/src/wireshark/epan/dissectors/packet-pcaplog.c
Line | Count | Source |
1 | | /* packet-pcaplog.c |
2 | | * Routines for pcaplog dissection |
3 | | * Copyright 2023, Dr. Lars Völker <lars.voelker@technica-engineering.de> |
4 | | * |
5 | | * Wireshark - Network traffic analyzer |
6 | | * By Gerald Combs <gerald@wireshark.org> |
7 | | * Copyright 1998 Gerald Combs |
8 | | * |
9 | | * SPDX-License-Identifier: GPL-2.0-or-later |
10 | | */ |
11 | | |
12 | | |
13 | | #include "config.h" |
14 | | #define WS_LOG_DOMAIN "pcaplog" |
15 | | |
16 | | #define PEN_VCTR 46254 |
17 | | |
18 | | #include <wireshark.h> |
19 | | |
20 | | #include <epan/packet.h> |
21 | | #include <epan/addr_resolv.h> |
22 | | |
23 | | void proto_reg_handoff_pcaplog(void); |
24 | | void proto_register_pcaplog(void); |
25 | | |
26 | | static int proto_pcaplog; |
27 | | static int hf_pcaplog_type; |
28 | | static int hf_pcaplog_length; |
29 | | static int hf_pcaplog_data; |
30 | | |
31 | | static dissector_handle_t pcaplog_handle; |
32 | | static dissector_handle_t xml_handle; |
33 | | |
34 | | static int ett_pcaplog; |
35 | | static int ett_pcaplog_data; |
36 | | |
37 | | static int |
38 | | dissect_pcaplog(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, |
39 | | void *data _U_) |
40 | 0 | { |
41 | 0 | uint32_t data_type; |
42 | 0 | uint32_t data_length; |
43 | 0 | proto_item *pcaplog_item; |
44 | 0 | proto_tree *pcaplog_tree; |
45 | 0 | proto_item *pi_tmp; |
46 | 0 | proto_tree *pt_pcaplog_data; |
47 | |
|
48 | 0 | pcaplog_item = proto_tree_add_item(tree, proto_pcaplog, tvb, 0, -1, ENC_NA); |
49 | 0 | pcaplog_tree = proto_item_add_subtree(pcaplog_item, ett_pcaplog); |
50 | |
|
51 | 0 | proto_tree_add_item_ret_uint(pcaplog_tree, hf_pcaplog_type, tvb, 0, 4, ENC_LITTLE_ENDIAN, &data_type); |
52 | 0 | proto_tree_add_item_ret_uint(pcaplog_tree, hf_pcaplog_length, tvb, 4, 4, ENC_LITTLE_ENDIAN, &data_length); |
53 | 0 | pi_tmp = proto_tree_add_item(pcaplog_tree, hf_pcaplog_data, tvb, 8, data_length, ENC_NA); |
54 | 0 | pt_pcaplog_data = proto_item_add_subtree(pi_tmp, ett_pcaplog_data); |
55 | |
|
56 | 0 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "pcaplog"); |
57 | 0 | col_add_fstr(pinfo->cinfo, COL_INFO, "Custom Block: PEN = %s (%d), will%s be copied", |
58 | 0 | enterprises_lookup(pinfo->rec->rec_header.custom_block_header.pen, "Unknown"), |
59 | 0 | pinfo->rec->rec_header.custom_block_header.pen, |
60 | 0 | pinfo->rec->rec_header.custom_block_header.copy_allowed ? "" : " not"); |
61 | | |
62 | | /* at least data_types 1-3 seem XML-based */ |
63 | 0 | if (data_type > 0 && data_type <= 3) { |
64 | 0 | call_dissector(xml_handle, tvb_new_subset_remaining(tvb, 8), pinfo, pt_pcaplog_data); |
65 | 0 | } else { |
66 | 0 | call_data_dissector(tvb_new_subset_remaining(tvb, 8), pinfo, pt_pcaplog_data); |
67 | 0 | } |
68 | 0 | return tvb_captured_length(tvb); |
69 | 0 | } |
70 | | |
71 | | void |
72 | | proto_register_pcaplog(void) |
73 | 16 | { |
74 | 16 | static hf_register_info hf[] = { |
75 | 16 | { &hf_pcaplog_type, |
76 | 16 | { "Date Type", "pcaplog.data_type", |
77 | 16 | FT_UINT32, BASE_DEC, NULL, 0x0, |
78 | 16 | NULL, HFILL} }, |
79 | | |
80 | 16 | { &hf_pcaplog_length, |
81 | 16 | { "Data Length", "pcaplog.data_length", |
82 | 16 | FT_UINT32, BASE_DEC, NULL, 0x0, |
83 | 16 | NULL, HFILL} }, |
84 | | |
85 | 16 | { &hf_pcaplog_data, |
86 | 16 | { "Data", "pcaplog.data", |
87 | 16 | FT_BYTES, BASE_NONE, NULL, 0x0, |
88 | 16 | NULL, HFILL} }, |
89 | 16 | }; |
90 | | |
91 | 16 | static int *ett[] = { |
92 | 16 | &ett_pcaplog, |
93 | 16 | &ett_pcaplog_data, |
94 | 16 | }; |
95 | | |
96 | 16 | proto_pcaplog = proto_register_protocol("pcaplog", |
97 | 16 | "pcaplog", "pcaplog"); |
98 | | |
99 | 16 | proto_register_field_array(proto_pcaplog, hf, array_length(hf)); |
100 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
101 | | |
102 | 16 | pcaplog_handle = register_dissector("pcaplog", dissect_pcaplog, |
103 | 16 | proto_pcaplog); |
104 | | |
105 | 16 | } |
106 | | |
107 | | void |
108 | | proto_reg_handoff_pcaplog(void) |
109 | 16 | { |
110 | 16 | xml_handle = find_dissector_add_dependency("xml", proto_pcaplog); |
111 | 16 | dissector_add_uint("pcapng_custom_block", PEN_VCTR, pcaplog_handle); |
112 | 16 | } |