0
    struct rlc_lte_info* p_rlc_lte_info;
359
0
    char* par_opt_field;
360
0
    char option[30];
361
362
0
    (void) g_strlcpy(option, option_str, 30);
363
364
    /* Only need to set info once per session. */
365
0
    p_rlc_lte_info = (struct rlc_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_rlc_lte, 0);
366
0
    if (p_rlc_lte_info != NULL)
367
0
    {
368
0
        return 1;
369
0
    }
370
371
    /* Allocate & zero struct */
372
0
    p_rlc_lte_info = (struct rlc_lte_info*) wmem_new0(pinfo->pool, rlc_lte_info);
373
    /* First mandatory parameter */
374
0
    par_opt_field = strtok(option, " ");
375
0
    if (par_opt_field == NULL)
376
0
    {
377
0
        return 0;
378
0
    }
379
0
    if (strcmp(par_opt_field, "SRB") == 0)
380
0
    {
381
0
        p_rlc_lte_info->channelType = CHANNEL_TYPE_SRB;
382
0
    }
383
0
    else if (strcmp(par_opt_field, "DRB") == 0)
384
0
    {
385
0
        p_rlc_lte_info->channelType = CHANNEL_TYPE_DRB;
386
0
    }
387
0
    else
388
0
    {
389
0
        return 0;
390
0
    }
391
    /* Fill in the RB ID */
392
0
    par_opt_field = strtok(NULL, " ");
393
0
    if (par_opt_field == NULL)
394
0
    {
395
0
        return 0;
396
0
    }
397
0
    ws_strtou16(par_opt_field, NULL, &p_rlc_lte_info->channelId);
398
399
    /* Second mandatory parameter */
400
0
    par_opt_field = strtok(NULL, " ");
401
0
    if (par_opt_field == NULL)
402
0
    {
403
0
        return 0;
404
0
    }
405
0
    if (strcmp(par_opt_field, "TM") == 0)
406
0
    {
407
0
        p_rlc_lte_info->rlcMode = RLC_TM_MODE;
408
0
    }
409
0
    else if (strcmp(par_opt_field, "UM") == 0)
410
0
    {
411
0
        p_rlc_lte_info->rlcMode = RLC_UM_MODE;
412
0
    }
413
0
    else if (strcmp(par_opt_field, "AM") == 0)
414
0
    {
415
0
        p_rlc_lte_info->rlcMode = RLC_AM_MODE;
416
0
    }
417
0
    else if (strcmp(par_opt_field, "NA") == 0)
418
0
    {
419
0
        p_rlc_lte_info->rlcMode = RLC_PREDEF;
420
0
    }
421
0
    else
422
0
    {
423
0
        return 0;
424
0
    }
425
426
    /* First optional parameter */
427
0
    par_opt_field = strtok(NULL, " ");
428
0
    if (par_opt_field != NULL)
429
0
    {
430
0
        if (strcmp(par_opt_field, "SN_5b") == 0)
431
0
        {
432
0
            p_rlc_lte_info->sequenceNumberLength = UM_SN_LENGTH_5_BITS;
433
0
        }
434
0
        else if (strcmp(par_opt_field, "SN_10b") == 0)
435
0
        {
436
0
            p_rlc_lte_info->sequenceNumberLength = UM_SN_LENGTH_10_BITS;
437
0
        }
438
0
    }
439
0
    p_rlc_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK;
440
0
    p_rlc_lte_info->priority = 0;
441
0
    p_rlc_lte_info->ueid = 0;
442
0
    p_rlc_lte_info->pduLength = length;
443
444
    /* Store info in packet */
445
0
    p_add_proto_data(wmem_file_scope(), pinfo, proto_rlc_lte, 0, p_rlc_lte_info);
446
447
0
    return 1;
448
0
}
449
450
/* In the optional string, PDCP info should be set as follow (M = mandatory, O = optional):
451
 * Plane: "SRB" or "DRB"
452
 * Sequence number length: "SN_7b" or "SN_12b"
453
 */
454
static bool
455
lte_pdcp_pseudo_hdr(char* option_str, packet_info* pinfo, uint16_t length _U_, packet_direction_t direction)
456
0
{
457
0
    struct pdcp_lte_info* p_pdcp_lte_info;
458
0
    char* par_opt_field;
459
0
    char option[30];
460
461
    /* look up for protocol handle */
462
0
    (void) g_strlcpy(option, option_str, 30);
463
464
    /* Only need to set info once per session. */
465
0
    p_pdcp_lte_info = (struct pdcp_lte_info*)p_get_proto_data(wmem_file_scope(), pinfo, proto_pdcp_lte, 0);
466
0
    if (p_pdcp_lte_info != NULL)
467
0
    {
468
0
        return 1;
469
0
    }
470
471
    /* Allocate & zero struct */
472
0
    p_pdcp_lte_info = (struct pdcp_lte_info*) wmem_new0(pinfo->pool, pdcp_lte_info);
473
    /* First mandatory parameter */
474
0
    par_opt_field = strtok(option, " ");
475
0
    if (par_opt_field == NULL)
476
0
    {
477
0
        return 0;
478
0
    }
479
0
    if (strcmp(par_opt_field, "SRB") == 0)
480
0
    {
481
0
        p_pdcp_lte_info->plane = SIGNALING_PLANE;
482
0
    }
483
0
    else if (strcmp(par_opt_field, "DRB") == 0)
484
0
    {
485
0
        p_pdcp_lte_info->plane = USER_PLANE;
486
0
    }
487
0
    else
488
0
    {
489
0
        return 0;
490
0
    }
491
    /* Second mandatory parameter */
492
0
    par_opt_field = strtok(NULL, " ");
493
0
    if (par_opt_field == NULL)
494
0
    {
495
0
        return 0;
496
0
    }
497
0
    if (strcmp(par_opt_field, "SN_7b") == 0)
498
0
    {
499
0
        p_pdcp_lte_info->seqnum_length = PDCP_SN_LENGTH_7_BITS;
500
0
    }
501
0
    else if (strcmp(par_opt_field, "SN_12b") == 0)
502
0
    {
503
0
        p_pdcp_lte_info->seqnum_length = PDCP_SN_LENGTH_12_BITS;
504
0
    }
505
0
    else
506
0
    {
507
0
        return 0;
508
0
    }
509
0
    p_pdcp_lte_info->no_header_pdu = 0;
510
0
    p_pdcp_lte_info->rohc.rohc_compression = 0;
511
0
    p_pdcp_lte_info->direction = (direction == UPLINK) ? DIRECTION_UPLINK : DIRECTION_DOWNLINK;
512
513
    /* Store info in packet */
514
0
    p_add_proto_data(wmem_file_scope(), pinfo, proto_pdcp_lte, 0, p_pdcp_lte_info);
515
516
0
    return 1;
517
0
}
518
519
520
/*****************************************/
521
/* Main dissection function.             */
522
/*****************************************/
523
static int
524
dissect_log3gpp(tvbuff_t* tvb, packet_info* pinfo, proto_tree* tree, void* data _U_)
525
0
{
526
0
    proto_tree* prot3gpp_tree = NULL;
527
0
    proto_item* ti = NULL;
528
0
    int         offset = 0;
529
0
    int         protocol_name_start;
530
0
    int         protocol_name_length;
531
0
    int         protocol_option_start;
532
0
    int         protocol_option_length;
533
0
    int         timestamp_start;
534
0
    int         timestamp_length;
535
0
    packet_direction_t      direction;
536
0
    tvbuff_t* next_tvb;
537
0
    dissector_handle_t protocol_handle = 0;
538
0
    int sub_dissector_result = 0;
539
0
    char* protocol_name;
540
0
    char* protocol_option;
541
0
    bool is_hex_data;
542
543
    /* Clear Info */
544
0
    col_clear(pinfo->cinfo, COL_INFO);
545
546
    /* Create root (protocol) tree. */
547
0
    ti = proto_tree_add_item(tree, proto_log3gpp, tvb, offset, -1, ENC_NA);
548
0
    prot3gpp_tree = proto_item_add_subtree(ti, ett_log3gpp);
549
550
    /*********************************************************************/
551
    /* Note that these are the fields of the stub header as written out  */
552
    /* by the wiretap module                                             */
553
554
    /* Timestamp in file */
555
0
    timestamp_start = offset;
556
0
    timestamp_length = tvb_strsize(tvb, offset);
557
0
    if (prot3gpp_tree) {
558
0
        proto_tree_add_double_format_value(prot3gpp_tree, hf_log3gpp_timestamp, tvb,
559
0
            offset, timestamp_length,
560
0
            g_ascii_strtod(tvb_format_text(pinfo->pool, tvb, offset, timestamp_length), NULL),
561
0
            "%s", tvb_format_text(pinfo->pool, tvb, offset, timestamp_length - 1));
562
0
    }
563
0
    offset += timestamp_length;
564
565
566
    /* protocol name */
567
0
    protocol_name_start = offset;
568
0
    protocol_name_length = tvb_strsize(tvb, offset);
569
0
    if (prot3gpp_tree) {
570
0
        proto_tree_add_item(prot3gpp_tree, hf_log3gpp_protocol, tvb, offset, protocol_name_length, ENC_ASCII);
571
0
    }
572
0
    offset += protocol_name_length;
573
574
    /* Direction */
575
0
    direction = (packet_direction_t)tvb_get_uint8(tvb, offset);
576
0
    if (prot3gpp_tree) {
577
0
        proto_tree_add_item(prot3gpp_tree, hf_log3gpp_direction, tvb, offset, 1, ENC_BIG_ENDIAN);
578
0
    }
579
0
    offset++;
580
581
    /* protocol option */
582
0
    protocol_option_start = offset;
583
0
    protocol_option_length = tvb_strsize(tvb, offset);
584
0
    if (prot3gpp_tree) {
585
0
        proto_tree_add_item(prot3gpp_tree, hf_log3gpp_dissector_option, tvb, offset, protocol_option_length, ENC_ASCII);
586
0
    }
587
0
    offset += protocol_option_length;
588
589
0
    if (prot3gpp_tree)
590
0
    {
591
        /* Set selection length of prot3gpp tree */
592
0
        proto_item_set_len(prot3gpp_tree, offset);
593
0
    }
594
595
    /* Add useful details to protocol tree label */
596
0
    protocol_name = (char*)tvb_get_string_enc(pinfo->pool, tvb, protocol_name_start, protocol_name_length, ENC_UTF_8 | ENC_NA);
597
    /* Set Protocol */
598
0
    col_set_str(pinfo->cinfo, COL_PROTOCOL, protocol_name);
599
    /* To know whether the data following is row byte stream or text data */
600
0
    is_hex_data = strcmp(protocol_name, "TXT");
601
602
0
    proto_item_append_text(ti, " t=%s   %c   prot=%s",
603
0
        tvb_get_string_enc(pinfo->pool, tvb, timestamp_start, timestamp_length, ENC_UTF_8 | ENC_NA),
604
0
        (direction == 0) ? 'U' : 'D',
605
0
        protocol_name);
606
607
0
    if (is_hex_data)
608
0
    {
609
        /* We might need to prepend pseudo header for the dissector */
610
0
        pseudo_hdr_func_ptr_t func_ptr = NULL;
611
612
        /* Look up for the optional information */
613
0
        protocol_option = (char*)tvb_get_string_enc(pinfo->pool, tvb, protocol_option_start, protocol_option_length, ENC_UTF_8 | ENC_NA);
614
615
        /* look up for the right dissector handle */
616
0
        protocol_handle = look_for_dissector(protocol_name, direction, &func_ptr);
617
618
        /***********************************************************************/
619
        /* Now hand off to the dissector of intended packet encapsulation type */
620
621
        /* Try appropriate dissector, if one has been selected */
622
0
        if (protocol_handle != 0)
623
0
        {
624
            /* Dissect the remainder of the frame using chosen protocol handle */
625
0
            next_tvb = tvb_new_subset_remaining(tvb, offset);
626
627
            /* This part is optional, only for dissector that need pseudo header information */
628
0
            if (func_ptr != NULL && strlen(protocol_option) != 0)
629
0
            {
630
0
                if (func_ptr(protocol_option, pinfo, offset, direction) == 0)
631
0
                {
632
                    /* There was an error, return */
633
0
                    return tvb_reported_length(tvb);
634
0
                }
635
0
            }
636
0
            sub_dissector_result = call_dissector(protocol_handle, next_tvb, pinfo, tree);
637
0
        }
638
0
    }
639
640
0
    if (protocol_handle == 0 || sub_dissector_result == 0)
641
0
    {
642
        /* Could get here because:
643
          - desired protocol is unavailable (probably disabled), OR
644
          - protocol rejected our data
645
          Show remaining bytes as unparsed data */
646
0
        proto_tree_add_item(prot3gpp_tree, hf_log3gpp_unparsed_data, tvb, offset, -1, ENC_NA);
647
648
0
        if (!is_hex_data)
649
0
        {
650
0
            col_add_str(pinfo->cinfo, COL_INFO,
651
0
                (char*)tvb_get_string_enc(pinfo->pool, tvb, offset, tvb_reported_length_remaining(tvb, offset), ENC_UTF_8 | ENC_NA));
652
0
        }
653
0
        else
654
0
        {
655
0
            col_add_fstr(pinfo->cinfo, COL_INFO,
656
0
                "Not dissected  ( t=%s   %c   prot=%s)",
657
0
                tvb_get_string_enc(pinfo->pool, tvb, timestamp_start, timestamp_length, ENC_UTF_8 | ENC_NA),
658
0
                (direction == 0) ? 'U' : 'D',
659
0
                tvb_get_string_enc(pinfo->pool, tvb, protocol_name_start, protocol_name_length, ENC_UTF_8 | ENC_NA));
660
0
        }
661
0
    }
662
0
    else
663
0
    {
664
        /* Show number of dissected bytes */
665
0
        proto_item* ti_local = proto_tree_add_uint(prot3gpp_tree,
666
0
            hf_log3gpp_dissected_length,
667
0
            tvb, 0, 0, tvb_reported_length(tvb) - offset);
668
0
        proto_item_set_generated(ti_local);
669
0
    }
670
0
    return tvb_reported_length(tvb);
671
0
}
672
673
/******************************************************************************/
674
/* Associate this protocol with the log3gpp file encapsulation type. */
675
/******************************************************************************/
676
void proto_reg_handoff_log3gpp(void)
677
16
{
678
16
    static bool init = false;
679
680
16
    if (init == false)
681
16
    {
682
16
        dissector_handle_t log3gpp_handle;
683
684
16
        log3gpp_handle = find_dissector("prot3gpp");
685
16
        dissector_add_uint("wtap_encap", WTAP_ENCAP_LOG_3GPP, log3gpp_handle);
686
687
16
        proto_mac_lte = proto_get_id_by_filter_name("mac-lte");
688
16
        proto_rlc_lte = proto_get_id_by_filter_name("rlc-lte");
689
16
        proto_pdcp_lte = proto_get_id_by_filter_name("pdcp-lte");
690
691
16
        init = true;
692
16
    }
693
16
    if (lte_rrc_prot_version == REL8)
694
16
    {
695
16
        update_dissector_name("LTE-RRC.BCCH.BCH", UPLINK, "lte-rrc.bcch.bch");
696
16
        update_dissector_name("LTE-RRC.BCCH.BCH", DOWNLINK, "lte-rrc.bcch.bch");
697
16
        update_dissector_name("LTE-RRC.BCCH.DL.SCH", UPLINK, "lte-rrc.bcch.dl.sch");
698
16
        update_dissector_name("LTE-RRC.BCCH.DL.SCH", DOWNLINK, "lte-rrc.bcch.dl.sch");
699
16
        update_dissector_name("LTE-RRC.CCCH", UPLINK, "lte-rrc.ul.ccch");
700
16
        update_dissector_name("LTE-RRC.CCCH", DOWNLINK, "lte-rrc.dl.ccch");
701
16
        update_dissector_name("LTE-RRC.DCCH", UPLINK, "lte-rrc.ul.dcch");
702
16
        update_dissector_name("LTE-RRC.DCCH", DOWNLINK, "lte-rrc.dl.dcch");
703
16
        update_dissector_name("LTE-RRC.PCCH", UPLINK, "lte-rrc.pcch");
704
16
        update_dissector_name("LTE-RRC.PCCH", DOWNLINK, "lte-rrc.pcch");
705
16
    }
706
0
    else if (lte_rrc_prot_version == FD1)
707
0
    {
708
0
        update_dissector_name("LTE-RRC.BCCH.BCH", UPLINK, "lte-rrc-fd1.bcch.bch");
709
0
        update_dissector_name("LTE-RRC.BCCH.BCH", DOWNLINK, "lte-rrc-fd1.bcch.bch");
710
0
        update_dissector_name("LTE-RRC.BCCH.DL.SCH", UPLINK, "lte-rrc-fd1.bcch.dl.sch");
711
0
        update_dissector_name("LTE-RRC.BCCH.DL.SCH", DOWNLINK, "lte-rrc-fd1.bcch.dl.sch");
712
0
        update_dissector_name("LTE-RRC.CCCH", UPLINK, "lte-rrc-fd1.ul.ccch");
713
0
        update_dissector_name("LTE-RRC.CCCH", DOWNLINK, "lte-rrc-fd1.dl.ccch");
714
0
        update_dissector_name("LTE-RRC.DCCH", UPLINK, "lte-rrc-fd1.ul.dcch");
715
0
        update_dissector_name("LTE-RRC.DCCH", DOWNLINK, "lte-rrc-fd1.dl.dcch");
716
0
        update_dissector_name("LTE-RRC.PCCH", UPLINK, "lte-rrc-fd1.pcch");
717
0
        update_dissector_name("LTE-RRC.PCCH", DOWNLINK, "lte-rrc-fd1.pcch");
718
0
    }
719
16
    if (nas_eps_prot_version == REL8)
720
16
    {
721
16
        update_dissector_name("NAS-EPS", UPLINK, "nas-eps");
722
16
        update_dissector_name("NAS-EPS", DOWNLINK, "nas-eps");
723
16
    }
724
0
    else if (nas_eps_prot_version == FD1)
725
0
    {
726
0
        update_dissector_name("NAS-EPS", UPLINK, "nas-eps-fd1");
727
0
        update_dissector_name("NAS-EPS", DOWNLINK, "nas-eps-fd1");
728
0
    }
729
16
}
730
731
/****************************************/
732
/* Register the protocol                */
733
/****************************************/
734
void proto_register_log3gpp(void)
735
16
{
736
16
  module_t *log3gpp_module;
737
16
    static hf_register_info hf[] =
738
16
    {
739
16
        { &hf_log3gpp_timestamp,
740
16
            { "Timestamp",
741
16
              "log3gpp.timestamp", FT_DOUBLE, BASE_NONE, NULL, 0x0,
742
16
              "File timestamp", HFILL
743
16
            }
744
16
        },
745
16
        { &hf_log3gpp_protocol,
746
16
            { "3GPP protocol",
747
16
              "log3gpp.protocol", FT_STRING, BASE_NONE, NULL, 0x0,
748
16
              "Original 3GPP protocol name", HFILL
749
16
            }
750
16
        },
751
16
        { &hf_log3gpp_dissector_option,
752
16
            { "option",
753
16
              "log3gpp.option", FT_STRING, BASE_NONE, NULL, 0x0,
754
16
              "Protocol option", HFILL
755
16
            }
756
16
        },
757
16
        { &hf_log3gpp_direction,
758
16
            { "Direction",
759
16
              "log3gpp.direction", FT_UINT8, BASE_DEC, VALS(direction_vals), 0x0,
760
16
              "Frame direction (Uplink or Downlink)", HFILL
761
16
            }
762
16
        },
763
16
        { &hf_log3gpp_unparsed_data,
764
16
            { "Unparsed protocol data",
765
16
              "log3gpp.unparsed_data", FT_BYTES, BASE_NONE, NULL, 0x0,
766
16
              "Unparsed 3GPP protocol data", HFILL
767
16
            }
768
16
        },
769
16
        { &hf_log3gpp_dissected_length,
770
16
            { "Dissected length",
771
16
              "log3gpp.dissected-length", FT_UINT16, BASE_DEC, NULL, 0x0,
772
16
              "Number of bytes dissected by subdissector(s)", HFILL
773
16
            }
774
16
        },
775
16
    };
776
777
16
    static int *ett[] =
778
16
    {
779
16
        &ett_log3gpp
780
16
    };
781
782
    /* Register protocol. */
783
16
    proto_log3gpp = proto_register_protocol("3GPP log packet",
784
16
                                            "LOG3GPP",
785
16
                                            "log3gpp");
786
16
    proto_register_field_array(proto_log3gpp, hf, array_length(hf));
787
16
    proto_register_subtree_array(ett, array_length(ett));
788
789
16
    log3gpp_module = prefs_register_protocol(proto_log3gpp, proto_reg_handoff_log3gpp);
790
16
    prefs_register_enum_preference(log3gpp_module,
791
16
                                   "rrc_release_version",
792
16
                                   "Select the release version of LTE RRC protocol",
793
16
                                   "There might be plugins corresponding to different version of the specification "
794
16
                                   "If they are present they should be listed here.",
795
16
                                   &lte_rrc_prot_version,
796
16
                                   lte_rrc_dissector_version,
797
16
                                   false);
798
799
16
    prefs_register_enum_preference(log3gpp_module,
800
16
                                   "nas_eps_release_version",
801
16
                                   "Select the release version of NAS EPS protocol",
802
16
                                   "There might be plugins corresponding to different version of the specification "
803
16
                                   "If they are present they should be listed here.",
804
16
                                   &nas_eps_prot_version,
805
16
                                   nas_eps_dissector_version,
806
16
                                   false);
807
808
    /* Allow dissector to find be found by name. */
809
16
    register_dissector("prot3gpp", dissect_log3gpp, proto_log3gpp);
810
16
}
811
812
/*
813
 * Editor modelines  -  https://www.wireshark.org/tools/modelines.html
814
 *
815
 * Local variables:
816
 * c-basic-offset: 4
817
 * tab-width: 8
818
 * indent-tabs-mode: nil
819
 * End:
820
 *
821
 * vi: set shiftwidth=4 tabstop=8 expandtab:
822
 * :indentSize=4:tabSize=8:noTabs=true:
823
 */