pcap-util.c:EXTRACT_BE_U_2:
   78|  5.42k|{
   79|       |	return ((uint16_t)ntohs(*(const uint16_t *)(p)));
   80|  5.42k|}

pcap_freecode:
 1511|  4.75k|{
 1512|  4.75k|	program->bf_len = 0;
 1513|  4.75k|	if (program->bf_insns != NULL) {
  ------------------
  |  Branch (1513:6): [True: 0, False: 4.75k]
  ------------------
 1514|      0|		free(program->bf_insns);
 1515|       |		program->bf_insns = NULL;
 1516|      0|	}
 1517|  4.75k|}

linktype_to_dlt:
 1494|  4.75k|{
 1495|       |	/*
 1496|       |	 * All values in the low matching range were handed out before
 1497|       |	 * assigning DLT_* codes became a free-for-all, so they're the
 1498|       |	 * same on all platforms, and are thus used as the LINKTYPE_*
 1499|       |	 * codes in capture files.
 1500|       |	 */
 1501|  4.75k|	if (linktype >= LINKTYPE_LOW_MATCHING_MIN &&
  ------------------
  |  |  110|  9.51k|#define LINKTYPE_LOW_MATCHING_MIN	0		/* lowest value in this "matching" range */
  ------------------
  |  Branch (1501:6): [True: 4.75k, False: 0]
  ------------------
 1502|  4.75k|	    linktype <= LINKTYPE_LOW_MATCHING_MAX)
  ------------------
  |  |  123|  4.75k|#define LINKTYPE_LOW_MATCHING_MAX	LINKTYPE_FDDI	/* highest value in this "matching" range */
  |  |  ------------------
  |  |  |  |  121|  4.75k|#define LINKTYPE_FDDI		DLT_FDDI
  |  |  |  |  ------------------
  |  |  |  |  |  |   77|  4.75k|#define DLT_FDDI	10	/* FDDI */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1502:6): [True: 1.09k, False: 3.66k]
  ------------------
 1503|  1.09k|		return (linktype);
 1504|       |
 1505|       |#if LINKTYPE_PFSYNC != DLT_PFSYNC
 1506|       |	/*
 1507|       |	 * DLT_PFSYNC has a code on several platforms that's in the
 1508|       |	 * non-matching range, a code on FreeBSD that's in the high
 1509|       |	 * matching range and that's *not* equal to LINKTYPE_PFSYNC,
 1510|       |	 * and has a code on the rmaining platforms that's equal
 1511|       |	 * to LINKTYPE_PFSYNC, which is in the high matching range.
 1512|       |	 *
 1513|       |	 * Map LINKTYPE_PFSYNC to whatever DLT_PFSYNC is on this
 1514|       |	 * platform, if the two aren't equal.
 1515|       |	 */
 1516|       |	if (linktype == LINKTYPE_PFSYNC)
 1517|       |		return (DLT_PFSYNC);
 1518|       |#endif
 1519|       |
 1520|       |	/*
 1521|       |	 * DLT_PKTAP is defined as DLT_USER2 - which is in the high
 1522|       |	 * matching range - on Darwin because Apple used DLT_USER2
 1523|       |	 * on systems that users ran, not just as an internal thing.
 1524|       |	 *
 1525|       |	 * We map LINKTYPE_PKTAP to the platform's DLT_PKTAP for
 1526|       |	 * the benefit of software that's expecting DLT_PKTAP
 1527|       |	 * (even if that's DLT_USER2) for an Apple PKTAP capture.
 1528|       |	 *
 1529|       |	 * (Yes, this is an annoyance if you want to read a
 1530|       |	 * LINKTYPE_USER2 packet as something other than DLT_PKTAP
 1531|       |	 * on a Darwin-based OS, as, on that OS, DLT_PKTAP and DLT_USER2
 1532|       |	 * are the same.  Feel free to complain to Apple about this.)
 1533|       |	 */
 1534|       |#if LINKTYPE_PKTAP != DLT_PKTAP
 1535|       |	if (linktype == LINKTYPE_PKTAP)
 1536|       |		return (DLT_PKTAP);
 1537|       |#endif
 1538|       |
 1539|       |	/*
 1540|       |	 * These DLT_* codes have different values on different
 1541|       |	 * platforms, so we assigned them LINKTYPE_* codes just
 1542|       |	 * below the lower bound of the high matching range;
 1543|       |	 * those values should never be equal to any DLT_*
 1544|       |	 * code, so that should avoid collisions.
 1545|       |	 *
 1546|       |	 * That way, for example, "raw IP" packets will have
 1547|       |	 * LINKTYPE_RAW as the code in all savefiles for
 1548|       |	 * which the code that writes them maps to that
 1549|       |	 * value, regardless of the platform on which they
 1550|       |	 * were written, so they should be readable on all
 1551|       |	 * platforms without having to determine on which
 1552|       |	 * platform they were written.
 1553|       |	 *
 1554|       |	 * We map the LINKTYPE_* codes to the corresponding
 1555|       |	 * DLT_* code on this platform.
 1556|       |	 */
 1557|  3.66k|	if (linktype == LINKTYPE_ATM_RFC1483)
  ------------------
  |  |  152|  3.66k|#define LINKTYPE_ATM_RFC1483	100		/* LLC/SNAP-encapsulated ATM */
  ------------------
  |  Branch (1557:6): [True: 3, False: 3.65k]
  ------------------
 1558|      3|		return (DLT_ATM_RFC1483);
  ------------------
  |  |  109|      3|#define DLT_ATM_RFC1483	11	/* LLC-encapsulated ATM */
  ------------------
 1559|  3.65k|	if (linktype == LINKTYPE_RAW)
  ------------------
  |  |  153|  3.65k|#define LINKTYPE_RAW		101		/* raw IP */
  ------------------
  |  Branch (1559:6): [True: 52, False: 3.60k]
  ------------------
 1560|     52|		return (DLT_RAW);
  ------------------
  |  |  114|     52|#define DLT_RAW		12	/* raw IP */
  ------------------
 1561|  3.60k|	if (linktype == LINKTYPE_SLIP_BSDOS)
  ------------------
  |  |  154|  3.60k|#define LINKTYPE_SLIP_BSDOS	102		/* BSD/OS SLIP BPF header */
  ------------------
  |  Branch (1561:6): [True: 1, False: 3.60k]
  ------------------
 1562|      1|		return (DLT_SLIP_BSDOS);
  ------------------
  |  |  130|      1|#define DLT_SLIP_BSDOS	15	/* BSD/OS Serial Line IP */
  ------------------
 1563|  3.60k|	if (linktype == LINKTYPE_PPP_BSDOS)
  ------------------
  |  |  155|  3.60k|#define LINKTYPE_PPP_BSDOS	103		/* BSD/OS PPP BPF header */
  ------------------
  |  Branch (1563:6): [True: 4, False: 3.60k]
  ------------------
 1564|      4|		return (DLT_PPP_BSDOS);
  ------------------
  |  |  131|      4|#define DLT_PPP_BSDOS	16	/* BSD/OS Point-to-point Protocol */
  ------------------
 1565|       |
 1566|       |	/*
 1567|       |	 * These DLT_* codes were originally defined on some platform,
 1568|       |	 * and weren't defined on other platforms.
 1569|       |	 *
 1570|       |	 * At least some of them have values, on at least one platform,
 1571|       |	 * that collide with other DLT_* codes on other platforms, e.g.
 1572|       |	 * DLT_LOOP, so we don't just define them, on all platforms,
 1573|       |	 * as having the same value as on the original platform.
 1574|       |	 *
 1575|       |	 * Therefore, we assigned new LINKTYPE_* codes to them, and,
 1576|       |	 * on the platforms where they weren't originally defined,
 1577|       |	 * define the DLT_* codes to have the same value as the
 1578|       |	 * corresponding LINKTYPE_* codes.
 1579|       |	 *
 1580|       |	 * This means that, for capture files with the original
 1581|       |	 * platform's DLT_* code rather than the LINKTYPE_* code
 1582|       |	 * as a link-layer type, we will recognize those types
 1583|       |	 * on that platform, but not on other platforms.
 1584|       |	 *
 1585|       |	 * We map the LINKTYPE_* codes to the corresponding
 1586|       |	 * DLT_* code on platforms where the two codes differ..
 1587|       |	 */
 1588|       |#ifdef DLT_FR
 1589|       |	/* BSD/OS Frame Relay */
 1590|       |	if (linktype == LINKTYPE_FRELAY)
 1591|       |		return (DLT_FR);
 1592|       |#endif
 1593|       |#if LINKTYPE_NETBSD_HDLC != DLT_HDLC
 1594|       |	/* NetBSD HDLC */
 1595|       |	if (linktype == LINKTYPE_NETBSD_HDLC)
 1596|       |		return (DLT_HDLC);
 1597|       |#endif
 1598|       |#if LINKTYPE_C_HDLC != DLT_C_HDLC
 1599|       |	/* BSD/OS Cisco HDLC */
 1600|       |	if (linktype == LINKTYPE_C_HDLC)
 1601|       |		return (DLT_C_HDLC);
 1602|       |#endif
 1603|       |#if LINKTYPE_LOOP != DLT_LOOP
 1604|       |	/* OpenBSD DLT_LOOP */
 1605|       |	if (linktype == LINKTYPE_LOOP)
 1606|       |		return (DLT_LOOP);
 1607|       |#endif
 1608|       |#if LINKTYPE_ENC != DLT_ENC
 1609|       |	/* OpenBSD DLT_ENC */
 1610|       |	if (linktype == LINKTYPE_ENC)
 1611|       |		return (DLT_ENC);
 1612|       |#endif
 1613|       |
 1614|       |	/*
 1615|       |	 * These DLT_* codes are not on all platforms, but, so far,
 1616|       |	 * there don't appear to be any platforms that define
 1617|       |	 * other codes with those values; we map them to
 1618|       |	 * different LINKTYPE_* values anyway, just in case.
 1619|       |	 *
 1620|       |	 * LINKTYPE_ATM_CLIP is a special case.  DLT_ATM_CLIP is
 1621|       |	 * not on all platforms, but, so far, there don't appear
 1622|       |	 * to be any platforms that define it as anything other
 1623|       |	 * than 19; we define LINKTYPE_ATM_CLIP as something
 1624|       |	 * other than 19, just in case.  That value is in the
 1625|       |	 * high matching range, so we have to check for it.
 1626|       |	 */
 1627|       |	/* Linux ATM Classical IP */
 1628|  3.60k|	if (linktype == LINKTYPE_ATM_CLIP)
  ------------------
  |  |  171|  3.60k|#define LINKTYPE_ATM_CLIP	106		/* Linux Classical IP over ATM */
  ------------------
  |  Branch (1628:6): [True: 3, False: 3.59k]
  ------------------
 1629|      3|		return (DLT_ATM_CLIP);
  ------------------
  |  |  225|      3|#define DLT_ATM_CLIP	19	/* Linux Classical IP over ATM */
  ------------------
 1630|       |
 1631|       |	/*
 1632|       |	 * For all other values, return the linktype code as the
 1633|       |	 * DLT_* code.
 1634|       |	 *
 1635|       |	 * If the code is in the high matching range, the
 1636|       |	 * DLT_* code is the same as the LINKTYPE_* code.
 1637|       |	 *
 1638|       |	 * If the code is greater than the maximum value in
 1639|       |	 * the high matching range, it may be a value from
 1640|       |	 * a newer version of libpcap; we provide it in case
 1641|       |	 * the program' capable of handling it.
 1642|       |	 *
 1643|       |	 * If the code is less than the minimum value in the
 1644|       |	 * high matching range, it might be from a capture
 1645|       |	 * written by code that doesn't map non-matching range
 1646|       |	 * DLT_* codes to the appropriate LINKTYPE_* code, so
 1647|       |	 * we'll just pass it through, so that *if it was written
 1648|       |	 * on this platform* it will be interpreted correctly.
 1649|       |	 * (We don't know whether it was written on this platform,
 1650|       |	 * but at least this way there's *some* chance that it
 1651|       |	 * can be read.)
 1652|       |	 */
 1653|  3.59k|	return linktype;
 1654|  3.60k|}
max_snaplen_for_dlt:
 1675|  49.1k|{
 1676|  49.1k|	switch (dlt) {
 1677|       |
 1678|  1.39k|	case DLT_DBUS:
  ------------------
  |  | 1173|  1.39k|#define DLT_DBUS		231
  ------------------
  |  Branch (1678:2): [True: 1.39k, False: 47.7k]
  ------------------
 1679|  1.39k|		return 128*1024*1024;
 1680|       |
 1681|    374|	case DLT_EBHSCR:
  ------------------
  |  | 1540|    374|#define DLT_EBHSCR	        279
  ------------------
  |  Branch (1681:2): [True: 374, False: 48.7k]
  ------------------
 1682|    374|		return 8*1024*1024;
 1683|       |
 1684|    421|	case DLT_USBPCAP:
  ------------------
  |  | 1305|    421|#define DLT_USBPCAP		249
  ------------------
  |  Branch (1684:2): [True: 421, False: 48.7k]
  ------------------
 1685|    421|		return 1024*1024;
 1686|       |
 1687|  46.9k|	default:
  ------------------
  |  Branch (1687:2): [True: 46.9k, False: 2.18k]
  ------------------
 1688|  46.9k|		return MAXIMUM_SNAPLEN;
  ------------------
  |  |  158|  46.9k|#define MAXIMUM_SNAPLEN		262144
  ------------------
 1689|  49.1k|	}
 1690|  49.1k|}

pcap-util.c:is_isochronous_transfer_completion:
   43|  2.55k|{
   44|  2.55k|	return (hdr->transfer_type == URB_ISOCHRONOUS &&
  ------------------
  |  |   43|  5.10k|#define URB_ISOCHRONOUS   0x0
  ------------------
  |  Branch (44:10): [True: 2.33k, False: 217]
  ------------------
   45|  2.33k|	    hdr->event_type == URB_COMPLETE &&
  ------------------
  |  |   52|  4.88k|#define URB_COMPLETE      'C'
  ------------------
  |  Branch (45:6): [True: 2.11k, False: 222]
  ------------------
   46|  2.11k|	    (hdr->endpoint_number & URB_TRANSFER_IN));
  ------------------
  |  |   42|  2.11k|#define URB_TRANSFER_IN   0x80
  ------------------
  |  Branch (46:6): [True: 2.10k, False: 6]
  ------------------
   47|  2.55k|}
pcap-util.c:iso_pseudo_header_len:
   55|  4.74k|{
   56|  4.74k|	return (sizeof(pcap_usb_header_mmapped) +
   57|  4.74k|	    usb_hdr->ndesc * sizeof (usb_isodesc));
   58|  4.74k|}
pcap-util.c:incoming_isochronous_transfer_completed_len:
   71|  1.05k|{
   72|  1.05k|	const pcap_usb_header_mmapped *hdr;
   73|  1.05k|	u_int bytes_left;
   74|  1.05k|	const usb_isodesc *descs;
   75|  1.05k|	u_int pre_truncation_data_len;
   76|       |
   77|       |	/*
   78|       |	 * All callers of this routine must ensure that pkth->caplen is
   79|       |	 * >= sizeof (pcap_usb_header_mmapped).
   80|       |	 */
   81|  1.05k|	bytes_left = phdr->caplen;
   82|  1.05k|	bytes_left -= sizeof (pcap_usb_header_mmapped);
   83|       |
   84|  1.05k|	hdr = (const pcap_usb_header_mmapped *) bp;
   85|  1.05k|	descs = (const usb_isodesc *) (bp + sizeof(pcap_usb_header_mmapped));
   86|       |
   87|       |	/*
   88|       |	 * Find the end of the last chunk of data in the buffer
   89|       |	 * referred to by the isochronous descriptors; that indicates
   90|       |	 * how far into the buffer the data would have gone.
   91|       |	 *
   92|       |	 * Make sure we don't run past the end of the captured data
   93|       |	 * while processing the isochronous descriptors.
   94|       |	 */
   95|  1.05k|	pre_truncation_data_len = 0;
   96|  1.05k|	for (uint32_t desc = 0;
   97|  3.94k|	    desc < hdr->ndesc && bytes_left >= sizeof (usb_isodesc);
  ------------------
  |  Branch (97:6): [True: 2.89k, False: 1.05k]
  |  Branch (97:27): [True: 2.89k, False: 0]
  ------------------
   98|  2.89k|	    desc++, bytes_left -= sizeof (usb_isodesc)) {
   99|  2.89k|		u_int desc_end;
  100|       |
  101|  2.89k|		if (descs[desc].len != 0) {
  ------------------
  |  Branch (101:7): [True: 1.96k, False: 929]
  ------------------
  102|       |			/*
  103|       |			 * Compute the end offset of the data
  104|       |			 * for this descriptor, i.e. the offset
  105|       |			 * of the byte after the data.  Clamp
  106|       |			 * the sum at UINT_MAX, so that it fits
  107|       |			 * in a u_int.
  108|       |			 */
  109|  1.96k|			desc_end = u_int_sum(descs[desc].offset,
  110|  1.96k|			    descs[desc].len);
  111|  1.96k|			if (desc_end > pre_truncation_data_len)
  ------------------
  |  Branch (111:8): [True: 844, False: 1.11k]
  ------------------
  112|    844|				pre_truncation_data_len = desc_end;
  113|  1.96k|		}
  114|  2.89k|	}
  115|       |
  116|       |	/*
  117|       |	 * Return the sum of the total header length (memory-mapped
  118|       |	 * header and ISO descriptors) and the data length, clamped
  119|       |	 * to UINT_MAX.
  120|       |	 *
  121|       |	 * We've made sure that the number of descriptors is
  122|       |	 * <= USB_MAXDESC, so we know that the total size,
  123|       |	 * in bytes, of the descriptors fits in a 32-bit
  124|       |	 * integer.
  125|       |	 */
  126|  1.05k|	return (u_int_sum(iso_pseudo_header_len(hdr), pre_truncation_data_len));
  127|  1.05k|}
pcap-util.c:u_int_sum:
   34|  3.01k|{
   35|  3.01k|	return (((b) <= UINT_MAX - (a)) ? (a) + (b) : UINT_MAX);
  ------------------
  |  Branch (35:10): [True: 2.05k, False: 960]
  ------------------
   36|  3.01k|}

pcapint_post_process:
  508|  40.6k|{
  509|  40.6k|	if (swapped)
  ------------------
  |  Branch (509:6): [True: 28.5k, False: 12.0k]
  ------------------
  510|  28.5k|		swap_pseudo_headers(linktype, hdr, data);
  511|       |
  512|       |	/*
  513|       |	 * Is this a memory-mapped Linux USB capture?
  514|       |	 */
  515|  40.6k|	if (linktype == DLT_USB_LINUX_MMAPPED) {
  ------------------
  |  | 1036|  40.6k|#define DLT_USB_LINUX_MMAPPED	220
  ------------------
  |  Branch (515:6): [True: 7.65k, False: 32.9k]
  ------------------
  516|       |		/*
  517|       |		 * Yes.
  518|       |		 *
  519|       |		 * In older versions of libpcap, in memory-mapped Linux
  520|       |		 * USB captures, the original length of completion events
  521|       |		 * for incoming isochronous transfers was miscalculated;
  522|       |		 * it needed to be calculated based on the offsets and
  523|       |		 * lengths in the descriptors, not on the raw URB length,
  524|       |		 * but it wasn't.
  525|       |		 *
  526|       |		 * If this packet contains transferred data (yes, data_flag
  527|       |		 * is 0 if we *do* have data), it's a completion event
  528|       |		 * for an incoming isochronous transfer, and the
  529|       |		 * transfer length appears to have been calculated
  530|       |		 * from the raw URB length, fix it.
  531|       |		 *
  532|       |		 * We only do this if we have the full USB pseudo-header,
  533|       |		 * because we will have to look at that header and at
  534|       |		 * all of the isochronous descriptors.
  535|       |		 */
  536|  7.65k|		if (hdr->caplen < sizeof (pcap_usb_header_mmapped)) {
  ------------------
  |  Branch (536:7): [True: 4.15k, False: 3.49k]
  ------------------
  537|       |			/*
  538|       |			 * We don't have the full pseudo-header.
  539|       |			 */
  540|  4.15k|			return;
  541|  4.15k|		}
  542|       |
  543|  3.49k|		const pcap_usb_header_mmapped *usb_hdr =
  544|  3.49k|		    (const pcap_usb_header_mmapped *) data;
  545|       |
  546|       |		/*
  547|       |		 * Make sure the number of descriptors is sane.
  548|       |		 *
  549|       |		 * The Linux binary USB monitor code limits the number of
  550|       |		 * isochronous descriptors to 128; if the number in the file
  551|       |		 * is larger than that, either 1) the file's been damaged
  552|       |		 * or 2) the file was produced after the number was raised
  553|       |		 * in the kernel.
  554|       |		 *
  555|       |		 * In case 1), the number can't be trusted, so don't rely on
  556|       |		 * it to attempt to fix the original length field in the pcap
  557|       |		 * or pcapng header.
  558|       |		 *
  559|       |		 * In case 2), the system was probably running a version of
  560|       |		 * libpcap that didn't miscalculate the original length, so
  561|       |		 * it probably doesn't need to be fixed.
  562|       |		 *
  563|       |		 * This avoids the possibility of the product of the number of
  564|       |		 * descriptors and the size of descriptors won't overflow an
  565|       |		 * unsigned 32-bit integer.
  566|       |		 */
  567|  3.49k|		if (usb_hdr->ndesc > USB_MAXDESC)
  ------------------
  |  |  132|  3.49k|#define USB_MAXDESC	128
  ------------------
  |  Branch (567:7): [True: 706, False: 2.79k]
  ------------------
  568|    706|			return;
  569|       |
  570|  2.79k|		if (!usb_hdr->data_flag &&
  ------------------
  |  Branch (570:7): [True: 2.55k, False: 241]
  ------------------
  571|  2.55k|		    is_isochronous_transfer_completion(usb_hdr) &&
  ------------------
  |  Branch (571:7): [True: 2.10k, False: 445]
  ------------------
  572|  2.10k|		    packet_length_might_be_wrong(hdr, usb_hdr)) {
  ------------------
  |  Branch (572:7): [True: 1.58k, False: 516]
  ------------------
  573|  1.58k|			u_int len;
  574|       |
  575|       |			/*
  576|       |			 * Make sure we have all of the descriptors,
  577|       |			 * as we will have to look at all of them.
  578|       |			 *
  579|       |			 * If not, we don't bother trying to fix
  580|       |			 * anything.
  581|       |			 */
  582|  1.58k|			if (hdr->caplen < iso_pseudo_header_len(usb_hdr))
  ------------------
  |  Branch (582:8): [True: 536, False: 1.05k]
  ------------------
  583|    536|				return;
  584|       |
  585|       |			/*
  586|       |			 * Calculate what the length should have been.
  587|       |			 */
  588|  1.05k|			len = incoming_isochronous_transfer_completed_len(hdr,
  589|  1.05k|			    data);
  590|       |
  591|       |			/*
  592|       |			 * len is the smaller of UINT_MAX and the total
  593|       |			 * header plus data length.  That's guaranteed
  594|       |			 * to fit in a UINT_MAX.
  595|       |			 *
  596|       |			 * Don't reduce the original length to a value
  597|       |			 * below the captured length, however, as that
  598|       |			 * is bogus.
  599|       |			 */
  600|  1.05k|			if (len >= hdr->caplen)
  ------------------
  |  Branch (600:8): [True: 837, False: 216]
  ------------------
  601|    837|				hdr->len = len;
  602|       |
  603|       |			/*
  604|       |			 * If the captured length is greater than the
  605|       |			 * length, use the captured length.
  606|       |			 *
  607|       |			 * For completion events for incoming isochronous
  608|       |			 * transfers, it's based on data_len, which is
  609|       |			 * calculated the same way we calculated
  610|       |			 * pre_truncation_data_len above, except that
  611|       |			 * it has access to all the isochronous descriptors,
  612|       |			 * not just the ones that the kernel were able to
  613|       |			 * provide us or, for a capture file, that weren't
  614|       |			 * sliced off by a snapshot length.
  615|       |			 *
  616|       |			 * However, it might have been reduced by the USB
  617|       |			 * capture mechanism arbitrarily limiting the amount
  618|       |			 * of data it provides to userland, or by the libpcap
  619|       |			 * capture code limiting it to being no more than the
  620|       |			 * snapshot, so we don't want to just use it all the
  621|       |			 * time; we only do so to try to get a better estimate
  622|       |			 * of the actual length - and to make sure the
  623|       |			 * original length is always >= the captured length.
  624|       |			 */
  625|  1.05k|			if (hdr->caplen > hdr->len)
  ------------------
  |  Branch (625:8): [True: 211, False: 842]
  ------------------
  626|    211|				hdr->len = hdr->caplen;
  627|  1.05k|		}
  628|  2.79k|	}
  629|  40.6k|}
pcap-util.c:swap_pseudo_headers:
  453|  28.5k|{
  454|       |	/*
  455|       |	 * Convert pseudo-headers from the byte order of
  456|       |	 * the host on which the file was saved to our
  457|       |	 * byte order, as necessary.
  458|       |	 */
  459|  28.5k|	switch (linktype) {
  ------------------
  |  Branch (459:10): [True: 19.8k, False: 8.67k]
  ------------------
  460|       |
  461|  2.47k|	case DLT_PFLOG:
  ------------------
  |  |  368|  2.47k|#define DLT_PFLOG	117
  ------------------
  |  Branch (461:2): [True: 2.47k, False: 26.0k]
  ------------------
  462|  2.47k|		swap_pflog_header(hdr, data);
  463|  2.47k|		break;
  464|       |
  465|  3.41k|	case DLT_LINUX_SLL:
  ------------------
  |  |  348|  3.41k|#define DLT_LINUX_SLL	113
  ------------------
  |  Branch (465:2): [True: 3.41k, False: 25.1k]
  ------------------
  466|  3.41k|		swap_linux_sll_socketcan_header(hdr, data);
  467|  3.41k|		break;
  468|       |
  469|  3.46k|	case DLT_LINUX_SLL2:
  ------------------
  |  | 1512|  3.46k|#define DLT_LINUX_SLL2	276
  ------------------
  |  Branch (469:2): [True: 3.46k, False: 25.0k]
  ------------------
  470|  3.46k|		swap_linux_sll2_socketcan_header(hdr, data);
  471|  3.46k|		break;
  472|       |
  473|  2.61k|	case DLT_USB_LINUX:
  ------------------
  |  |  799|  2.61k|#define DLT_USB_LINUX		189
  ------------------
  |  Branch (473:2): [True: 2.61k, False: 25.9k]
  ------------------
  474|  2.61k|		swap_linux_usb_header(hdr, data, 0);
  475|  2.61k|		break;
  476|       |
  477|  6.31k|	case DLT_USB_LINUX_MMAPPED:
  ------------------
  |  | 1036|  6.31k|#define DLT_USB_LINUX_MMAPPED	220
  ------------------
  |  Branch (477:2): [True: 6.31k, False: 22.2k]
  ------------------
  478|  6.31k|		swap_linux_usb_header(hdr, data, 1);
  479|  6.31k|		break;
  480|       |
  481|  1.59k|	case DLT_NFLOG:
  ------------------
  |  | 1220|  1.59k|#define DLT_NFLOG		239
  ------------------
  |  Branch (481:2): [True: 1.59k, False: 26.9k]
  ------------------
  482|  1.59k|		swap_nflog_header(hdr, data);
  483|  1.59k|		break;
  484|  28.5k|	}
  485|  28.5k|}
pcap-util.c:swap_pflog_header:
   52|  2.47k|{
   53|  2.47k|	u_int caplen = hdr->caplen;
   54|  2.47k|	u_int length = hdr->len;
   55|  2.47k|	u_int pfloghdr_length;
   56|  2.47k|	struct pfloghdr *pflhdr = (struct pfloghdr *)buf;
   57|       |
   58|  2.47k|	if (caplen < (u_int) (offsetof(struct pfloghdr, uid) + sizeof pflhdr->uid) ||
  ------------------
  |  Branch (58:6): [True: 382, False: 2.08k]
  ------------------
   59|  2.08k|	    length < (u_int) (offsetof(struct pfloghdr, uid) + sizeof pflhdr->uid)) {
  ------------------
  |  Branch (59:6): [True: 195, False: 1.89k]
  ------------------
   60|       |		/* Not enough data to have the uid field */
   61|    577|		return;
   62|    577|	}
   63|       |
   64|  1.89k|	pfloghdr_length = pflhdr->length;
   65|       |
   66|  1.89k|	if (pfloghdr_length < (u_int) (offsetof(struct pfloghdr, uid) + sizeof pflhdr->uid)) {
  ------------------
  |  Branch (66:6): [True: 201, False: 1.69k]
  ------------------
   67|       |		/* Header doesn't include uid field */
   68|    201|		return;
   69|    201|	}
   70|  1.69k|	pflhdr->uid = PCAP_BSWAP_32(pflhdr->uid);
  ------------------
  |  |   78|  1.69k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
   71|       |
   72|  1.69k|	if (caplen < (u_int) (offsetof(struct pfloghdr, pid) + sizeof pflhdr->pid) ||
  ------------------
  |  Branch (72:6): [True: 200, False: 1.49k]
  ------------------
   73|  1.49k|	    length < (u_int) (offsetof(struct pfloghdr, pid) + sizeof pflhdr->pid)) {
  ------------------
  |  Branch (73:6): [True: 70, False: 1.42k]
  ------------------
   74|       |		/* Not enough data to have the pid field */
   75|    270|		return;
   76|    270|	}
   77|  1.42k|	if (pfloghdr_length < (u_int) (offsetof(struct pfloghdr, pid) + sizeof pflhdr->pid)) {
  ------------------
  |  Branch (77:6): [True: 234, False: 1.18k]
  ------------------
   78|       |		/* Header doesn't include pid field */
   79|    234|		return;
   80|    234|	}
   81|  1.18k|	pflhdr->pid = PCAP_BSWAP_32(pflhdr->pid);
  ------------------
  |  |   78|  1.18k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
   82|       |
   83|  1.18k|	if (caplen < (u_int) (offsetof(struct pfloghdr, rule_uid) + sizeof pflhdr->rule_uid) ||
  ------------------
  |  Branch (83:6): [True: 230, False: 959]
  ------------------
   84|    959|	    length < (u_int) (offsetof(struct pfloghdr, rule_uid) + sizeof pflhdr->rule_uid)) {
  ------------------
  |  Branch (84:6): [True: 68, False: 891]
  ------------------
   85|       |		/* Not enough data to have the rule_uid field */
   86|    298|		return;
   87|    298|	}
   88|    891|	if (pfloghdr_length < (u_int) (offsetof(struct pfloghdr, rule_uid) + sizeof pflhdr->rule_uid)) {
  ------------------
  |  Branch (88:6): [True: 201, False: 690]
  ------------------
   89|       |		/* Header doesn't include rule_uid field */
   90|    201|		return;
   91|    201|	}
   92|    690|	pflhdr->rule_uid = PCAP_BSWAP_32(pflhdr->rule_uid);
  ------------------
  |  |   78|    690|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
   93|       |
   94|    690|	if (caplen < (u_int) (offsetof(struct pfloghdr, rule_pid) + sizeof pflhdr->rule_pid) ||
  ------------------
  |  Branch (94:6): [True: 238, False: 452]
  ------------------
   95|    452|	    length < (u_int) (offsetof(struct pfloghdr, rule_pid) + sizeof pflhdr->rule_pid)) {
  ------------------
  |  Branch (95:6): [True: 35, False: 417]
  ------------------
   96|       |		/* Not enough data to have the rule_pid field */
   97|    273|		return;
   98|    273|	}
   99|    417|	if (pfloghdr_length < (u_int) (offsetof(struct pfloghdr, rule_pid) + sizeof pflhdr->rule_pid)) {
  ------------------
  |  Branch (99:6): [True: 198, False: 219]
  ------------------
  100|       |		/* Header doesn't include rule_pid field */
  101|    198|		return;
  102|    198|	}
  103|    219|	pflhdr->rule_pid = PCAP_BSWAP_32(pflhdr->rule_pid);
  ------------------
  |  |   78|    219|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  104|    219|}
pcap-util.c:swap_linux_sll_socketcan_header:
  191|  3.41k|{
  192|  3.41k|	u_int caplen = hdr->caplen;
  193|  3.41k|	u_int length = hdr->len;
  194|  3.41k|	struct sll_header *shdr = (struct sll_header *)buf;
  195|       |
  196|  3.41k|	if (caplen < (u_int) sizeof(struct sll_header) ||
  ------------------
  |  Branch (196:6): [True: 620, False: 2.79k]
  ------------------
  197|  2.79k|	    length < (u_int) sizeof(struct sll_header)) {
  ------------------
  |  Branch (197:6): [True: 203, False: 2.59k]
  ------------------
  198|       |		/* Not enough data to have the protocol field */
  199|    823|		return;
  200|    823|	}
  201|       |
  202|       |	/*
  203|       |	 * Byte-swap what needs to be byte-swapped.
  204|       |	 */
  205|  2.59k|	swap_socketcan_header(EXTRACT_BE_U_2(&shdr->sll_protocol),
  206|  2.59k|	    caplen - (u_int) sizeof(struct sll_header),
  207|  2.59k|	    length - (u_int) sizeof(struct sll_header),
  208|  2.59k|	    buf + sizeof(struct sll_header));
  209|  2.59k|}
pcap-util.c:swap_socketcan_header:
  124|  5.42k|{
  125|  5.42k|	pcap_can_socketcan_hdr *hdrp;
  126|  5.42k|	pcap_can_socketcan_xl_hdr *xl_hdrp;
  127|       |
  128|  5.42k|	switch (protocol) {
  129|       |
  130|    987|	case LINUX_SLL_P_CAN:
  ------------------
  |  |  142|    987|#define LINUX_SLL_P_CAN		0x000C	/* CAN frames, with SocketCAN pseudo-headers */
  ------------------
  |  Branch (130:2): [True: 987, False: 4.43k]
  ------------------
  131|  1.83k|	case LINUX_SLL_P_CANFD:
  ------------------
  |  |  143|  1.83k|#define LINUX_SLL_P_CANFD	0x000D	/* CAN FD frames, with SocketCAN pseudo-headers */
  ------------------
  |  Branch (131:2): [True: 844, False: 4.57k]
  ------------------
  132|       |		/*
  133|       |		 * CAN classic/CAN FD packet; fix up the packet's header
  134|       |		 * by byte-swapping the CAN ID field.
  135|       |		 */
  136|  1.83k|		hdrp = (pcap_can_socketcan_hdr *)buf;
  137|  1.83k|		if (caplen < (u_int) (offsetof(pcap_can_socketcan_hdr, can_id) + sizeof hdrp->can_id) ||
  ------------------
  |  Branch (137:7): [True: 626, False: 1.20k]
  ------------------
  138|  1.21k|		    length < (u_int) (offsetof(pcap_can_socketcan_hdr, can_id) + sizeof hdrp->can_id)) {
  ------------------
  |  Branch (138:7): [True: 588, False: 617]
  ------------------
  139|       |			/* Not enough data to have the can_id field */
  140|  1.21k|			return;
  141|  1.21k|		}
  142|    617|		hdrp->can_id = PCAP_BSWAP_32(hdrp->can_id);
  ------------------
  |  |   78|    617|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  143|    617|		break;
  144|       |
  145|  3.04k|	case LINUX_SLL_P_CANXL:
  ------------------
  |  |  144|  3.04k|#define LINUX_SLL_P_CANXL	0x000E	/* CAN XL frames, with SocketCAN pseudo-headers */
  ------------------
  |  Branch (145:2): [True: 3.04k, False: 2.38k]
  ------------------
  146|       |		/*
  147|       |		 * CAN XL packet; fix up the packet's header by
  148|       |		 * byte-swapping the priority/VCID field, the
  149|       |		 * payload length, and the acceptance field.
  150|       |		 */
  151|  3.04k|		xl_hdrp = (pcap_can_socketcan_xl_hdr *)buf;
  152|  3.04k|		if (caplen < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, priority_vcid) + sizeof xl_hdrp->priority_vcid) ||
  ------------------
  |  Branch (152:7): [True: 409, False: 2.63k]
  ------------------
  153|  2.63k|		    length < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, priority_vcid) + sizeof xl_hdrp->priority_vcid)) {
  ------------------
  |  Branch (153:7): [True: 435, False: 2.19k]
  ------------------
  154|       |			/* Not enough data to have the priority_vcid field */
  155|    844|			return;
  156|    844|		}
  157|  2.19k|		xl_hdrp->priority_vcid = PCAP_BSWAP_32(xl_hdrp->priority_vcid);
  ------------------
  |  |   78|  2.19k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  158|  2.19k|		if (caplen < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, payload_length) + sizeof xl_hdrp->payload_length) ||
  ------------------
  |  Branch (158:7): [True: 478, False: 1.72k]
  ------------------
  159|  1.72k|		    length < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, payload_length) + sizeof xl_hdrp->payload_length)) {
  ------------------
  |  Branch (159:7): [True: 394, False: 1.32k]
  ------------------
  160|       |			/* Not enough data to have the payload_length field */
  161|    872|			return;
  162|    872|		}
  163|  1.32k|		xl_hdrp->payload_length = PCAP_BSWAP_16(xl_hdrp->payload_length);
  ------------------
  |  |   88|  1.32k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  164|  1.32k|		if (caplen < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, acceptance_field) + sizeof xl_hdrp->acceptance_field) ||
  ------------------
  |  Branch (164:7): [True: 494, False: 832]
  ------------------
  165|    832|		    length < (u_int) (offsetof(pcap_can_socketcan_xl_hdr, acceptance_field) + sizeof xl_hdrp->acceptance_field)) {
  ------------------
  |  Branch (165:7): [True: 266, False: 566]
  ------------------
  166|       |			/* Not enough data to have the acceptance_field field */
  167|    760|			return;
  168|    760|		}
  169|    566|		xl_hdrp->acceptance_field = PCAP_BSWAP_32(xl_hdrp->acceptance_field);
  ------------------
  |  |   78|    566|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  170|    566|		break;
  171|       |
  172|    549|	default:
  ------------------
  |  Branch (172:2): [True: 549, False: 4.87k]
  ------------------
  173|       |		/*
  174|       |		 * Not a CAN packet; nothing to do.
  175|       |		 */
  176|    549|		break;
  177|  5.42k|	}
  178|  5.42k|}
pcap-util.c:swap_linux_sll2_socketcan_header:
  216|  3.46k|{
  217|  3.46k|	u_int caplen = hdr->caplen;
  218|  3.46k|	u_int length = hdr->len;
  219|  3.46k|	struct sll2_header *shdr = (struct sll2_header *)buf;
  220|       |
  221|  3.46k|	if (caplen < (u_int) sizeof(struct sll2_header) ||
  ------------------
  |  Branch (221:6): [True: 432, False: 3.03k]
  ------------------
  222|  3.03k|	    length < (u_int) sizeof(struct sll2_header)) {
  ------------------
  |  Branch (222:6): [True: 203, False: 2.83k]
  ------------------
  223|       |		/* Not enough data to have the protocol field */
  224|    635|		return;
  225|    635|	}
  226|       |
  227|       |	/*
  228|       |	 * Byte-swap what needs to be byte-swapped.
  229|       |	 */
  230|  2.83k|	swap_socketcan_header(EXTRACT_BE_U_2(&shdr->sll2_protocol),
  231|  2.83k|	    caplen - (u_int) sizeof(struct sll2_header),
  232|  2.83k|	    length - (u_int) sizeof(struct sll2_header),
  233|  2.83k|	    buf + sizeof(struct sll2_header));
  234|  2.83k|}
pcap-util.c:swap_linux_usb_header:
  248|  8.93k|{
  249|  8.93k|	pcap_usb_header_mmapped *uhdr = (pcap_usb_header_mmapped *)buf;
  250|  8.93k|	bpf_u_int32 offset = 0;
  251|       |
  252|       |	/*
  253|       |	 * "offset" is the offset *past* the field we're swapping;
  254|       |	 * we skip the field *before* checking to make sure
  255|       |	 * the captured data length includes the entire field.
  256|       |	 */
  257|       |
  258|       |	/*
  259|       |	 * The URB id is a totally opaque value; do we really need to
  260|       |	 * convert it to the reading host's byte order???
  261|       |	 */
  262|  8.93k|	offset += 8;			/* skip past id */
  263|  8.93k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (263:6): [True: 1.01k, False: 7.91k]
  ------------------
  264|  1.01k|		return;
  265|  7.91k|	uhdr->id = swap_4_byte_aligned_uint64(uhdr->id);
  266|       |
  267|  7.91k|	offset += 4;			/* skip past various 1-byte fields */
  268|       |
  269|  7.91k|	offset += 2;			/* skip past bus_id */
  270|  7.91k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (270:6): [True: 398, False: 7.51k]
  ------------------
  271|    398|		return;
  272|  7.51k|	uhdr->bus_id = PCAP_BSWAP_16(uhdr->bus_id);
  ------------------
  |  |   88|  7.51k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  273|       |
  274|  7.51k|	offset += 2;			/* skip past various 1-byte fields */
  275|       |
  276|  7.51k|	offset += 8;			/* skip past ts_sec */
  277|  7.51k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (277:6): [True: 406, False: 7.11k]
  ------------------
  278|    406|		return;
  279|  7.11k|	uhdr->ts_sec = swap_4_byte_aligned_int64(uhdr->ts_sec);
  280|       |
  281|  7.11k|	offset += 4;			/* skip past ts_usec */
  282|  7.11k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (282:6): [True: 406, False: 6.70k]
  ------------------
  283|    406|		return;
  284|  6.70k|	uhdr->ts_usec = PCAP_BSWAP_32(uhdr->ts_usec);
  ------------------
  |  |   78|  6.70k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  285|       |
  286|  6.70k|	offset += 4;			/* skip past status */
  287|  6.70k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (287:6): [True: 397, False: 6.31k]
  ------------------
  288|    397|		return;
  289|  6.31k|	uhdr->status = PCAP_BSWAP_32(uhdr->status);
  ------------------
  |  |   78|  6.31k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  290|       |
  291|  6.31k|	offset += 4;			/* skip past urb_len */
  292|  6.31k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (292:6): [True: 421, False: 5.88k]
  ------------------
  293|    421|		return;
  294|  5.88k|	uhdr->urb_len = PCAP_BSWAP_32(uhdr->urb_len);
  ------------------
  |  |   78|  5.88k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  295|       |
  296|  5.88k|	offset += 4;			/* skip past data_len */
  297|  5.88k|	if (hdr->caplen < offset)
  ------------------
  |  Branch (297:6): [True: 392, False: 5.49k]
  ------------------
  298|    392|		return;
  299|  5.49k|	uhdr->data_len = PCAP_BSWAP_32(uhdr->data_len);
  ------------------
  |  |   78|  5.49k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  300|       |
  301|  5.49k|	if (uhdr->transfer_type == URB_ISOCHRONOUS) {
  ------------------
  |  |   43|  5.49k|#define URB_ISOCHRONOUS   0x0
  ------------------
  |  Branch (301:6): [True: 4.23k, False: 1.25k]
  ------------------
  302|  4.23k|		offset += 4;			/* skip past s.iso.error_count */
  303|  4.23k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (303:7): [True: 393, False: 3.84k]
  ------------------
  304|    393|			return;
  305|  3.84k|		uhdr->s.iso.error_count = PCAP_BSWAP_32(uhdr->s.iso.error_count);
  ------------------
  |  |   78|  3.84k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  306|       |
  307|  3.84k|		offset += 4;			/* skip past s.iso.numdesc */
  308|  3.84k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (308:7): [True: 392, False: 3.45k]
  ------------------
  309|    392|			return;
  310|  3.45k|		uhdr->s.iso.numdesc = PCAP_BSWAP_32(uhdr->s.iso.numdesc);
  ------------------
  |  |   78|  3.45k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  311|  3.45k|	} else
  312|  1.25k|		offset += 8;			/* skip USB setup header */
  313|       |
  314|       |	/*
  315|       |	 * With the old header, there are no isochronous descriptors
  316|       |	 * after the header.
  317|       |	 *
  318|       |	 * With the new header, the actual number of descriptors in
  319|       |	 * the header is not s.iso.numdesc, it's ndesc - only the
  320|       |	 * first N descriptors, for some value of N, are put into
  321|       |	 * the header, and ndesc is set to the actual number copied.
  322|       |	 * In addition, if s.iso.numdesc is negative, no descriptors
  323|       |	 * are captured, and ndesc is set to 0.
  324|       |	 */
  325|  4.71k|	if (header_len_64_bytes) {
  ------------------
  |  Branch (325:6): [True: 4.23k, False: 482]
  ------------------
  326|       |		/*
  327|       |		 * This is either the "version 1" header, with
  328|       |		 * 16 bytes of additional fields at the end, or
  329|       |		 * a "version 0" header from a memory-mapped
  330|       |		 * capture, with 16 bytes of zeroed-out padding
  331|       |		 * at the end.  Byte swap them as if this were
  332|       |		 * a "version 1" header.
  333|       |		 */
  334|  4.23k|		offset += 4;			/* skip past interval */
  335|  4.23k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (335:7): [True: 405, False: 3.82k]
  ------------------
  336|    405|			return;
  337|  3.82k|		uhdr->interval = PCAP_BSWAP_32(uhdr->interval);
  ------------------
  |  |   78|  3.82k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  338|       |
  339|  3.82k|		offset += 4;			/* skip past start_frame */
  340|  3.82k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (340:7): [True: 205, False: 3.62k]
  ------------------
  341|    205|			return;
  342|  3.62k|		uhdr->start_frame = PCAP_BSWAP_32(uhdr->start_frame);
  ------------------
  |  |   78|  3.62k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  343|       |
  344|  3.62k|		offset += 4;			/* skip past xfer_flags */
  345|  3.62k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (345:7): [True: 196, False: 3.42k]
  ------------------
  346|    196|			return;
  347|  3.42k|		uhdr->xfer_flags = PCAP_BSWAP_32(uhdr->xfer_flags);
  ------------------
  |  |   78|  3.42k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  348|       |
  349|  3.42k|		offset += 4;			/* skip past ndesc */
  350|  3.42k|		if (hdr->caplen < offset)
  ------------------
  |  Branch (350:7): [True: 201, False: 3.22k]
  ------------------
  351|    201|			return;
  352|  3.22k|		uhdr->ndesc = PCAP_BSWAP_32(uhdr->ndesc);
  ------------------
  |  |   78|  3.22k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  353|       |
  354|  3.22k|		if (uhdr->transfer_type == URB_ISOCHRONOUS) {
  ------------------
  |  |   43|  3.22k|#define URB_ISOCHRONOUS   0x0
  ------------------
  |  Branch (354:7): [True: 2.64k, False: 577]
  ------------------
  355|       |			/* swap the values in struct linux_usb_isodesc */
  356|  2.64k|			usb_isodesc *pisodesc;
  357|  2.64k|			uint32_t i;
  358|       |
  359|  2.64k|			pisodesc = (usb_isodesc *)(void *)(buf+offset);
  360|   154k|			for (i = 0; i < uhdr->ndesc; i++) {
  ------------------
  |  Branch (360:16): [True: 153k, False: 1.53k]
  ------------------
  361|   153k|				offset += 4;		/* skip past status */
  362|   153k|				if (hdr->caplen < offset)
  ------------------
  |  Branch (362:9): [True: 503, False: 152k]
  ------------------
  363|    503|					return;
  364|   152k|				pisodesc->status = PCAP_BSWAP_32(pisodesc->status);
  ------------------
  |  |   78|   152k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  365|       |
  366|   152k|				offset += 4;		/* skip past offset */
  367|   152k|				if (hdr->caplen < offset)
  ------------------
  |  Branch (367:9): [True: 236, False: 152k]
  ------------------
  368|    236|					return;
  369|   152k|				pisodesc->offset = PCAP_BSWAP_32(pisodesc->offset);
  ------------------
  |  |   78|   152k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  370|       |
  371|   152k|				offset += 4;		/* skip past len */
  372|   152k|				if (hdr->caplen < offset)
  ------------------
  |  Branch (372:9): [True: 376, False: 152k]
  ------------------
  373|    376|					return;
  374|   152k|				pisodesc->len = PCAP_BSWAP_32(pisodesc->len);
  ------------------
  |  |   78|   152k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  375|       |
  376|   152k|				offset += 4;		/* skip past padding */
  377|       |
  378|   152k|				pisodesc++;
  379|   152k|			}
  380|  2.64k|		}
  381|  3.22k|	}
  382|  4.71k|}
pcap-util.c:swap_nflog_header:
  397|  1.59k|{
  398|  1.59k|	u_char *p = buf;
  399|  1.59k|	nflog_hdr_t *nfhdr = (nflog_hdr_t *)buf;
  400|  1.59k|	nflog_tlv_t *tlv;
  401|  1.59k|	u_int caplen = hdr->caplen;
  402|  1.59k|	u_int length = hdr->len;
  403|  1.59k|	u_int size;
  404|       |
  405|  1.59k|	if (caplen < (u_int) sizeof(nflog_hdr_t) ||
  ------------------
  |  Branch (405:6): [True: 332, False: 1.26k]
  ------------------
  406|  1.26k|	    length < (u_int) sizeof(nflog_hdr_t)) {
  ------------------
  |  Branch (406:6): [True: 196, False: 1.07k]
  ------------------
  407|       |		/* Not enough data to have any TLVs. */
  408|    528|		return;
  409|    528|	}
  410|       |
  411|  1.07k|	if (nfhdr->nflog_version != 0) {
  ------------------
  |  Branch (411:6): [True: 238, False: 832]
  ------------------
  412|       |		/* Unknown NFLOG version */
  413|    238|		return;
  414|    238|	}
  415|       |
  416|    832|	length -= sizeof(nflog_hdr_t);
  417|    832|	caplen -= sizeof(nflog_hdr_t);
  418|    832|	p += sizeof(nflog_hdr_t);
  419|       |
  420|  2.10k|	while (caplen >= sizeof(nflog_tlv_t)) {
  ------------------
  |  Branch (420:9): [True: 1.62k, False: 477]
  ------------------
  421|  1.62k|		tlv = (nflog_tlv_t *) p;
  422|       |
  423|       |		/* Swap the type and length. */
  424|  1.62k|		tlv->tlv_type = PCAP_BSWAP_16(tlv->tlv_type);
  ------------------
  |  |   88|  1.62k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  425|  1.62k|		tlv->tlv_length = PCAP_BSWAP_16(tlv->tlv_length);
  ------------------
  |  |   88|  1.62k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  426|       |
  427|       |		/* Get the length of the TLV. */
  428|  1.62k|		size = tlv->tlv_length;
  429|  1.62k|		if (size % 4 != 0)
  ------------------
  |  Branch (429:7): [True: 1.07k, False: 546]
  ------------------
  430|  1.07k|			size += 4 - size % 4;
  431|       |
  432|       |		/* Is the TLV's length less than the minimum? */
  433|  1.62k|		if (size < sizeof(nflog_tlv_t)) {
  ------------------
  |  Branch (433:7): [True: 124, False: 1.50k]
  ------------------
  434|       |			/* Yes. Give up now. */
  435|    124|			return;
  436|    124|		}
  437|       |
  438|       |		/* Do we have enough data for the full TLV? */
  439|  1.50k|		if (caplen < size || length < size) {
  ------------------
  |  Branch (439:7): [True: 231, False: 1.27k]
  |  Branch (439:24): [True: 0, False: 1.27k]
  ------------------
  440|       |			/* No. */
  441|    231|			return;
  442|    231|		}
  443|       |
  444|       |		/* Skip over the TLV. */
  445|  1.27k|		length -= size;
  446|  1.27k|		caplen -= size;
  447|  1.27k|		p += size;
  448|  1.27k|	}
  449|    832|}
pcap-util.c:packet_length_might_be_wrong:
  490|  2.10k|{
  491|  2.10k|	uint32_t old_style_packet_length;
  492|       |
  493|       |	/*
  494|       |	 * Calculate the packet length the old way.
  495|       |	 * We know that the multiplication won't overflow, but
  496|       |	 * we don't know that the additions won't.  Calculate
  497|       |	 * it with no overflow checks, as that's how it
  498|       |	 * would have been calculated when it was captured.
  499|       |	 */
  500|  2.10k|	old_style_packet_length = iso_pseudo_header_len(usb_hdr) +
  501|  2.10k|	    usb_hdr->urb_len;
  502|  2.10k|	return (hdr->len == old_style_packet_length);
  503|  2.10k|}

pcap-util.c:swap_4_byte_aligned_uint64:
   99|  7.91k|{
  100|  7.91k|	return (pcap_4_byte_aligned_uint64){.halves[0] = PCAP_BSWAP_32(val.halves[1]), .halves[1] = PCAP_BSWAP_32(val.halves[0])};
  ------------------
  |  |   78|  15.8k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
              	return (pcap_4_byte_aligned_uint64){.halves[0] = PCAP_BSWAP_32(val.halves[1]), .halves[1] = PCAP_BSWAP_32(val.halves[0])};
  ------------------
  |  |   78|  7.91k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  101|  7.91k|}
pcap-util.c:swap_4_byte_aligned_int64:
  107|  7.11k|{
  108|  7.11k|	return (pcap_4_byte_aligned_int64){.halves[0] = PCAP_BSWAP_32(val.halves[1]), .halves[1] = PCAP_BSWAP_32(val.halves[0])};
  ------------------
  |  |   78|  14.2k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
              	return (pcap_4_byte_aligned_int64){.halves[0] = PCAP_BSWAP_32(val.halves[1]), .halves[1] = PCAP_BSWAP_32(val.halves[0])};
  ------------------
  |  |   78|  7.11k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  109|  7.11k|}

pcapint_oneshot:
  546|  40.6k|{
  547|  40.6k|	struct oneshot_userdata *sp = (struct oneshot_userdata *)user;
  548|       |
  549|  40.6k|	*sp->hdr = *h;
  550|  40.6k|	*sp->pkt = pkt;
  551|  40.6k|}
pcap_next_ex:
  570|  45.4k|{
  571|  45.4k|	struct oneshot_userdata s;
  572|       |
  573|  45.4k|	s.hdr = &p->pcap_header;
  574|  45.4k|	s.pkt = pkt_data;
  575|  45.4k|	s.pd = p;
  576|       |
  577|       |	/* Saves a pointer to the packet headers */
  578|  45.4k|	*pkt_header= &p->pcap_header;
  579|       |
  580|  45.4k|	if (p->rfile != NULL) {
  ------------------
  |  Branch (580:6): [True: 45.4k, False: 0]
  ------------------
  581|  45.4k|		int status;
  582|       |
  583|       |		/* We are on an offline capture */
  584|  45.4k|		status = pcapint_offline_read(p, 1, p->oneshot_callback,
  585|  45.4k|		    (u_char *)&s);
  586|       |
  587|       |		/*
  588|       |		 * Return codes for pcapint_offline_read() are:
  589|       |		 *   -  0: EOF
  590|       |		 *   - -1: error
  591|       |		 *   - >0: OK - result is number of packets read, so
  592|       |		 *         it will be 1 in this case, as we've passed
  593|       |		 *         a maximum packet count of 1
  594|       |		 * The first one ('0') conflicts with the return code of
  595|       |		 * 0 from pcap_read() meaning "no packets arrived before
  596|       |		 * the timeout expired", so we map it to -2 so you can
  597|       |		 * distinguish between an EOF from a savefile and a
  598|       |		 * "no packets arrived before the timeout expired, try
  599|       |		 * again" from a live capture.
  600|       |		 */
  601|  45.4k|		if (status == 0)
  ------------------
  |  Branch (601:7): [True: 3.60k, False: 41.8k]
  ------------------
  602|  3.60k|			return (-2);
  603|  41.8k|		else
  604|  41.8k|			return (status);
  605|  45.4k|	}
  606|       |
  607|       |	/*
  608|       |	 * Return codes for pcap_read() are:
  609|       |	 *   -  0: timeout
  610|       |	 *   - -1: error
  611|       |	 *   - -2: loop was broken out of with pcap_breakloop()
  612|       |	 *   - >0: OK, result is number of packets captured, so
  613|       |	 *         it will be 1 in this case, as we've passed
  614|       |	 *         a maximum packet count of 1
  615|       |	 * The first one ('0') conflicts with the return code of 0 from
  616|       |	 * pcapint_offline_read() meaning "end of file".
  617|       |	*/
  618|      0|	return (p->read_op(p, 1, p->oneshot_callback, (u_char *)&s));
  619|  45.4k|}
pcapint_open_offline_common:
 2933|  5.13k|{
 2934|  5.13k|	pcap_t *p;
 2935|       |
 2936|  5.13k|	p = pcap_alloc_pcap_t(ebuf, total_size, private_offset);
 2937|  5.13k|	if (p == NULL)
  ------------------
  |  Branch (2937:6): [True: 0, False: 5.13k]
  ------------------
 2938|      0|		return (NULL);
 2939|       |
 2940|  5.13k|	p->opt.tstamp_precision = PCAP_TSTAMP_PRECISION_MICRO;
  ------------------
  |  |  537|  5.13k|#define PCAP_TSTAMP_PRECISION_MICRO	0	/* use timestamps with microsecond precision, default */
  ------------------
 2941|       |
 2942|  5.13k|	return (p);
 2943|  5.13k|}
pcap_datalink:
 2992|  4.75k|{
 2993|  4.75k|	if (!p->activated)
  ------------------
  |  Branch (2993:6): [True: 0, False: 4.75k]
  ------------------
 2994|      0|		return (PCAP_ERROR_NOT_ACTIVATED);
  ------------------
  |  |  362|      0|#define PCAP_ERROR_NOT_ACTIVATED	-3	/* the capture needs to be activated */
  ------------------
 2995|  4.75k|	return (p->linktype);
 2996|  4.75k|}
pcap_datalink_val_to_description:
 3432|  15.0k|{
 3433|  15.0k|	int i;
 3434|       |
 3435|  1.18M|	for (i = 0; dlt_choices[i].name != NULL; i++) {
  ------------------
  |  Branch (3435:14): [True: 1.18M, False: 614]
  ------------------
 3436|  1.18M|		if (dlt_choices[i].dlt == dlt)
  ------------------
  |  Branch (3436:7): [True: 14.4k, False: 1.16M]
  ------------------
 3437|  14.4k|			return (dlt_choices[i].description);
 3438|  1.18M|	}
 3439|    614|	return (NULL);
 3440|  15.0k|}
pcap_close:
 4329|  4.75k|{
 4330|  4.75k|	p->cleanup_op(p);
 4331|       |
 4332|       |	/*
 4333|       |	 * Free information set by pcap_create() *after* calling
 4334|       |	 * the module's cleanup routine; that routine might have
 4335|       |	 * to use p->opt.device (see commit
 4336|       |	 * e333a6044f7d2d3225a6a22205b6b7c1e389945f).
 4337|       |	 */
 4338|  4.75k|	if (p->opt.device != NULL) {
  ------------------
  |  Branch (4338:6): [True: 0, False: 4.75k]
  ------------------
 4339|      0|		free(p->opt.device);
 4340|       |		p->opt.device = NULL;
 4341|      0|	}
 4342|  4.75k|	free(p);
 4343|  4.75k|}
pcap.c:pcap_alloc_pcap_t:
 2483|  5.13k|{
 2484|  5.13k|	char *chunk;
 2485|  5.13k|	pcap_t *p;
 2486|       |
 2487|       |	/*
 2488|       |	 * total_size is the size of a structure containing a pcap_t
 2489|       |	 * followed by a private structure.
 2490|       |	 */
 2491|  5.13k|	chunk = calloc(total_size, 1);
 2492|  5.13k|	if (chunk == NULL) {
  ------------------
  |  Branch (2492:6): [True: 0, False: 5.13k]
  ------------------
 2493|      0|		pcapint_fmt_errmsg_for_errno(ebuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
 2494|      0|		    errno, "malloc");
 2495|      0|		return (NULL);
 2496|      0|	}
 2497|       |
 2498|       |	/*
 2499|       |	 * Get a pointer to the pcap_t at the beginning.
 2500|       |	 */
 2501|  5.13k|	p = (pcap_t *)chunk;
 2502|       |
 2503|       |#ifdef _WIN32
 2504|       |	p->handle = INVALID_HANDLE_VALUE;	/* not opened yet */
 2505|       |#else /* _WIN32 */
 2506|  5.13k|	p->fd = -1;	/* not opened yet */
 2507|  5.13k|	p->selectable_fd = -1;
 2508|  5.13k|	p->required_select_timeout = NULL;
 2509|  5.13k|#endif /* _WIN32 */
 2510|       |
 2511|       |	/*
 2512|       |	 * private_offset is the offset, in bytes, of the private
 2513|       |	 * data from the beginning of the structure.
 2514|       |	 *
 2515|       |	 * Set the pointer to the private data; that's private_offset
 2516|       |	 * bytes past the pcap_t.
 2517|       |	 */
 2518|  5.13k|	p->priv = (void *)(chunk + private_offset);
 2519|       |
 2520|  5.13k|	return (p);
 2521|  5.13k|}

pcapint_sf_cleanup:
  238|  4.75k|{
  239|  4.75k|	if (p->rfile != stdin)
  ------------------
  |  Branch (239:6): [True: 4.75k, False: 0]
  ------------------
  240|  4.75k|		(void)fclose(p->rfile);
  241|  4.75k|	if (p->buffer != NULL)
  ------------------
  |  Branch (241:6): [True: 4.75k, False: 0]
  ------------------
  242|  4.75k|		free(p->buffer);
  243|  4.75k|	pcap_freecode(&p->fcode);
  244|  4.75k|}
pcapint_adjust_snapshot:
  440|  16.0k|{
  441|  16.0k|	if (snaplen == 0 || snaplen > INT_MAX) {
  ------------------
  |  Branch (441:6): [True: 3.62k, False: 12.4k]
  |  Branch (441:22): [True: 5.75k, False: 6.70k]
  ------------------
  442|       |		/*
  443|       |		 * Bogus snapshot length; use the maximum for this
  444|       |		 * link-layer type as a fallback.
  445|       |		 *
  446|       |		 * XXX - we don't clamp snapshot lengths that are
  447|       |		 * <= INT_MAX but > max_snaplen_for_dlt(linktype),
  448|       |		 * so a capture file could cause us to allocate
  449|       |		 * a Really Big Buffer.
  450|       |		 */
  451|  9.38k|		snaplen = max_snaplen_for_dlt(linktype);
  452|  9.38k|	}
  453|  16.0k|	return snaplen;
  454|  16.0k|}
pcap_fopen_offline_with_tstamp_precision:
  469|  5.56k|{
  470|  5.56k|	pcap_t *p;
  471|  5.56k|	uint8_t magic[4];
  472|  5.56k|	size_t amt_read;
  473|  5.56k|	u_int i;
  474|  5.56k|	int err;
  475|       |
  476|       |	/*
  477|       |	 * Fail if we were passed a NULL fp.
  478|       |	 *
  479|       |	 * That shouldn't happen if we're opening with a path name, but
  480|       |	 * it could happen if buggy code is opening with a FILE * and
  481|       |	 * didn't bother to make sure the FILE * isn't null.
  482|       |	 */
  483|  5.56k|	if (fp == NULL) {
  ------------------
  |  Branch (483:6): [True: 0, False: 5.56k]
  ------------------
  484|      0|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  485|      0|		    "Null FILE * pointer provided to savefile open routine");
  486|      0|		return (NULL);
  487|      0|	}
  488|       |
  489|       |	/*
  490|       |	 * Read the first 4 bytes of the file; the network analyzer dump
  491|       |	 * file formats we support (pcap and pcapng), and several other
  492|       |	 * formats we might support in the future (such as snoop, DOS and
  493|       |	 * Windows Sniffer, and Microsoft Network Monitor) all have magic
  494|       |	 * numbers that are unique in their first 4 bytes.
  495|       |	 */
  496|  5.56k|	amt_read = fread(&magic, 1, sizeof(magic), fp);
  497|  5.56k|	if (amt_read != sizeof(magic)) {
  ------------------
  |  Branch (497:6): [True: 0, False: 5.56k]
  ------------------
  498|      0|		if (ferror(fp)) {
  ------------------
  |  Branch (498:7): [True: 0, False: 0]
  ------------------
  499|      0|			pcapint_fmt_errmsg_for_errno(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  500|      0|			    errno, "error reading dump file");
  501|      0|		} else {
  502|      0|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  503|      0|			    "truncated dump file; tried to read %zu file header bytes, only got %zu",
  504|      0|			    sizeof(magic), amt_read);
  505|      0|		}
  506|      0|		return (NULL);
  507|      0|	}
  508|       |
  509|       |	/*
  510|       |	 * Try all file types.
  511|       |	 */
  512|  7.46k|	for (i = 0; i < N_FILE_TYPES; i++) {
  ------------------
  |  |  461|  7.46k|#define	N_FILE_TYPES	(sizeof check_headers / sizeof check_headers[0])
  ------------------
  |  Branch (512:14): [True: 7.15k, False: 314]
  ------------------
  513|  7.15k|		p = (*check_headers[i])(magic, fp, precision, errbuf, &err);
  514|  7.15k|		if (p != NULL) {
  ------------------
  |  Branch (514:7): [True: 4.75k, False: 2.39k]
  ------------------
  515|       |			/* Yup, that's it. */
  516|  4.75k|			goto found;
  517|  4.75k|		}
  518|  2.39k|		if (err) {
  ------------------
  |  Branch (518:7): [True: 491, False: 1.90k]
  ------------------
  519|       |			/*
  520|       |			 * Error trying to read the header.
  521|       |			 */
  522|    491|			return (NULL);
  523|    491|		}
  524|  2.39k|	}
  525|       |
  526|       |	/*
  527|       |	 * Well, who knows what this mess is....
  528|       |	 */
  529|    314|	snprintf(errbuf, PCAP_ERRBUF_SIZE, "unknown file format");
  ------------------
  |  |  149|    314|#define PCAP_ERRBUF_SIZE 256
  ------------------
  530|    314|	return (NULL);
  531|       |
  532|  4.75k|found:
  533|  4.75k|	p->rfile = fp;
  534|       |
  535|       |	/* Padding only needed for live capture fcode */
  536|  4.75k|	p->fddipad = 0;
  537|       |
  538|  4.75k|#if !defined(_WIN32)
  539|       |	/*
  540|       |	 * You can do "select()" and "poll()" on plain files on most
  541|       |	 * platforms, and should be able to do so on pipes.
  542|       |	 *
  543|       |	 * You can't do "select()" on anything other than sockets in
  544|       |	 * Windows, so, on Win32 systems, we don't have "selectable_fd".
  545|       |	 */
  546|  4.75k|	p->selectable_fd = fileno(fp);
  547|  4.75k|#endif
  548|       |
  549|  4.75k|	p->can_set_rfmon_op = sf_cant_set_rfmon;
  550|  4.75k|	p->read_op = pcapint_offline_read;
  551|  4.75k|	p->inject_op = sf_inject;
  552|  4.75k|	p->setfilter_op = pcapint_install_bpf_program;
  553|  4.75k|	p->setdirection_op = sf_setdirection;
  554|  4.75k|	p->set_datalink_op = NULL;	/* we don't support munging link-layer headers */
  555|  4.75k|	p->getnonblock_op = sf_getnonblock;
  556|  4.75k|	p->setnonblock_op = sf_setnonblock;
  557|  4.75k|	p->stats_op = sf_stats;
  558|       |#ifdef _WIN32
  559|       |	p->stats_ex_op = sf_stats_ex;
  560|       |	p->setbuff_op = sf_setbuff;
  561|       |	p->setmode_op = sf_setmode;
  562|       |	p->setmintocopy_op = sf_setmintocopy;
  563|       |	p->getevent_op = sf_getevent;
  564|       |	p->oid_get_request_op = sf_oid_get_request;
  565|       |	p->oid_set_request_op = sf_oid_set_request;
  566|       |	p->sendqueue_transmit_op = sf_sendqueue_transmit;
  567|       |	p->setuserbuffer_op = sf_setuserbuffer;
  568|       |	p->live_dump_op = sf_live_dump;
  569|       |	p->live_dump_ended_op = sf_live_dump_ended;
  570|       |#endif
  571|       |
  572|       |	/*
  573|       |	 * For offline captures, the standard one-shot callback can
  574|       |	 * be used for pcap_next()/pcap_next_ex().
  575|       |	 */
  576|  4.75k|	p->oneshot_callback = pcapint_oneshot;
  577|       |
  578|       |	/*
  579|       |	 * Default breakloop operation.
  580|       |	 */
  581|  4.75k|	p->breakloop_op = pcapint_breakloop_common;
  582|       |
  583|       |	/*
  584|       |	 * For link-layer headers in which the packet type is indicated
  585|       |	 * by an AF_ value, we don't know what OS generated it, so we
  586|       |	 * don't know what numerical value corresponds to AF_INET6, and
  587|       |	 * we don't know the byte order of the host that originally
  588|       |	 * captured the packets in the file (as opposed to the host
  589|       |	 * that *wrote* this file), so we don't know the byte order
  590|       |	 * of multi-byte AF_ values.
  591|       |	 *
  592|       |	 * That requires different filtering code than a live capture.
  593|       |	 *
  594|       |	 * Savefiles don't require any other special BPF code generation.
  595|       |	 */
  596|  4.75k|	p->bpf_codegen_flags = BPF_OFFLINE_AF_HANDLING;
  ------------------
  |  |  408|  4.75k|#define BPF_OFFLINE_AF_HANDLING	0x00000004
  ------------------
  597|       |
  598|  4.75k|	p->activated = 1;
  599|       |
  600|  4.75k|	return (p);
  601|  5.56k|}
pcap_fopen_offline:
  611|  5.56k|{
  612|  5.56k|	return (pcap_fopen_offline_with_tstamp_precision(fp,
  613|  5.56k|	    PCAP_TSTAMP_PRECISION_MICRO, errbuf));
  ------------------
  |  |  537|  5.56k|#define PCAP_TSTAMP_PRECISION_MICRO	0	/* use timestamps with microsecond precision, default */
  ------------------
  614|  5.56k|}
pcapint_offline_read:
  624|  45.4k|{
  625|  45.4k|	int n = 0;
  626|  45.4k|	u_char *data;
  627|       |
  628|       |	/*
  629|       |	 * This can conceivably process more than INT_MAX packets,
  630|       |	 * which would overflow the packet count, causing it either
  631|       |	 * to look like a negative number, and thus cause us to
  632|       |	 * return a value that looks like an error, or overflow
  633|       |	 * back into positive territory, and thus cause us to
  634|       |	 * return a too-low count.
  635|       |	 *
  636|       |	 * Therefore, if the packet count is unlimited, we clip
  637|       |	 * it at INT_MAX; this routine is not expected to
  638|       |	 * process packets indefinitely, so that's not an issue.
  639|       |	 */
  640|  45.4k|	if (PACKET_COUNT_IS_UNLIMITED(cnt))
  ------------------
  |  |  433|  45.4k|#define PACKET_COUNT_IS_UNLIMITED(count)	((count) <= 0)
  |  |  ------------------
  |  |  |  Branch (433:42): [True: 0, False: 45.4k]
  |  |  ------------------
  ------------------
  641|      0|		cnt = INT_MAX;
  642|       |
  643|  45.4k|	for (;;) {
  644|  45.4k|		struct pcap_pkthdr h;
  645|  45.4k|		int status;
  646|       |
  647|       |		/*
  648|       |		 * Has "pcap_breakloop()" been called?
  649|       |		 * If so, return immediately - if we haven't read any
  650|       |		 * packets, clear the flag and return -2 to indicate
  651|       |		 * that we were told to break out of the loop, otherwise
  652|       |		 * leave the flag set, so that the *next* call will break
  653|       |		 * out of the loop without having read any packets, and
  654|       |		 * return the number of packets we've processed so far.
  655|       |		 */
  656|  45.4k|		if (p->break_loop) {
  ------------------
  |  Branch (656:7): [True: 0, False: 45.4k]
  ------------------
  657|      0|			if (n == 0) {
  ------------------
  |  Branch (657:8): [True: 0, False: 0]
  ------------------
  658|      0|				p->break_loop = 0;
  659|      0|				return (-2);
  660|      0|			} else
  661|      0|				return (n);
  662|      0|		}
  663|       |
  664|  45.4k|		status = p->next_packet_op(p, &h, &data);
  665|  45.4k|		if (status < 0) {
  ------------------
  |  Branch (665:7): [True: 1.15k, False: 44.2k]
  ------------------
  666|       |			/*
  667|       |			 * Error.  Pass it back to the caller.
  668|       |			 */
  669|  1.15k|			return (status);
  670|  1.15k|		}
  671|  44.2k|		if (status == 0) {
  ------------------
  |  Branch (671:7): [True: 3.60k, False: 40.6k]
  ------------------
  672|       |			/*
  673|       |			 * EOF.  Nothing more to process;
  674|       |			 */
  675|  3.60k|			break;
  676|  3.60k|		}
  677|       |
  678|       |		/*
  679|       |		 * OK, we've read a packet; run it through the filter
  680|       |		 * and, if it passes, process it.
  681|       |		 */
  682|  40.6k|		if (p->fcode.bf_insns == NULL ||
  ------------------
  |  Branch (682:7): [True: 40.6k, False: 0]
  ------------------
  683|      0|		    pcapint_filter(p->fcode.bf_insns, p->fcode.bf_len,
  ------------------
  |  Branch (683:7): [True: 0, False: 0]
  ------------------
  684|  40.6k|		                   data, h.len, h.caplen)) {
  685|  40.6k|			(*callback)(user, &h, data);
  686|  40.6k|			n++;	/* count the packet */
  687|  40.6k|			if (n >= cnt)
  ------------------
  |  Branch (687:8): [True: 40.6k, False: 0]
  ------------------
  688|  40.6k|				break;
  689|  40.6k|		}
  690|  40.6k|	}
  691|       |	/*XXX this breaks semantics tcpslice expects */
  692|  44.2k|	return (n);
  693|  45.4k|}

pcap_check_header:
  220|  5.56k|{
  221|  5.56k|	bpf_u_int32 magic_int;
  222|  5.56k|	struct pcap_file_header hdr;
  223|  5.56k|	size_t amt_read;
  224|  5.56k|	pcap_t *p;
  225|  5.56k|	int swapped = 0;
  226|  5.56k|	struct pcap_sf *ps;
  227|       |
  228|       |	/*
  229|       |	 * Assume no read errors.
  230|       |	 */
  231|  5.56k|	*err = 0;
  232|       |
  233|       |	/*
  234|       |	 * Check whether the first 4 bytes of the file are the magic
  235|       |	 * number for a pcap savefile, or for a byte-swapped pcap
  236|       |	 * savefile.
  237|       |	 */
  238|  5.56k|	memcpy(&magic_int, magic, sizeof(magic_int));
  239|  5.56k|	if (magic_int != TCPDUMP_MAGIC &&
  ------------------
  |  |   71|  11.1k|#define TCPDUMP_MAGIC		0xa1b2c3d4
  ------------------
  |  Branch (239:6): [True: 4.73k, False: 830]
  ------------------
  240|  4.73k|	    magic_int != KUZNETZOV_TCPDUMP_MAGIC &&
  ------------------
  |  |   76|  10.2k|#define KUZNETZOV_TCPDUMP_MAGIC	0xa1b2cd34
  ------------------
  |  Branch (240:6): [True: 4.68k, False: 41]
  ------------------
  241|  4.68k|	    magic_int != NSEC_TCPDUMP_MAGIC) {
  ------------------
  |  |   94|  4.68k|#define NSEC_TCPDUMP_MAGIC	0xa1b23c4d
  ------------------
  |  Branch (241:6): [True: 4.66k, False: 20]
  ------------------
  242|  4.66k|		magic_int = PCAP_BSWAP_32(magic_int);
  ------------------
  |  |   78|  4.66k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  243|  4.66k|		if (magic_int != TCPDUMP_MAGIC &&
  ------------------
  |  |   71|  9.33k|#define TCPDUMP_MAGIC		0xa1b2c3d4
  ------------------
  |  Branch (243:7): [True: 2.39k, False: 2.27k]
  ------------------
  244|  2.39k|		    magic_int != KUZNETZOV_TCPDUMP_MAGIC &&
  ------------------
  |  |   76|  7.06k|#define KUZNETZOV_TCPDUMP_MAGIC	0xa1b2cd34
  ------------------
  |  Branch (244:7): [True: 2.34k, False: 49]
  ------------------
  245|  2.34k|		    magic_int != NSEC_TCPDUMP_MAGIC)
  ------------------
  |  |   94|  2.34k|#define NSEC_TCPDUMP_MAGIC	0xa1b23c4d
  ------------------
  |  Branch (245:7): [True: 1.59k, False: 756]
  ------------------
  246|  1.59k|			return (NULL);	/* nope */
  247|  3.07k|		swapped = 1;
  248|  3.07k|	}
  249|       |
  250|       |	/*
  251|       |	 * They are.  Put the magic number in the header, and read
  252|       |	 * the rest of the header.
  253|       |	 */
  254|  3.97k|	hdr.magic = magic_int;
  255|  3.97k|	amt_read = fread(((char *)&hdr) + sizeof hdr.magic, 1,
  256|  3.97k|	    sizeof(hdr) - sizeof(hdr.magic), fp);
  257|  3.97k|	if (amt_read != sizeof(hdr) - sizeof(hdr.magic)) {
  ------------------
  |  Branch (257:6): [True: 0, False: 3.97k]
  ------------------
  258|      0|		if (ferror(fp)) {
  ------------------
  |  Branch (258:7): [True: 0, False: 0]
  ------------------
  259|      0|			pcapint_fmt_errmsg_for_errno(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  260|      0|			    errno, "error reading dump file");
  261|      0|		} else {
  262|      0|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  263|      0|			    "truncated dump file; tried to read %zu file header bytes, only got %zu",
  264|      0|			    sizeof(hdr), amt_read);
  265|      0|		}
  266|      0|		*err = 1;
  267|      0|		return (NULL);
  268|      0|	}
  269|       |
  270|       |	/*
  271|       |	 * If it's a byte-swapped capture file, byte-swap the header.
  272|       |	 */
  273|  3.97k|	if (swapped) {
  ------------------
  |  Branch (273:6): [True: 3.07k, False: 891]
  ------------------
  274|  3.07k|		hdr.version_major = PCAP_BSWAP_16(hdr.version_major);
  ------------------
  |  |   88|  3.07k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  275|  3.07k|		hdr.version_minor = PCAP_BSWAP_16(hdr.version_minor);
  ------------------
  |  |   88|  3.07k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  276|  3.07k|		hdr.thiszone = PCAP_BSWAP_32(hdr.thiszone);
  ------------------
  |  |   78|  3.07k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  277|  3.07k|		hdr.sigfigs = PCAP_BSWAP_32(hdr.sigfigs);
  ------------------
  |  |   78|  3.07k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  278|  3.07k|		hdr.snaplen = PCAP_BSWAP_32(hdr.snaplen);
  ------------------
  |  |   78|  3.07k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  279|  3.07k|		hdr.linktype = PCAP_BSWAP_32(hdr.linktype);
  ------------------
  |  |   78|  3.07k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  280|  3.07k|	}
  281|       |
  282|       |	/*
  283|       |	 * currently only versions 2.[0-4] are supported with
  284|       |	 * the exception of 543.0 for DG/UX tcpdump.
  285|       |	 */
  286|  3.97k|	if (! ((hdr.version_major == PCAP_VERSION_MAJOR &&
  ------------------
  |  |  146|  7.94k|#define PCAP_VERSION_MAJOR 2
  ------------------
  |  Branch (286:10): [True: 3.31k, False: 654]
  ------------------
  287|  3.31k|		hdr.version_minor <= PCAP_VERSION_MINOR) ||
  ------------------
  |  |  147|  3.31k|#define PCAP_VERSION_MINOR 4
  ------------------
  |  Branch (287:3): [True: 3.30k, False: 14]
  ------------------
  288|    668|	       (hdr.version_major == 543 &&
  ------------------
  |  Branch (288:10): [True: 625, False: 43]
  ------------------
  289|    625|		hdr.version_minor == 0))) {
  ------------------
  |  Branch (289:3): [True: 609, False: 16]
  ------------------
  290|     59|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     59|#define PCAP_ERRBUF_SIZE 256
  ------------------
  291|     59|			 "unsupported pcap savefile version %u.%u",
  292|     59|			 hdr.version_major, hdr.version_minor);
  293|     59|		*err = 1;
  294|     59|		return NULL;
  295|     59|	}
  296|       |
  297|       |	/*
  298|       |	 * Check the main reserved field.
  299|       |	 */
  300|  3.91k|	if (LT_RESERVED1(hdr.linktype) != 0) {
  ------------------
  |  |  267|  3.91k|#define LT_RESERVED1(x)			((x) & 0x03FF0000)
  ------------------
  |  Branch (300:6): [True: 10, False: 3.90k]
  ------------------
  301|     10|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     10|#define PCAP_ERRBUF_SIZE 256
  ------------------
  302|     10|			 "savefile linktype reserved field not zero (0x%08x)",
  303|     10|			 LT_RESERVED1(hdr.linktype));
  ------------------
  |  |  267|     10|#define LT_RESERVED1(x)			((x) & 0x03FF0000)
  ------------------
  304|     10|		*err = 1;
  305|     10|		return NULL;
  306|     10|	}
  307|       |
  308|       |	/*
  309|       |	 * OK, this is a good pcap file.
  310|       |	 * Allocate a pcap_t for it.
  311|       |	 */
  312|  3.90k|	p = PCAP_OPEN_OFFLINE_COMMON(errbuf, struct pcap_sf);
  ------------------
  |  |  559|  3.90k|	pcapint_open_offline_common(ebuf, \
  |  |  560|  3.90k|	    sizeof (struct { pcap_t __common; type __private; }), \
  |  |  561|  3.90k|	    offsetof (struct { pcap_t __common; type __private; }, __private))
  ------------------
  313|  3.90k|	if (p == NULL) {
  ------------------
  |  Branch (313:6): [True: 0, False: 3.90k]
  ------------------
  314|       |		/* Allocation failed. */
  315|      0|		*err = 1;
  316|      0|		return (NULL);
  317|      0|	}
  318|  3.90k|	p->swapped = swapped;
  319|  3.90k|	p->version_major = hdr.version_major;
  320|  3.90k|	p->version_minor = hdr.version_minor;
  321|  3.90k|	p->linktype = linktype_to_dlt(LT_LINKTYPE(hdr.linktype));
  ------------------
  |  |  265|  3.90k|#define LT_LINKTYPE(x)			((x) & 0x0000FFFF)
  ------------------
  322|  3.90k|	p->linktype_ext = LT_LINKTYPE_EXT(hdr.linktype);
  ------------------
  |  |  266|  3.90k|#define LT_LINKTYPE_EXT(x)		((x) & 0xFFFF0000)
  ------------------
  323|  3.90k|	p->snapshot = pcapint_adjust_snapshot(p->linktype, hdr.snaplen);
  324|       |
  325|  3.90k|	p->next_packet_op = pcap_next_packet;
  326|       |
  327|  3.90k|	ps = p->priv;
  328|       |
  329|  3.90k|	p->opt.tstamp_precision = precision;
  330|       |
  331|       |	/*
  332|       |	 * Will we need to scale the timestamps to match what the
  333|       |	 * user wants?
  334|       |	 */
  335|  3.90k|	switch (precision) {
  336|       |
  337|  3.90k|	case PCAP_TSTAMP_PRECISION_MICRO:
  ------------------
  |  |  537|  3.90k|#define PCAP_TSTAMP_PRECISION_MICRO	0	/* use timestamps with microsecond precision, default */
  ------------------
  |  Branch (337:2): [True: 3.90k, False: 0]
  ------------------
  338|  3.90k|		if (magic_int == NSEC_TCPDUMP_MAGIC) {
  ------------------
  |  |   94|  3.90k|#define NSEC_TCPDUMP_MAGIC	0xa1b23c4d
  ------------------
  |  Branch (338:7): [True: 752, False: 3.14k]
  ------------------
  339|       |			/*
  340|       |			 * The file has nanoseconds, the user
  341|       |			 * wants microseconds; scale the
  342|       |			 * precision down.
  343|       |			 */
  344|    752|			ps->scale_type = SCALE_DOWN;
  345|  3.14k|		} else {
  346|       |			/*
  347|       |			 * The file has microseconds, the
  348|       |			 * user wants microseconds; nothing to do.
  349|       |			 */
  350|  3.14k|			ps->scale_type = PASS_THROUGH;
  351|  3.14k|		}
  352|  3.90k|		break;
  353|       |
  354|      0|	case PCAP_TSTAMP_PRECISION_NANO:
  ------------------
  |  |  538|      0|#define PCAP_TSTAMP_PRECISION_NANO	1	/* use timestamps with nanosecond precision */
  ------------------
  |  Branch (354:2): [True: 0, False: 3.90k]
  ------------------
  355|      0|		if (magic_int == NSEC_TCPDUMP_MAGIC) {
  ------------------
  |  |   94|      0|#define NSEC_TCPDUMP_MAGIC	0xa1b23c4d
  ------------------
  |  Branch (355:7): [True: 0, False: 0]
  ------------------
  356|       |			/*
  357|       |			 * The file has nanoseconds, the
  358|       |			 * user wants nanoseconds; nothing to do.
  359|       |			 */
  360|      0|			ps->scale_type = PASS_THROUGH;
  361|      0|		} else {
  362|       |			/*
  363|       |			 * The file has microseconds, the user
  364|       |			 * wants nanoseconds; scale the
  365|       |			 * precision up.
  366|       |			 */
  367|      0|			ps->scale_type = SCALE_UP;
  368|      0|		}
  369|      0|		break;
  370|       |
  371|      0|	default:
  ------------------
  |  Branch (371:2): [True: 0, False: 3.90k]
  ------------------
  372|      0|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  373|      0|		    "unknown time stamp resolution %u", precision);
  374|      0|		free(p);
  375|      0|		*err = 1;
  376|      0|		return (NULL);
  377|  3.90k|	}
  378|       |
  379|       |	/*
  380|       |	 * We interchanged the caplen and len fields at version 2.3,
  381|       |	 * in order to match the bpf header layout.  But unfortunately
  382|       |	 * some files were written with version 2.3 in their headers
  383|       |	 * but without the interchanged fields.
  384|       |	 *
  385|       |	 * In addition, DG/UX tcpdump writes out files with a version
  386|       |	 * number of 543.0, and with the caplen and len fields in the
  387|       |	 * pre-2.3 order.
  388|       |	 */
  389|  3.90k|	switch (hdr.version_major) {
  390|       |
  391|  3.29k|	case 2:
  ------------------
  |  Branch (391:2): [True: 3.29k, False: 607]
  ------------------
  392|  3.29k|		if (hdr.version_minor < 3)
  ------------------
  |  Branch (392:7): [True: 1.25k, False: 2.03k]
  ------------------
  393|  1.25k|			ps->lengths_swapped = SWAPPED;
  394|  2.03k|		else if (hdr.version_minor == 3)
  ------------------
  |  Branch (394:12): [True: 1.37k, False: 667]
  ------------------
  395|  1.37k|			ps->lengths_swapped = MAYBE_SWAPPED;
  396|    667|		else
  397|    667|			ps->lengths_swapped = NOT_SWAPPED;
  398|  3.29k|		break;
  399|       |
  400|    607|	case 543:
  ------------------
  |  Branch (400:2): [True: 607, False: 3.29k]
  ------------------
  401|    607|		ps->lengths_swapped = SWAPPED;
  402|    607|		break;
  403|       |
  404|      0|	default:
  ------------------
  |  Branch (404:2): [True: 0, False: 3.90k]
  ------------------
  405|      0|		ps->lengths_swapped = NOT_SWAPPED;
  406|      0|		break;
  407|  3.90k|	}
  408|       |
  409|  3.90k|	if (magic_int == KUZNETZOV_TCPDUMP_MAGIC) {
  ------------------
  |  |   76|  3.90k|#define KUZNETZOV_TCPDUMP_MAGIC	0xa1b2cd34
  ------------------
  |  Branch (409:6): [True: 83, False: 3.81k]
  ------------------
  410|       |		/*
  411|       |		 * XXX - the patch that's in some versions of libpcap
  412|       |		 * changes the packet header but not the magic number,
  413|       |		 * and some other versions with this magic number have
  414|       |		 * some extra debugging information in the packet header;
  415|       |		 * we'd have to use some hacks^H^H^H^H^Hheuristics to
  416|       |		 * detect those variants.
  417|       |		 *
  418|       |		 * Wireshark does that, but it does so by trying to read
  419|       |		 * the first two packets of the file with each of the
  420|       |		 * record header formats.  That currently means it seeks
  421|       |		 * backwards and retries the reads, which doesn't work
  422|       |		 * on pipes.  We want to be able to read from a pipe, so
  423|       |		 * that strategy won't work; we'd have to buffer some
  424|       |		 * data ourselves and read from that buffer in order to
  425|       |		 * make that work.
  426|       |		 */
  427|     83|		ps->hdrsize = sizeof(struct pcap_sf_patched_pkthdr);
  428|       |
  429|     83|		if (p->linktype == DLT_EN10MB) {
  ------------------
  |  |   68|     83|#define DLT_EN10MB	1	/* Ethernet (10Mb) */
  ------------------
  |  Branch (429:7): [True: 59, False: 24]
  ------------------
  430|       |			/*
  431|       |			 * This capture might have been done in raw mode
  432|       |			 * or cooked mode.
  433|       |			 *
  434|       |			 * If it was done in cooked mode, p->snapshot was
  435|       |			 * passed to recvfrom() as the buffer size, meaning
  436|       |			 * that the most packet data that would be copied
  437|       |			 * would be p->snapshot.  However, a faked Ethernet
  438|       |			 * header would then have been added to it, so the
  439|       |			 * most data that would be in a packet in the file
  440|       |			 * would be p->snapshot + 14.
  441|       |			 *
  442|       |			 * We can't easily tell whether the capture was done
  443|       |			 * in raw mode or cooked mode, so we'll assume it was
  444|       |			 * cooked mode, and add 14 to the snapshot length.
  445|       |			 * That means that, for a raw capture, the snapshot
  446|       |			 * length will be misleading if you use it to figure
  447|       |			 * out why a capture doesn't have all the packet data,
  448|       |			 * but there's not much we can do to avoid that.
  449|       |			 *
  450|       |			 * But don't grow the snapshot length past the
  451|       |			 * maximum value of an int.
  452|       |			 */
  453|     59|			if (p->snapshot <= INT_MAX - 14)
  ------------------
  |  Branch (453:8): [True: 57, False: 2]
  ------------------
  454|     57|				p->snapshot += 14;
  455|      2|			else
  456|      2|				p->snapshot = INT_MAX;
  457|     59|		}
  458|     83|	} else
  459|  3.81k|		ps->hdrsize = sizeof(struct pcap_sf_pkthdr);
  460|       |
  461|       |	/*
  462|       |	 * Allocate a buffer for the packet data.
  463|       |	 * Choose the minimum of the file's snapshot length and 2K bytes;
  464|       |	 * that should be enough for most network packets - we'll grow it
  465|       |	 * if necessary.  That way, we don't allocate a huge chunk of
  466|       |	 * memory just because there's a huge snapshot length, as the
  467|       |	 * snapshot length might be larger than the size of the largest
  468|       |	 * packet.
  469|       |	 */
  470|  3.90k|	p->bufsize = p->snapshot;
  471|  3.90k|	if (p->bufsize > 2048)
  ------------------
  |  Branch (471:6): [True: 3.62k, False: 278]
  ------------------
  472|  3.62k|		p->bufsize = 2048;
  473|  3.90k|	p->buffer = malloc(p->bufsize);
  474|  3.90k|	if (p->buffer == NULL) {
  ------------------
  |  Branch (474:6): [True: 0, False: 3.90k]
  ------------------
  475|      0|		snprintf(errbuf, PCAP_ERRBUF_SIZE, "out of memory");
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  476|      0|		free(p);
  477|      0|		*err = 1;
  478|      0|		return (NULL);
  479|      0|	}
  480|       |
  481|  3.90k|	p->cleanup_op = pcapint_sf_cleanup;
  482|       |
  483|  3.90k|	return (p);
  484|  3.90k|}
sf-pcap.c:pcap_next_packet:
  511|  42.4k|{
  512|  42.4k|	struct pcap_sf *ps = p->priv;
  513|  42.4k|	struct pcap_sf_patched_pkthdr sf_hdr;
  514|  42.4k|	FILE *fp = p->rfile;
  515|  42.4k|	size_t amt_read;
  516|  42.4k|	bpf_u_int32 t;
  517|       |
  518|       |	/*
  519|       |	 * Read the packet header; the structure we use as a buffer
  520|       |	 * is the longer structure for files generated by the patched
  521|       |	 * libpcap, but if the file has the magic number for an
  522|       |	 * unpatched libpcap we only read as many bytes as the regular
  523|       |	 * header has.
  524|       |	 */
  525|  42.4k|	amt_read = fread(&sf_hdr, 1, ps->hdrsize, fp);
  526|  42.4k|	if (amt_read != ps->hdrsize) {
  ------------------
  |  Branch (526:6): [True: 3.55k, False: 38.8k]
  ------------------
  527|  3.55k|		if (ferror(fp)) {
  ------------------
  |  Branch (527:7): [True: 0, False: 3.55k]
  ------------------
  528|      0|			pcapint_fmt_errmsg_for_errno(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  529|      0|			    errno, "error reading dump file");
  530|      0|			return (-1);
  531|  3.55k|		} else {
  532|  3.55k|			if (amt_read != 0) {
  ------------------
  |  Branch (532:8): [True: 284, False: 3.27k]
  ------------------
  533|    284|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|    284|#define PCAP_ERRBUF_SIZE 256
  ------------------
  534|    284|				    "truncated dump file; tried to read %zu header bytes, only got %zu",
  535|    284|				    ps->hdrsize, amt_read);
  536|    284|				return (-1);
  537|    284|			}
  538|       |			/* EOF */
  539|  3.27k|			return (0);
  540|  3.55k|		}
  541|  3.55k|	}
  542|       |
  543|  38.8k|	if (p->swapped) {
  ------------------
  |  Branch (543:6): [True: 27.8k, False: 11.0k]
  ------------------
  544|       |		/* these were written in opposite byte order */
  545|  27.8k|		hdr->caplen = PCAP_BSWAP_32(sf_hdr.caplen);
  ------------------
  |  |   78|  27.8k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  546|  27.8k|		hdr->len = PCAP_BSWAP_32(sf_hdr.len);
  ------------------
  |  |   78|  27.8k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  547|  27.8k|		hdr->ts.tv_sec = PCAP_BSWAP_32(sf_hdr.ts.tv_sec);
  ------------------
  |  |   78|  27.8k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  548|  27.8k|		hdr->ts.tv_usec = PCAP_BSWAP_32(sf_hdr.ts.tv_usec);
  ------------------
  |  |   78|  27.8k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  549|  27.8k|	} else {
  550|  11.0k|		hdr->caplen = sf_hdr.caplen;
  551|  11.0k|		hdr->len = sf_hdr.len;
  552|  11.0k|		hdr->ts.tv_sec = sf_hdr.ts.tv_sec;
  553|  11.0k|		hdr->ts.tv_usec = sf_hdr.ts.tv_usec;
  554|  11.0k|	}
  555|       |
  556|  38.8k|	switch (ps->scale_type) {
  ------------------
  |  Branch (556:10): [True: 38.8k, False: 0]
  ------------------
  557|       |
  558|  31.4k|	case PASS_THROUGH:
  ------------------
  |  Branch (558:2): [True: 31.4k, False: 7.40k]
  ------------------
  559|       |		/*
  560|       |		 * Just pass the time stamp through.
  561|       |		 */
  562|  31.4k|		break;
  563|       |
  564|      0|	case SCALE_UP:
  ------------------
  |  Branch (564:2): [True: 0, False: 38.8k]
  ------------------
  565|       |		/*
  566|       |		 * File has microseconds, user wants nanoseconds; convert
  567|       |		 * it.
  568|       |		 */
  569|      0|		hdr->ts.tv_usec = hdr->ts.tv_usec * 1000;
  570|      0|		break;
  571|       |
  572|  7.40k|	case SCALE_DOWN:
  ------------------
  |  Branch (572:2): [True: 7.40k, False: 31.4k]
  ------------------
  573|       |		/*
  574|       |		 * File has nanoseconds, user wants microseconds; convert
  575|       |		 * it.
  576|       |		 */
  577|  7.40k|		hdr->ts.tv_usec = hdr->ts.tv_usec / 1000;
  578|  7.40k|		break;
  579|  38.8k|	}
  580|       |
  581|       |	/* Swap the caplen and len fields, if necessary. */
  582|  38.8k|	switch (ps->lengths_swapped) {
  ------------------
  |  Branch (582:10): [True: 38.8k, False: 0]
  ------------------
  583|       |
  584|  6.29k|	case NOT_SWAPPED:
  ------------------
  |  Branch (584:2): [True: 6.29k, False: 32.5k]
  ------------------
  585|  6.29k|		break;
  586|       |
  587|  17.1k|	case MAYBE_SWAPPED:
  ------------------
  |  Branch (587:2): [True: 17.1k, False: 21.6k]
  ------------------
  588|  17.1k|		if (hdr->caplen <= hdr->len) {
  ------------------
  |  Branch (588:7): [True: 9.32k, False: 7.86k]
  ------------------
  589|       |			/*
  590|       |			 * The captured length is <= the actual length,
  591|       |			 * so presumably they weren't swapped.
  592|       |			 */
  593|  9.32k|			break;
  594|  9.32k|		}
  595|       |		/* FALLTHROUGH */
  596|       |
  597|  23.2k|	case SWAPPED:
  ------------------
  |  Branch (597:2): [True: 15.3k, False: 23.4k]
  ------------------
  598|  23.2k|		t = hdr->caplen;
  599|  23.2k|		hdr->caplen = hdr->len;
  600|  23.2k|		hdr->len = t;
  601|  23.2k|		break;
  602|  38.8k|	}
  603|       |
  604|       |	/*
  605|       |	 * Is the packet bigger than we consider sane?
  606|       |	 */
  607|  38.8k|	if (hdr->caplen > max_snaplen_for_dlt(p->linktype)) {
  ------------------
  |  Branch (607:6): [True: 97, False: 38.7k]
  ------------------
  608|       |		/*
  609|       |		 * Yes.  This may be a damaged or fuzzed file.
  610|       |		 *
  611|       |		 * Is it bigger than the snapshot length?
  612|       |		 * (We don't treat that as an error if it's not
  613|       |		 * bigger than the maximum we consider sane; see
  614|       |		 * below.)
  615|       |		 */
  616|     97|		if (hdr->caplen > (bpf_u_int32)p->snapshot) {
  ------------------
  |  Branch (616:7): [True: 82, False: 15]
  ------------------
  617|     82|			snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     82|#define PCAP_ERRBUF_SIZE 256
  ------------------
  618|     82|			    "invalid packet capture length %u, bigger than "
  619|     82|			    "snaplen of %d", hdr->caplen, p->snapshot);
  620|     82|		} else {
  621|     15|			snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     15|#define PCAP_ERRBUF_SIZE 256
  ------------------
  622|     15|			    "invalid packet capture length %u, bigger than "
  623|     15|			    "maximum of %u", hdr->caplen,
  624|     15|			    max_snaplen_for_dlt(p->linktype));
  625|     15|		}
  626|     97|		return (-1);
  627|     97|	}
  628|       |
  629|  38.7k|	if (hdr->caplen > (bpf_u_int32)p->snapshot) {
  ------------------
  |  Branch (629:6): [True: 3.16k, False: 35.5k]
  ------------------
  630|       |		/*
  631|       |		 * The packet is bigger than the snapshot length
  632|       |		 * for this file.
  633|       |		 *
  634|       |		 * This can happen due to Solaris 2.3 systems tripping
  635|       |		 * over the BUFMOD problem and not setting the snapshot
  636|       |		 * length correctly in the savefile header.
  637|       |		 *
  638|       |		 * libpcap 0.4 and later on Solaris 2.3 should set the
  639|       |		 * snapshot length correctly in the pcap file header,
  640|       |		 * even though they don't set a snapshot length in bufmod
  641|       |		 * (the buggy bufmod chops off the *beginning* of the
  642|       |		 * packet if a snapshot length is specified); they should
  643|       |		 * also reduce the captured length, as supplied to the
  644|       |		 * per-packet callback, to the snapshot length if it's
  645|       |		 * greater than the snapshot length, so the code using
  646|       |		 * libpcap should see the packet cut off at the snapshot
  647|       |		 * length, even though the full packet is copied up to
  648|       |		 * userland.
  649|       |		 *
  650|       |		 * However, perhaps some versions of libpcap failed to
  651|       |		 * set the snapshot length correctly in the file header
  652|       |		 * or the per-packet header, or perhaps this is a
  653|       |		 * corrupted savefile or a savefile built/modified by a
  654|       |		 * fuzz tester, so we check anyway.  We grow the buffer
  655|       |		 * to be big enough for the snapshot length, read up
  656|       |		 * to the snapshot length, discard the rest of the
  657|       |		 * packet, and report the snapshot length as the captured
  658|       |		 * length; we don't want to hand our caller a packet
  659|       |		 * bigger than the snapshot length, because they might
  660|       |		 * be assuming they'll never be handed such a packet,
  661|       |		 * and might copy the packet into a snapshot-length-
  662|       |		 * sized buffer, assuming it'll fit.
  663|       |		 */
  664|  3.16k|		size_t bytes_to_discard;
  665|  3.16k|		size_t bytes_to_read, bytes_read;
  666|  3.16k|		char discard_buf[4096];
  667|       |
  668|  3.16k|		if (hdr->caplen > p->bufsize) {
  ------------------
  |  Branch (668:7): [True: 3.16k, False: 0]
  ------------------
  669|       |			/*
  670|       |			 * Grow the buffer to the snapshot length.
  671|       |			 */
  672|  3.16k|			if (!grow_buffer(p, p->snapshot))
  ------------------
  |  Branch (672:8): [True: 0, False: 3.16k]
  ------------------
  673|      0|				return (-1);
  674|  3.16k|		}
  675|       |
  676|       |		/*
  677|       |		 * Read the first p->snapshot bytes into the buffer.
  678|       |		 */
  679|  3.16k|		amt_read = fread(p->buffer, 1, p->snapshot, fp);
  680|  3.16k|		if (amt_read != (bpf_u_int32)p->snapshot) {
  ------------------
  |  Branch (680:7): [True: 63, False: 3.10k]
  ------------------
  681|     63|			if (ferror(fp)) {
  ------------------
  |  Branch (681:8): [True: 0, False: 63]
  ------------------
  682|      0|				pcapint_fmt_errmsg_for_errno(p->errbuf,
  683|      0|				     PCAP_ERRBUF_SIZE, errno,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  684|      0|				    "error reading dump file");
  685|     63|			} else {
  686|       |				/*
  687|       |				 * Yes, this uses hdr->caplen; technically,
  688|       |				 * it's true, because we would try to read
  689|       |				 * and discard the rest of those bytes, and
  690|       |				 * that would fail because we got EOF before
  691|       |				 * the read finished.
  692|       |				 */
  693|     63|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     63|#define PCAP_ERRBUF_SIZE 256
  ------------------
  694|     63|				    "truncated dump file; tried to read %d captured bytes, only got %zu",
  695|     63|				    p->snapshot, amt_read);
  696|     63|			}
  697|     63|			return (-1);
  698|     63|		}
  699|       |
  700|       |		/*
  701|       |		 * Now read and discard what's left.
  702|       |		 */
  703|  3.10k|		bytes_to_discard = hdr->caplen - p->snapshot;
  704|  3.10k|		bytes_read = amt_read;
  705|  6.51k|		while (bytes_to_discard != 0) {
  ------------------
  |  Branch (705:10): [True: 3.47k, False: 3.03k]
  ------------------
  706|  3.47k|			bytes_to_read = bytes_to_discard;
  707|  3.47k|			if (bytes_to_read > sizeof (discard_buf))
  ------------------
  |  Branch (707:8): [True: 414, False: 3.06k]
  ------------------
  708|    414|				bytes_to_read = sizeof (discard_buf);
  709|  3.47k|			amt_read = fread(discard_buf, 1, bytes_to_read, fp);
  710|  3.47k|			bytes_read += amt_read;
  711|  3.47k|			if (amt_read != bytes_to_read) {
  ------------------
  |  Branch (711:8): [True: 64, False: 3.41k]
  ------------------
  712|     64|				if (ferror(fp)) {
  ------------------
  |  Branch (712:9): [True: 0, False: 64]
  ------------------
  713|      0|					pcapint_fmt_errmsg_for_errno(p->errbuf,
  714|      0|					    PCAP_ERRBUF_SIZE, errno,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  715|      0|					    "error reading dump file");
  716|     64|				} else {
  717|     64|					snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     64|#define PCAP_ERRBUF_SIZE 256
  ------------------
  718|     64|					    "truncated dump file; tried to read %u captured bytes, only got %zu",
  719|     64|					    hdr->caplen, bytes_read);
  720|     64|				}
  721|     64|				return (-1);
  722|     64|			}
  723|  3.41k|			bytes_to_discard -= amt_read;
  724|  3.41k|		}
  725|       |
  726|       |		/*
  727|       |		 * Adjust caplen accordingly, so we don't get confused later
  728|       |		 * as to how many bytes we have to play with.
  729|       |		 */
  730|  3.03k|		hdr->caplen = p->snapshot;
  731|  35.5k|	} else {
  732|       |		/*
  733|       |		 * The packet is within the snapshot length for this file.
  734|       |		 */
  735|  35.5k|		if (hdr->caplen > p->bufsize) {
  ------------------
  |  Branch (735:7): [True: 407, False: 35.1k]
  ------------------
  736|       |			/*
  737|       |			 * Grow the buffer to the next power of 2, or
  738|       |			 * the snaplen, whichever is lower.
  739|       |			 */
  740|    407|			u_int new_bufsize;
  741|       |
  742|    407|			new_bufsize = hdr->caplen;
  743|       |			/*
  744|       |			 * https://graphics.stanford.edu/~seander/bithacks.html#RoundUpPowerOf2
  745|       |			 */
  746|    407|			new_bufsize--;
  747|    407|			new_bufsize |= new_bufsize >> 1;
  748|    407|			new_bufsize |= new_bufsize >> 2;
  749|    407|			new_bufsize |= new_bufsize >> 4;
  750|    407|			new_bufsize |= new_bufsize >> 8;
  751|    407|			new_bufsize |= new_bufsize >> 16;
  752|    407|			new_bufsize++;
  753|       |
  754|    407|			if (new_bufsize > (u_int)p->snapshot)
  ------------------
  |  Branch (754:8): [True: 34, False: 373]
  ------------------
  755|     34|				new_bufsize = p->snapshot;
  756|       |
  757|    407|			if (!grow_buffer(p, new_bufsize))
  ------------------
  |  Branch (757:8): [True: 0, False: 407]
  ------------------
  758|      0|				return (-1);
  759|    407|		}
  760|       |
  761|       |		/* read the packet itself */
  762|  35.5k|		amt_read = fread(p->buffer, 1, hdr->caplen, fp);
  763|  35.5k|		if (amt_read != hdr->caplen) {
  ------------------
  |  Branch (763:7): [True: 120, False: 35.4k]
  ------------------
  764|    120|			if (ferror(fp)) {
  ------------------
  |  Branch (764:8): [True: 0, False: 120]
  ------------------
  765|      0|				pcapint_fmt_errmsg_for_errno(p->errbuf,
  766|      0|				    PCAP_ERRBUF_SIZE, errno,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  767|      0|				    "error reading dump file");
  768|    120|			} else {
  769|    120|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|    120|#define PCAP_ERRBUF_SIZE 256
  ------------------
  770|    120|				    "truncated dump file; tried to read %u captured bytes, only got %zu",
  771|    120|				    hdr->caplen, amt_read);
  772|    120|			}
  773|    120|			return (-1);
  774|    120|		}
  775|  35.5k|	}
  776|  38.5k|	*data = p->buffer;
  777|       |
  778|  38.5k|	pcapint_post_process(p->linktype, p->swapped, hdr, *data);
  779|       |
  780|  38.5k|	return (1);
  781|  38.7k|}
sf-pcap.c:grow_buffer:
  491|  3.57k|{
  492|  3.57k|	void *bigger_buffer;
  493|       |
  494|  3.57k|	bigger_buffer = realloc(p->buffer, bufsize);
  495|  3.57k|	if (bigger_buffer == NULL) {
  ------------------
  |  Branch (495:6): [True: 0, False: 3.57k]
  ------------------
  496|      0|		snprintf(p->errbuf, PCAP_ERRBUF_SIZE, "out of memory");
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  497|      0|		return (0);
  498|      0|	}
  499|  3.57k|	p->buffer = bigger_buffer;
  500|  3.57k|	p->bufsize = bufsize;
  501|  3.57k|	return (1);
  502|  3.57k|}

pcap_ng_check_header:
  771|  1.59k|{
  772|  1.59k|	bpf_u_int32 magic_int;
  773|  1.59k|	size_t amt_read;
  774|  1.59k|	bpf_u_int32 total_length;
  775|  1.59k|	bpf_u_int32 byte_order_magic;
  776|  1.59k|	struct block_header *bhdrp;
  777|  1.59k|	struct section_header_block *shbp;
  778|  1.59k|	pcap_t *p;
  779|  1.59k|	int swapped = 0;
  780|  1.59k|	struct pcap_ng_sf *ps;
  781|  1.59k|	int status;
  782|  1.59k|	struct block_cursor cursor;
  783|  1.59k|	struct interface_description_block *idbp;
  784|       |
  785|       |	/*
  786|       |	 * Assume no read errors.
  787|       |	 */
  788|  1.59k|	*err = 0;
  789|       |
  790|       |	/*
  791|       |	 * Check whether the first 4 bytes of the file are the block
  792|       |	 * type for a pcapng savefile.
  793|       |	 */
  794|  1.59k|	memcpy(&magic_int, magic, sizeof(magic_int));
  795|  1.59k|	if (magic_int != BT_SHB) {
  ------------------
  |  |   86|  1.59k|#define BT_SHB			0x0A0D0D0A
  ------------------
  |  Branch (795:6): [True: 225, False: 1.36k]
  ------------------
  796|       |		/*
  797|       |		 * XXX - check whether this looks like what the block
  798|       |		 * type would be after being munged by mapping between
  799|       |		 * UN*X and DOS/Windows text file format and, if it
  800|       |		 * does, look for the byte-order magic number in
  801|       |		 * the appropriate place and, if we find it, report
  802|       |		 * this as possibly being a pcapng file transferred
  803|       |		 * between UN*X and Windows in text file format?
  804|       |		 */
  805|    225|		return (NULL);	/* nope */
  806|    225|	}
  807|       |
  808|       |	/*
  809|       |	 * OK, they are.  However, that's just \n\r\r\n, so it could,
  810|       |	 * conceivably, be an ordinary text file.
  811|       |	 *
  812|       |	 * It could not, however, conceivably be any other type of
  813|       |	 * capture file, so we can read the rest of the putative
  814|       |	 * Section Header Block; put the block type in the common
  815|       |	 * header, read the rest of the common header and the
  816|       |	 * fixed-length portion of the SHB, and look for the byte-order
  817|       |	 * magic value.
  818|       |	 */
  819|  1.36k|	amt_read = fread(&total_length, 1, sizeof(total_length), fp);
  820|  1.36k|	if (amt_read < sizeof(total_length)) {
  ------------------
  |  Branch (820:6): [True: 0, False: 1.36k]
  ------------------
  821|      0|		if (ferror(fp)) {
  ------------------
  |  Branch (821:7): [True: 0, False: 0]
  ------------------
  822|      0|			pcapint_fmt_errmsg_for_errno(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  823|      0|			    errno, "error reading dump file");
  824|      0|			*err = 1;
  825|      0|			return (NULL);	/* fail */
  826|      0|		}
  827|       |
  828|       |		/*
  829|       |		 * Possibly a weird short text file, so just say
  830|       |		 * "not pcapng".
  831|       |		 */
  832|      0|		return (NULL);
  833|      0|	}
  834|  1.36k|	amt_read = fread(&byte_order_magic, 1, sizeof(byte_order_magic), fp);
  835|  1.36k|	if (amt_read < sizeof(byte_order_magic)) {
  ------------------
  |  Branch (835:6): [True: 0, False: 1.36k]
  ------------------
  836|      0|		if (ferror(fp)) {
  ------------------
  |  Branch (836:7): [True: 0, False: 0]
  ------------------
  837|      0|			pcapint_fmt_errmsg_for_errno(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  838|      0|			    errno, "error reading dump file");
  839|      0|			*err = 1;
  840|      0|			return (NULL);	/* fail */
  841|      0|		}
  842|       |
  843|       |		/*
  844|       |		 * Possibly a weird short text file, so just say
  845|       |		 * "not pcapng".
  846|       |		 */
  847|      0|		return (NULL);
  848|      0|	}
  849|  1.36k|	if (byte_order_magic != BYTE_ORDER_MAGIC) {
  ------------------
  |  |   99|  1.36k|#define BYTE_ORDER_MAGIC	0x1A2B3C4D
  ------------------
  |  Branch (849:6): [True: 530, False: 835]
  ------------------
  850|    530|		byte_order_magic = PCAP_BSWAP_32(byte_order_magic);
  ------------------
  |  |   78|    530|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  851|    530|		if (byte_order_magic != BYTE_ORDER_MAGIC) {
  ------------------
  |  |   99|    530|#define BYTE_ORDER_MAGIC	0x1A2B3C4D
  ------------------
  |  Branch (851:7): [True: 89, False: 441]
  ------------------
  852|       |			/*
  853|       |			 * Not a pcapng file.
  854|       |			 */
  855|     89|			return (NULL);
  856|     89|		}
  857|    441|		swapped = 1;
  858|    441|		total_length = PCAP_BSWAP_32(total_length);
  ------------------
  |  |   78|    441|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  859|    441|	}
  860|       |
  861|       |	/*
  862|       |	 * Check the sanity of the total length.
  863|       |	 */
  864|  1.27k|	if (total_length < sizeof(*bhdrp) + sizeof(*shbp) + sizeof(struct block_trailer) ||
  ------------------
  |  Branch (864:6): [True: 4, False: 1.27k]
  ------------------
  865|  1.27k|            (total_length > BT_SHB_INSANE_MAX)) {
  ------------------
  |  |   87|  1.27k|#define BT_SHB_INSANE_MAX       1024U*1024U*1U  /* 1MB should be enough */
  ------------------
  |  Branch (865:13): [True: 36, False: 1.23k]
  ------------------
  866|     40|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     40|#define PCAP_ERRBUF_SIZE 256
  ------------------
  867|     40|		    "Section Header Block in pcapng dump file has invalid length %zu < _%u_ < %u (BT_SHB_INSANE_MAX)",
  868|     40|		    sizeof(*bhdrp) + sizeof(*shbp) + sizeof(struct block_trailer),
  869|     40|		    total_length,
  870|     40|		    BT_SHB_INSANE_MAX);
  ------------------
  |  |   87|     40|#define BT_SHB_INSANE_MAX       1024U*1024U*1U  /* 1MB should be enough */
  ------------------
  871|       |
  872|     40|		*err = 1;
  873|     40|		return (NULL);
  874|     40|	}
  875|       |
  876|       |	/*
  877|       |	 * OK, this is a good pcapng file.
  878|       |	 * Allocate a pcap_t for it.
  879|       |	 */
  880|  1.23k|	p = PCAP_OPEN_OFFLINE_COMMON(errbuf, struct pcap_ng_sf);
  ------------------
  |  |  559|  1.23k|	pcapint_open_offline_common(ebuf, \
  |  |  560|  1.23k|	    sizeof (struct { pcap_t __common; type __private; }), \
  |  |  561|  1.23k|	    offsetof (struct { pcap_t __common; type __private; }, __private))
  ------------------
  881|  1.23k|	if (p == NULL) {
  ------------------
  |  Branch (881:6): [True: 0, False: 1.23k]
  ------------------
  882|       |		/* Allocation failed. */
  883|      0|		*err = 1;
  884|      0|		return (NULL);
  885|      0|	}
  886|  1.23k|	p->swapped = swapped;
  887|  1.23k|	ps = p->priv;
  888|       |
  889|       |	/*
  890|       |	 * What precision does the user want?
  891|       |	 */
  892|  1.23k|	switch (precision) {
  893|       |
  894|  1.23k|	case PCAP_TSTAMP_PRECISION_MICRO:
  ------------------
  |  |  537|  1.23k|#define PCAP_TSTAMP_PRECISION_MICRO	0	/* use timestamps with microsecond precision, default */
  ------------------
  |  Branch (894:2): [True: 1.23k, False: 0]
  ------------------
  895|  1.23k|		ps->user_tsresol = 1000000;
  896|  1.23k|		break;
  897|       |
  898|      0|	case PCAP_TSTAMP_PRECISION_NANO:
  ------------------
  |  |  538|      0|#define PCAP_TSTAMP_PRECISION_NANO	1	/* use timestamps with nanosecond precision */
  ------------------
  |  Branch (898:2): [True: 0, False: 1.23k]
  ------------------
  899|      0|		ps->user_tsresol = 1000000000;
  900|      0|		break;
  901|       |
  902|      0|	default:
  ------------------
  |  Branch (902:2): [True: 0, False: 1.23k]
  ------------------
  903|      0|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  904|      0|		    "unknown time stamp resolution %u", precision);
  905|      0|		free(p);
  906|      0|		*err = 1;
  907|      0|		return (NULL);
  908|  1.23k|	}
  909|       |
  910|  1.23k|	p->opt.tstamp_precision = precision;
  911|       |
  912|       |	/*
  913|       |	 * Allocate a buffer into which to read blocks.  We default to
  914|       |	 * the maximum of:
  915|       |	 *
  916|       |	 *	the total length of the SHB for which we read the header;
  917|       |	 *
  918|       |	 *	2K, which should be more than large enough for an Enhanced
  919|       |	 *	Packet Block containing a full-size Ethernet frame, and
  920|       |	 *	leaving room for some options.
  921|       |	 *
  922|       |	 * If we find a bigger block, we reallocate the buffer, up to
  923|       |	 * the maximum size.  We start out with a maximum size of
  924|       |	 * INITIAL_MAX_BLOCKSIZE; if we see any link-layer header types
  925|       |	 * with a maximum snapshot that results in a larger maximum
  926|       |	 * block length, we boost the maximum.
  927|       |	 */
  928|  1.23k|	p->bufsize = 2048;
  929|  1.23k|	if (p->bufsize < total_length)
  ------------------
  |  Branch (929:6): [True: 45, False: 1.19k]
  ------------------
  930|     45|		p->bufsize = total_length;
  931|  1.23k|	p->buffer = malloc(p->bufsize);
  932|  1.23k|	if (p->buffer == NULL) {
  ------------------
  |  Branch (932:6): [True: 0, False: 1.23k]
  ------------------
  933|      0|		snprintf(errbuf, PCAP_ERRBUF_SIZE, "out of memory");
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  934|      0|		free(p);
  935|      0|		*err = 1;
  936|      0|		return (NULL);
  937|      0|	}
  938|  1.23k|	ps->max_blocksize = INITIAL_MAX_BLOCKSIZE;
  ------------------
  |  |  238|  1.23k|#define INITIAL_MAX_BLOCKSIZE	(16*1024*1024)
  ------------------
  939|       |
  940|       |	/*
  941|       |	 * Copy the stuff we've read to the buffer, and read the rest
  942|       |	 * of the SHB.
  943|       |	 */
  944|  1.23k|	bhdrp = (struct block_header *)p->buffer;
  945|  1.23k|	shbp = (struct section_header_block *)(p->buffer + sizeof(struct block_header));
  946|  1.23k|	bhdrp->block_type = magic_int;
  947|  1.23k|	bhdrp->total_length = total_length;
  948|  1.23k|	shbp->byte_order_magic = byte_order_magic;
  949|  1.23k|	if (read_bytes(fp,
  ------------------
  |  Branch (949:6): [True: 59, False: 1.17k]
  ------------------
  950|  1.23k|	    p->buffer + (sizeof(magic_int) + sizeof(total_length) + sizeof(byte_order_magic)),
  951|  1.23k|	    total_length - (sizeof(magic_int) + sizeof(total_length) + sizeof(byte_order_magic)),
  952|  1.23k|	    1, errbuf) == -1)
  953|     59|		goto fail;
  954|       |
  955|  1.17k|	if (p->swapped) {
  ------------------
  |  Branch (955:6): [True: 414, False: 763]
  ------------------
  956|       |		/*
  957|       |		 * Byte-swap the fields we've read.
  958|       |		 */
  959|    414|		shbp->major_version = PCAP_BSWAP_16(shbp->major_version);
  ------------------
  |  |   88|    414|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  960|    414|		shbp->minor_version = PCAP_BSWAP_16(shbp->minor_version);
  ------------------
  |  |   88|    414|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  961|       |
  962|       |		/*
  963|       |		 * XXX - we don't care about the section length.
  964|       |		 */
  965|    414|	}
  966|       |	/* Currently only SHB versions 1.0 and 1.2 are supported;
  967|       |	   version 1.2 is treated as being the same as version 1.0.
  968|       |	   See the current version of the pcapng specification.
  969|       |
  970|       |	   Version 1.2 is written by some programs that write additional
  971|       |	   block types (which can be read by any code that handles them,
  972|       |	   regardless of whether the minor version if 0 or 2, so that's
  973|       |	   not a reason to change the minor version number).
  974|       |
  975|       |	   XXX - the pcapng specification says that readers should
  976|       |	   just ignore sections with an unsupported version number;
  977|       |	   presumably they can also report an error if they skip
  978|       |	   all the way to the end of the file without finding
  979|       |	   any versions that they support. */
  980|  1.17k|	if (! (shbp->major_version == PCAP_NG_VERSION_MAJOR &&
  ------------------
  |  |  106|  2.35k|#define PCAP_NG_VERSION_MAJOR	1
  ------------------
  |  Branch (980:9): [True: 1.16k, False: 16]
  ------------------
  981|  1.16k|	       (shbp->minor_version == PCAP_NG_VERSION_MINOR ||
  ------------------
  |  |  107|  2.32k|#define PCAP_NG_VERSION_MINOR	0
  ------------------
  |  Branch (981:10): [True: 1.12k, False: 33]
  ------------------
  982|     40|	        shbp->minor_version == 2))) {
  ------------------
  |  Branch (982:10): [True: 9, False: 24]
  ------------------
  983|     40|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     40|#define PCAP_ERRBUF_SIZE 256
  ------------------
  984|     40|		    "unsupported pcapng savefile version %u.%u",
  985|     40|		    shbp->major_version, shbp->minor_version);
  986|     40|		goto fail;
  987|     40|	}
  988|  1.13k|	p->version_major = shbp->major_version;
  989|  1.13k|	p->version_minor = shbp->minor_version;
  990|       |
  991|       |	/*
  992|       |	 * Save the time stamp resolution the user requested.
  993|       |	 */
  994|  1.13k|	p->opt.tstamp_precision = precision;
  995|       |
  996|       |	/*
  997|       |	 * Now start looking for an Interface Description Block.
  998|       |	 */
  999|  1.40k|	for (;;) {
 1000|       |		/*
 1001|       |		 * Read the next block.
 1002|       |		 */
 1003|  1.40k|		status = read_block(fp, p, &cursor, errbuf);
 1004|  1.40k|		if (status == 0) {
  ------------------
  |  Branch (1004:7): [True: 13, False: 1.39k]
  ------------------
 1005|       |			/* EOF - no IDB in this file */
 1006|     13|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     13|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1007|     13|			    "the capture file has no Interface Description Blocks");
 1008|     13|			goto fail;
 1009|     13|		}
 1010|  1.39k|		if (status == -1)
  ------------------
  |  Branch (1010:7): [True: 177, False: 1.21k]
  ------------------
 1011|    177|			goto fail;	/* error */
 1012|  1.21k|		switch (cursor.block_type) {
 1013|       |
 1014|    944|		case BT_IDB:
  ------------------
  |  |  112|    944|#define BT_IDB			0x00000001
  ------------------
  |  Branch (1014:3): [True: 944, False: 273]
  ------------------
 1015|       |			/*
 1016|       |			 * Get a pointer to the fixed-length portion of the
 1017|       |			 * IDB.
 1018|       |			 */
 1019|    944|			idbp = get_from_block_data(&cursor, sizeof(*idbp),
 1020|    944|			    errbuf);
 1021|    944|			if (idbp == NULL)
  ------------------
  |  Branch (1021:8): [True: 2, False: 942]
  ------------------
 1022|      2|				goto fail;	/* error */
 1023|       |
 1024|       |			/*
 1025|       |			 * Byte-swap it if necessary.
 1026|       |			 */
 1027|    942|			if (p->swapped) {
  ------------------
  |  Branch (1027:8): [True: 325, False: 617]
  ------------------
 1028|    325|				idbp->linktype = PCAP_BSWAP_16(idbp->linktype);
  ------------------
  |  |   88|    325|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
 1029|    325|				idbp->snaplen = PCAP_BSWAP_32(idbp->snaplen);
  ------------------
  |  |   78|    325|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1030|    325|			}
 1031|       |
 1032|       |			/*
 1033|       |			 * Try to add this interface.
 1034|       |			 */
 1035|    942|			if (!add_interface(p, idbp, &cursor, errbuf))
  ------------------
  |  Branch (1035:8): [True: 88, False: 854]
  ------------------
 1036|     88|				goto fail;
 1037|       |
 1038|    854|			goto done;
 1039|       |
 1040|    854|		case BT_EPB:
  ------------------
  |  |  141|      1|#define BT_EPB			0x00000006
  ------------------
  |  Branch (1040:3): [True: 1, False: 1.21k]
  ------------------
 1041|      2|		case BT_SPB:
  ------------------
  |  |  155|      2|#define BT_SPB			0x00000003
  ------------------
  |  Branch (1041:3): [True: 1, False: 1.21k]
  ------------------
 1042|      3|		case BT_PB:
  ------------------
  |  |  165|      3|#define BT_PB			0x00000002
  ------------------
  |  Branch (1042:3): [True: 1, False: 1.21k]
  ------------------
 1043|       |			/*
 1044|       |			 * Saw a packet before we saw any IDBs.  That's
 1045|       |			 * not valid, as we don't know what link-layer
 1046|       |			 * encapsulation the packet has.
 1047|       |			 */
 1048|      3|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      3|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1049|      3|			    "the capture file has a packet block before any Interface Description Blocks");
 1050|      3|			goto fail;
 1051|       |
 1052|    270|		default:
  ------------------
  |  Branch (1052:3): [True: 270, False: 947]
  ------------------
 1053|       |			/*
 1054|       |			 * Just ignore it.
 1055|       |			 */
 1056|    270|			break;
 1057|  1.21k|		}
 1058|  1.21k|	}
 1059|       |
 1060|    854|done:
 1061|    854|	p->linktype = linktype_to_dlt(idbp->linktype);
 1062|    854|	p->snapshot = pcapint_adjust_snapshot(p->linktype, idbp->snaplen);
 1063|    854|	p->linktype_ext = 0;
 1064|       |
 1065|       |	/*
 1066|       |	 * If the maximum block size for a packet with the maximum
 1067|       |	 * snapshot length for this DLT_ is bigger than the current
 1068|       |	 * maximum block size, increase the maximum.
 1069|       |	 */
 1070|    854|	if (MAX_BLOCKSIZE_FOR_SNAPLEN(max_snaplen_for_dlt(p->linktype)) > ps->max_blocksize)
  ------------------
  |  |  246|    854|	(sizeof (struct block_header) + \
  |  |  247|    854|	 sizeof (struct enhanced_packet_block) + \
  |  |  248|    854|	 (max_snaplen) + 131072 + \
  |  |  249|    854|	 sizeof (struct block_trailer))
  ------------------
  |  Branch (1070:6): [True: 48, False: 806]
  ------------------
 1071|     48|		ps->max_blocksize = MAX_BLOCKSIZE_FOR_SNAPLEN(max_snaplen_for_dlt(p->linktype));
  ------------------
  |  |  246|     48|	(sizeof (struct block_header) + \
  |  |  247|     48|	 sizeof (struct enhanced_packet_block) + \
  |  |  248|     48|	 (max_snaplen) + 131072 + \
  |  |  249|     48|	 sizeof (struct block_trailer))
  ------------------
 1072|       |
 1073|    854|	p->next_packet_op = pcap_ng_next_packet;
 1074|    854|	p->cleanup_op = pcap_ng_cleanup;
 1075|       |
 1076|    854|	return (p);
 1077|       |
 1078|    382|fail:
 1079|    382|	free(ps->ifaces);
 1080|    382|	free(p->buffer);
 1081|    382|	free(p);
 1082|    382|	*err = 1;
 1083|       |	return (NULL);
 1084|  1.13k|}
sf-pcapng.c:read_bytes:
  258|  34.0k|{
  259|  34.0k|	size_t amt_read;
  260|       |
  261|  34.0k|	amt_read = fread(buf, 1, bytes_to_read, fp);
  262|  34.0k|	if (amt_read != bytes_to_read) {
  ------------------
  |  Branch (262:6): [True: 508, False: 33.5k]
  ------------------
  263|    508|		if (ferror(fp)) {
  ------------------
  |  Branch (263:7): [True: 0, False: 508]
  ------------------
  264|      0|			pcapint_fmt_errmsg_for_errno(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  265|      0|			    errno, "error reading dump file");
  266|    508|		} else {
  267|    508|			if (amt_read == 0 && !fail_on_eof)
  ------------------
  |  Branch (267:8): [True: 377, False: 131]
  |  Branch (267:25): [True: 343, False: 34]
  ------------------
  268|    343|				return (0);	/* EOF */
  269|    165|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|    165|#define PCAP_ERRBUF_SIZE 256
  ------------------
  270|    165|			    "truncated pcapng dump file; tried to read %zu bytes, only got %zu",
  271|    165|			    bytes_to_read, amt_read);
  272|    165|		}
  273|    165|		return (-1);
  274|    508|	}
  275|  33.5k|	return (1);
  276|  34.0k|}
sf-pcapng.c:read_block:
  280|  16.6k|{
  281|  16.6k|	struct pcap_ng_sf *ps;
  282|  16.6k|	int status;
  283|  16.6k|	struct block_header bhdr;
  284|  16.6k|	struct block_trailer *btrlr;
  285|  16.6k|	u_char *bdata;
  286|  16.6k|	size_t data_remaining;
  287|       |
  288|  16.6k|	ps = p->priv;
  289|       |
  290|  16.6k|	status = read_bytes(fp, &bhdr, sizeof(bhdr), 0, errbuf);
  291|  16.6k|	if (status <= 0)
  ------------------
  |  Branch (291:6): [True: 398, False: 16.2k]
  ------------------
  292|    398|		return (status);	/* error or EOF */
  293|       |
  294|  16.2k|	if (p->swapped) {
  ------------------
  |  Branch (294:6): [True: 7.17k, False: 9.07k]
  ------------------
  295|  7.17k|		bhdr.block_type = PCAP_BSWAP_32(bhdr.block_type);
  ------------------
  |  |   78|  7.17k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  296|  7.17k|		bhdr.total_length = PCAP_BSWAP_32(bhdr.total_length);
  ------------------
  |  |   78|  7.17k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  297|  7.17k|	}
  298|       |
  299|       |	/*
  300|       |	 * Is this block "too small" - i.e., is it shorter than a block
  301|       |	 * header plus a block trailer?
  302|       |	 */
  303|  16.2k|	if (bhdr.total_length < sizeof(struct block_header) +
  ------------------
  |  Branch (303:6): [True: 10, False: 16.2k]
  ------------------
  304|  16.2k|	    sizeof(struct block_trailer)) {
  305|     10|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     10|#define PCAP_ERRBUF_SIZE 256
  ------------------
  306|     10|		    "block in pcapng dump file has a length of %u < %zu",
  307|     10|		    bhdr.total_length,
  308|     10|		    sizeof(struct block_header) + sizeof(struct block_trailer));
  309|     10|		return (-1);
  310|     10|	}
  311|       |
  312|       |	/*
  313|       |	 * Is the block total length a multiple of 4?
  314|       |	 */
  315|  16.2k|	if ((bhdr.total_length % 4) != 0) {
  ------------------
  |  Branch (315:6): [True: 12, False: 16.2k]
  ------------------
  316|       |		/*
  317|       |		 * No.  Report that as an error.
  318|       |		 */
  319|     12|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     12|#define PCAP_ERRBUF_SIZE 256
  ------------------
  320|     12|		    "block in pcapng dump file has a length of %u that is not a multiple of 4",
  321|     12|		    bhdr.total_length);
  322|     12|		return (-1);
  323|     12|	}
  324|       |
  325|       |	/*
  326|       |	 * Is the buffer big enough?
  327|       |	 */
  328|  16.2k|	if (p->bufsize < bhdr.total_length) {
  ------------------
  |  Branch (328:6): [True: 212, False: 16.0k]
  ------------------
  329|       |		/*
  330|       |		 * No - make it big enough, unless it's too big, in
  331|       |		 * which case we fail.
  332|       |		 */
  333|    212|		void *bigger_buffer;
  334|       |
  335|    212|		if (bhdr.total_length > ps->max_blocksize) {
  ------------------
  |  Branch (335:7): [True: 78, False: 134]
  ------------------
  336|     78|			snprintf(errbuf, PCAP_ERRBUF_SIZE, "pcapng block size %u > maximum %u", bhdr.total_length,
  ------------------
  |  |  149|     78|#define PCAP_ERRBUF_SIZE 256
  ------------------
  337|     78|			    ps->max_blocksize);
  338|     78|			return (-1);
  339|     78|		}
  340|    134|		bigger_buffer = realloc(p->buffer, bhdr.total_length);
  341|    134|		if (bigger_buffer == NULL) {
  ------------------
  |  Branch (341:7): [True: 0, False: 134]
  ------------------
  342|      0|			snprintf(errbuf, PCAP_ERRBUF_SIZE, "out of memory");
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  343|      0|			return (-1);
  344|      0|		}
  345|    134|		p->buffer = bigger_buffer;
  346|    134|	}
  347|       |
  348|       |	/*
  349|       |	 * Copy the stuff we've read to the buffer, and read the rest
  350|       |	 * of the block.
  351|       |	 */
  352|  16.1k|	memcpy(p->buffer, &bhdr, sizeof(bhdr));
  353|  16.1k|	bdata = p->buffer + sizeof(bhdr);
  354|  16.1k|	data_remaining = bhdr.total_length - sizeof(bhdr);
  355|  16.1k|	if (read_bytes(fp, bdata, data_remaining, 1, errbuf) == -1)
  ------------------
  |  Branch (355:6): [True: 51, False: 16.1k]
  ------------------
  356|     51|		return (-1);
  357|       |
  358|       |	/*
  359|       |	 * Get the block size from the trailer.
  360|       |	 */
  361|  16.1k|	btrlr = (struct block_trailer *)(bdata + data_remaining - sizeof (struct block_trailer));
  362|  16.1k|	if (p->swapped)
  ------------------
  |  Branch (362:6): [True: 7.12k, False: 8.97k]
  ------------------
  363|  7.12k|		btrlr->total_length = PCAP_BSWAP_32(btrlr->total_length);
  ------------------
  |  |   78|  7.12k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  364|       |
  365|       |	/*
  366|       |	 * Is the total length from the trailer the same as the total
  367|       |	 * length from the header?
  368|       |	 */
  369|  16.1k|	if (bhdr.total_length != btrlr->total_length) {
  ------------------
  |  Branch (369:6): [True: 53, False: 16.0k]
  ------------------
  370|       |		/*
  371|       |		 * No.
  372|       |		 */
  373|     53|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     53|#define PCAP_ERRBUF_SIZE 256
  ------------------
  374|     53|		    "block total length in header %u and trailer %u don't match",
  375|     53|		    bhdr.total_length, btrlr->total_length);
  376|     53|		return (-1);
  377|     53|	}
  378|       |
  379|       |	/*
  380|       |	 * Initialize the cursor.
  381|       |	 */
  382|  16.0k|	cursor->data = bdata;
  383|  16.0k|	cursor->data_remaining = data_remaining - sizeof(struct block_trailer);
  384|  16.0k|	cursor->block_type = bhdr.block_type;
  385|  16.0k|	return (1);
  386|  16.1k|}
sf-pcapng.c:get_from_block_data:
  391|  44.3k|{
  392|  44.3k|	void *data;
  393|       |
  394|       |	/*
  395|       |	 * Make sure we have the specified amount of data remaining in
  396|       |	 * the block data.
  397|       |	 */
  398|  44.3k|	if (cursor->data_remaining < chunk_size) {
  ------------------
  |  Branch (398:6): [True: 125, False: 44.2k]
  ------------------
  399|    125|		snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|    125|#define PCAP_ERRBUF_SIZE 256
  ------------------
  400|    125|		    "block of type %u in pcapng dump file is too short",
  401|    125|		    cursor->block_type);
  402|    125|		return (NULL);
  403|    125|	}
  404|       |
  405|       |	/*
  406|       |	 * Return the current pointer, and skip past the chunk.
  407|       |	 */
  408|  44.2k|	data = cursor->data;
  409|  44.2k|	cursor->data += chunk_size;
  410|  44.2k|	cursor->data_remaining -= chunk_size;
  411|  44.2k|	return (data);
  412|  44.3k|}
sf-pcapng.c:add_interface:
  594|  12.2k|{
  595|  12.2k|	struct pcap_ng_sf *ps;
  596|  12.2k|	uint64_t tsresol;
  597|  12.2k|	int64_t tsoffset;
  598|  12.2k|	int is_binary;
  599|       |
  600|  12.2k|	ps = p->priv;
  601|       |
  602|       |	/*
  603|       |	 * Count this interface.
  604|       |	 */
  605|  12.2k|	ps->ifcount++;
  606|       |
  607|       |	/*
  608|       |	 * Grow the array of per-interface information as necessary.
  609|       |	 */
  610|  12.2k|	if (ps->ifcount > ps->ifaces_size) {
  ------------------
  |  Branch (610:6): [True: 1.44k, False: 10.7k]
  ------------------
  611|       |		/*
  612|       |		 * We need to grow the array.
  613|       |		 */
  614|  1.44k|		bpf_u_int32 new_ifaces_size;
  615|  1.44k|		struct pcap_ng_if *new_ifaces;
  616|       |
  617|  1.44k|		if (ps->ifaces_size == 0) {
  ------------------
  |  Branch (617:7): [True: 942, False: 499]
  ------------------
  618|       |			/*
  619|       |			 * It's currently empty.
  620|       |			 *
  621|       |			 * (The Clang static analyzer doesn't do enough,
  622|       |			 * err, umm, dataflow *analysis* to realize that
  623|       |			 * ps->ifaces_size == 0 if ps->ifaces == NULL,
  624|       |			 * and so complains about a possible zero argument
  625|       |			 * to realloc(), so we check for the former
  626|       |			 * condition to shut it up.
  627|       |			 *
  628|       |			 * However, it doesn't complain that one of the
  629|       |			 * multiplications below could overflow, which is
  630|       |			 * a real, albeit extremely unlikely, problem (you'd
  631|       |			 * need a pcapng file with tens of millions of
  632|       |			 * interfaces).)
  633|       |			 */
  634|    942|			new_ifaces_size = 1;
  635|    942|			new_ifaces = malloc(sizeof (struct pcap_ng_if));
  636|    942|		} else {
  637|       |			/*
  638|       |			 * It's not currently empty; double its size.
  639|       |			 * (Perhaps overkill once we have a lot of interfaces.)
  640|       |			 *
  641|       |			 * Check for overflow if we double it.
  642|       |			 */
  643|    499|			if (ps->ifaces_size * 2 < ps->ifaces_size) {
  ------------------
  |  Branch (643:8): [True: 0, False: 499]
  ------------------
  644|       |				/*
  645|       |				 * The maximum number of interfaces before
  646|       |				 * ps->ifaces_size overflows is the largest
  647|       |				 * possible 32-bit power of 2, as we do
  648|       |				 * size doubling.
  649|       |				 */
  650|      0|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  651|      0|				    "more than %u interfaces in the file",
  652|      0|				    0x80000000U);
  653|      0|				return (0);
  654|      0|			}
  655|       |
  656|       |			/*
  657|       |			 * ps->ifaces_size * 2 doesn't overflow, so it's
  658|       |			 * safe to multiply.
  659|       |			 */
  660|    499|			new_ifaces_size = ps->ifaces_size * 2;
  661|       |
  662|       |			/*
  663|       |			 * Now make sure that's not so big that it overflows
  664|       |			 * if we multiply by sizeof (struct pcap_ng_if).
  665|       |			 *
  666|       |			 * That can happen on 32-bit platforms, with a 32-bit
  667|       |			 * size_t; it shouldn't happen on 64-bit platforms,
  668|       |			 * with a 64-bit size_t, as new_ifaces_size is
  669|       |			 * 32 bits.
  670|       |			 */
  671|    499|			if (new_ifaces_size * sizeof (struct pcap_ng_if) < new_ifaces_size) {
  ------------------
  |  Branch (671:8): [True: 0, False: 499]
  ------------------
  672|       |				/*
  673|       |				 * As this fails only with 32-bit size_t,
  674|       |				 * the multiplication was 32x32->32, and
  675|       |				 * the largest 32-bit value that can safely
  676|       |				 * be multiplied by sizeof (struct pcap_ng_if)
  677|       |				 * without overflow is the largest 32-bit
  678|       |				 * (unsigned) value divided by
  679|       |				 * sizeof (struct pcap_ng_if).
  680|       |				 */
  681|      0|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  682|      0|				    "more than %u interfaces in the file",
  683|      0|				    0xFFFFFFFFU / ((u_int)sizeof (struct pcap_ng_if)));
  684|      0|				return (0);
  685|      0|			}
  686|    499|			new_ifaces = realloc(ps->ifaces, new_ifaces_size * sizeof (struct pcap_ng_if));
  687|    499|		}
  688|  1.44k|		if (new_ifaces == NULL) {
  ------------------
  |  Branch (688:7): [True: 0, False: 1.44k]
  ------------------
  689|       |			/*
  690|       |			 * We ran out of memory.
  691|       |			 * Give up.
  692|       |			 */
  693|      0|			snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      0|#define PCAP_ERRBUF_SIZE 256
  ------------------
  694|      0|			    "out of memory for per-interface information (%u interfaces)",
  695|      0|			    ps->ifcount);
  696|      0|			return (0);
  697|      0|		}
  698|  1.44k|		ps->ifaces_size = new_ifaces_size;
  699|  1.44k|		ps->ifaces = new_ifaces;
  700|  1.44k|	}
  701|       |
  702|  12.2k|	ps->ifaces[ps->ifcount - 1].snaplen = idbp->snaplen;
  703|       |
  704|       |	/*
  705|       |	 * Set the default time stamp resolution and offset.
  706|       |	 */
  707|  12.2k|	tsresol = 1000000;	/* microsecond resolution */
  708|  12.2k|	is_binary = 0;		/* which is a power of 10 */
  709|  12.2k|	tsoffset = 0;		/* absolute timestamps */
  710|       |
  711|       |	/*
  712|       |	 * Now look for various time stamp options, so we know
  713|       |	 * how to interpret the time stamps for this interface.
  714|       |	 */
  715|  12.2k|	if (process_idb_options(p, cursor, &tsresol, &tsoffset, &is_binary,
  ------------------
  |  Branch (715:6): [True: 94, False: 12.1k]
  ------------------
  716|  12.2k|	    errbuf) == -1)
  717|     94|		return (0);
  718|       |
  719|  12.1k|	ps->ifaces[ps->ifcount - 1].tsresol = tsresol;
  720|  12.1k|	ps->ifaces[ps->ifcount - 1].tsoffset = tsoffset;
  721|       |
  722|       |	/*
  723|       |	 * Determine whether we're scaling up or down or not
  724|       |	 * at all for this interface.
  725|       |	 */
  726|  12.1k|	if (tsresol == ps->user_tsresol) {
  ------------------
  |  Branch (726:6): [True: 6.00k, False: 6.12k]
  ------------------
  727|       |		/*
  728|       |		 * The resolution is the resolution the user wants,
  729|       |		 * so we don't have to do scaling.
  730|       |		 */
  731|  6.00k|		ps->ifaces[ps->ifcount - 1].scale_type = PASS_THROUGH;
  732|  6.12k|	} else if (tsresol > ps->user_tsresol) {
  ------------------
  |  Branch (732:13): [True: 814, False: 5.31k]
  ------------------
  733|       |		/*
  734|       |		 * The resolution is greater than what the user wants,
  735|       |		 * so we have to scale the timestamps down.
  736|       |		 */
  737|    814|		if (is_binary)
  ------------------
  |  Branch (737:7): [True: 261, False: 553]
  ------------------
  738|    261|			ps->ifaces[ps->ifcount - 1].scale_type = SCALE_DOWN_BIN;
  739|    553|		else {
  740|       |			/*
  741|       |			 * Calculate the scale factor.
  742|       |			 */
  743|    553|			ps->ifaces[ps->ifcount - 1].scale_factor = tsresol/ps->user_tsresol;
  744|    553|			ps->ifaces[ps->ifcount - 1].scale_type = SCALE_DOWN_DEC;
  745|    553|		}
  746|  5.31k|	} else {
  747|       |		/*
  748|       |		 * The resolution is less than what the user wants,
  749|       |		 * so we have to scale the timestamps up.
  750|       |		 */
  751|  5.31k|		if (is_binary)
  ------------------
  |  Branch (751:7): [True: 623, False: 4.68k]
  ------------------
  752|    623|			ps->ifaces[ps->ifcount - 1].scale_type = SCALE_UP_BIN;
  753|  4.68k|		else {
  754|       |			/*
  755|       |			 * Calculate the scale factor.
  756|       |			 */
  757|  4.68k|			ps->ifaces[ps->ifcount - 1].scale_factor = ps->user_tsresol/tsresol;
  758|  4.68k|			ps->ifaces[ps->ifcount - 1].scale_type = SCALE_UP_DEC;
  759|  4.68k|		}
  760|  5.31k|	}
  761|  12.1k|	return (1);
  762|  12.2k|}
sf-pcapng.c:process_idb_options:
  463|  12.2k|{
  464|  12.2k|	struct option_header *opthdr;
  465|  12.2k|	void *optvalue;
  466|  12.2k|	int saw_tsresol, saw_tsoffset;
  467|  12.2k|	uint8_t tsresol_opt;
  468|  12.2k|	u_int i;
  469|       |
  470|  12.2k|	saw_tsresol = 0;
  471|  12.2k|	saw_tsoffset = 0;
  472|  24.9k|	while (cursor->data_remaining != 0) {
  ------------------
  |  Branch (472:9): [True: 13.4k, False: 11.5k]
  ------------------
  473|       |		/*
  474|       |		 * Get the option header.
  475|       |		 */
  476|  13.4k|		opthdr = get_opthdr_from_block_data(p, cursor, errbuf);
  477|  13.4k|		if (opthdr == NULL) {
  ------------------
  |  Branch (477:7): [True: 0, False: 13.4k]
  ------------------
  478|       |			/*
  479|       |			 * Option header is cut short.
  480|       |			 */
  481|      0|			return (-1);
  482|      0|		}
  483|       |
  484|       |		/*
  485|       |		 * Get option value.
  486|       |		 */
  487|  13.4k|		optvalue = get_optvalue_from_block_data(cursor, opthdr,
  488|  13.4k|		    errbuf);
  489|  13.4k|		if (optvalue == NULL) {
  ------------------
  |  Branch (489:7): [True: 32, False: 13.4k]
  ------------------
  490|       |			/*
  491|       |			 * Option value is cut short.
  492|       |			 */
  493|     32|			return (-1);
  494|     32|		}
  495|       |
  496|  13.4k|		switch (opthdr->option_code) {
  497|       |
  498|    633|		case OPT_ENDOFOPT:
  ------------------
  |  |   67|    633|#define OPT_ENDOFOPT	0	/* end of options */
  ------------------
  |  Branch (498:3): [True: 633, False: 12.8k]
  ------------------
  499|    633|			if (opthdr->option_length != 0) {
  ------------------
  |  Branch (499:8): [True: 23, False: 610]
  ------------------
  500|     23|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     23|#define PCAP_ERRBUF_SIZE 256
  ------------------
  501|     23|				    "Interface Description Block has opt_endofopt option with length %u != 0",
  502|     23|				    opthdr->option_length);
  503|     23|				return (-1);
  504|     23|			}
  505|    610|			goto done;
  506|       |
  507|  6.15k|		case IF_TSRESOL:
  ------------------
  |  |  131|  6.15k|#define IF_TSRESOL	9	/* interface's time stamp resolution */
  ------------------
  |  Branch (507:3): [True: 6.15k, False: 7.28k]
  ------------------
  508|  6.15k|			if (opthdr->option_length != 1) {
  ------------------
  |  Branch (508:8): [True: 14, False: 6.13k]
  ------------------
  509|     14|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     14|#define PCAP_ERRBUF_SIZE 256
  ------------------
  510|     14|				    "Interface Description Block has if_tsresol option with length %u != 1",
  511|     14|				    opthdr->option_length);
  512|     14|				return (-1);
  513|     14|			}
  514|  6.13k|			if (saw_tsresol) {
  ------------------
  |  Branch (514:8): [True: 1, False: 6.13k]
  ------------------
  515|      1|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      1|#define PCAP_ERRBUF_SIZE 256
  ------------------
  516|      1|				    "Interface Description Block has more than one if_tsresol option");
  517|      1|				return (-1);
  518|      1|			}
  519|  6.13k|			saw_tsresol = 1;
  520|  6.13k|			memcpy(&tsresol_opt, optvalue, sizeof(tsresol_opt));
  521|  6.13k|			if (tsresol_opt & 0x80) {
  ------------------
  |  Branch (521:8): [True: 893, False: 5.24k]
  ------------------
  522|       |				/*
  523|       |				 * Resolution is negative power of 2.
  524|       |				 */
  525|    893|				uint8_t tsresol_shift = (tsresol_opt & 0x7F);
  526|       |
  527|    893|				if (tsresol_shift > 63) {
  ------------------
  |  Branch (527:9): [True: 8, False: 885]
  ------------------
  528|       |					/*
  529|       |					 * Resolution is too high; 2^-{res}
  530|       |					 * won't fit in a 64-bit value.
  531|       |					 */
  532|      8|					snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      8|#define PCAP_ERRBUF_SIZE 256
  ------------------
  533|      8|					    "Interface Description Block if_tsresol option resolution 2^-%u is too high",
  534|      8|					    tsresol_shift);
  535|      8|					return (-1);
  536|      8|				}
  537|    885|				*is_binary = 1;
  538|    885|				*tsresol = ((uint64_t)1) << tsresol_shift;
  539|  5.24k|			} else {
  540|       |				/*
  541|       |				 * Resolution is negative power of 10.
  542|       |				 */
  543|  5.24k|				if (tsresol_opt > 19) {
  ------------------
  |  Branch (543:9): [True: 1, False: 5.24k]
  ------------------
  544|       |					/*
  545|       |					 * Resolution is too high; 2^-{res}
  546|       |					 * won't fit in a 64-bit value (the
  547|       |					 * largest power of 10 that fits
  548|       |					 * in a 64-bit value is 10^19, as
  549|       |					 * the largest 64-bit unsigned
  550|       |					 * value is ~1.8*10^19).
  551|       |					 */
  552|      1|					snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      1|#define PCAP_ERRBUF_SIZE 256
  ------------------
  553|      1|					    "Interface Description Block if_tsresol option resolution 10^-%u is too high",
  554|      1|					    tsresol_opt);
  555|      1|					return (-1);
  556|      1|				}
  557|  5.24k|				*is_binary = 0;
  558|  5.24k|				*tsresol = 1;
  559|  29.9k|				for (i = 0; i < tsresol_opt; i++)
  ------------------
  |  Branch (559:17): [True: 24.7k, False: 5.24k]
  ------------------
  560|  24.7k|					*tsresol *= 10;
  561|  5.24k|			}
  562|  6.12k|			break;
  563|       |
  564|  6.12k|		case IF_TSOFFSET:
  ------------------
  |  |  136|    418|#define IF_TSOFFSET	14	/* time stamp offset for this interface */
  ------------------
  |  Branch (564:3): [True: 418, False: 13.0k]
  ------------------
  565|    418|			if (opthdr->option_length != 8) {
  ------------------
  |  Branch (565:8): [True: 13, False: 405]
  ------------------
  566|     13|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     13|#define PCAP_ERRBUF_SIZE 256
  ------------------
  567|     13|				    "Interface Description Block has if_tsoffset option with length %u != 8",
  568|     13|				    opthdr->option_length);
  569|     13|				return (-1);
  570|     13|			}
  571|    405|			if (saw_tsoffset) {
  ------------------
  |  Branch (571:8): [True: 2, False: 403]
  ------------------
  572|      2|				snprintf(errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      2|#define PCAP_ERRBUF_SIZE 256
  ------------------
  573|      2|				    "Interface Description Block has more than one if_tsoffset option");
  574|      2|				return (-1);
  575|      2|			}
  576|    403|			saw_tsoffset = 1;
  577|    403|			memcpy(tsoffset, optvalue, sizeof(*tsoffset));
  578|    403|			if (p->swapped)
  ------------------
  |  Branch (578:8): [True: 204, False: 199]
  ------------------
  579|    204|				*tsoffset = PCAP_BSWAP_64(*tsoffset);
  ------------------
  |  |   64|    204|#define PCAP_BSWAP_64(y) __builtin_bswap64((uint64_t)(y))
  ------------------
  580|    403|			break;
  581|       |
  582|  6.23k|		default:
  ------------------
  |  Branch (582:3): [True: 6.23k, False: 7.20k]
  ------------------
  583|  6.23k|			break;
  584|  13.4k|		}
  585|  13.4k|	}
  586|       |
  587|  12.1k|done:
  588|  12.1k|	return (0);
  589|  12.2k|}
sf-pcapng.c:get_opthdr_from_block_data:
  416|  13.4k|{
  417|  13.4k|	struct option_header *opthdr;
  418|       |
  419|  13.4k|	opthdr = get_from_block_data(cursor, sizeof(*opthdr), errbuf);
  420|  13.4k|	if (opthdr == NULL) {
  ------------------
  |  Branch (420:6): [True: 0, False: 13.4k]
  ------------------
  421|       |		/*
  422|       |		 * Option header is cut short.
  423|       |		 */
  424|      0|		return (NULL);
  425|      0|	}
  426|       |
  427|       |	/*
  428|       |	 * Byte-swap it if necessary.
  429|       |	 */
  430|  13.4k|	if (p->swapped) {
  ------------------
  |  Branch (430:6): [True: 9.24k, False: 4.22k]
  ------------------
  431|  9.24k|		opthdr->option_code = PCAP_BSWAP_16(opthdr->option_code);
  ------------------
  |  |   88|  9.24k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  432|  9.24k|		opthdr->option_length = PCAP_BSWAP_16(opthdr->option_length);
  ------------------
  |  |   88|  9.24k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
  433|  9.24k|	}
  434|       |
  435|  13.4k|	return (opthdr);
  436|  13.4k|}
sf-pcapng.c:get_optvalue_from_block_data:
  441|  13.4k|{
  442|  13.4k|	size_t padded_option_len;
  443|  13.4k|	void *optvalue;
  444|       |
  445|       |	/* Pad option length to 4-byte boundary */
  446|  13.4k|	padded_option_len = opthdr->option_length;
  447|  13.4k|	padded_option_len = ((padded_option_len + 3)/4)*4;
  448|       |
  449|  13.4k|	optvalue = get_from_block_data(cursor, padded_option_len, errbuf);
  450|  13.4k|	if (optvalue == NULL) {
  ------------------
  |  Branch (450:6): [True: 32, False: 13.4k]
  ------------------
  451|       |		/*
  452|       |		 * Option value is cut short.
  453|       |		 */
  454|     32|		return (NULL);
  455|     32|	}
  456|       |
  457|  13.4k|	return (optvalue);
  458|  13.4k|}
sf-pcapng.c:pcap_ng_cleanup:
 1088|    854|{
 1089|    854|	struct pcap_ng_sf *ps = p->priv;
 1090|       |
 1091|    854|	free(ps->ifaces);
 1092|    854|	pcapint_sf_cleanup(p);
 1093|    854|}
sf-pcapng.c:pcap_ng_next_packet:
 1102|  2.99k|{
 1103|  2.99k|	struct pcap_ng_sf *ps = p->priv;
 1104|  2.99k|	struct block_cursor cursor;
 1105|  2.99k|	int status;
 1106|  2.99k|	struct enhanced_packet_block *epbp;
 1107|  2.99k|	struct simple_packet_block *spbp;
 1108|  2.99k|	struct packet_block *pbp;
 1109|  2.99k|	bpf_u_int32 interface_id = 0xFFFFFFFF;
 1110|  2.99k|	struct interface_description_block *idbp;
 1111|  2.99k|	struct section_header_block *shbp;
 1112|  2.99k|	FILE *fp = p->rfile;
 1113|  2.99k|	uint64_t t, sec, frac;
 1114|       |
 1115|       |	/*
 1116|       |	 * Look for an Enhanced Packet Block, a Simple Packet Block,
 1117|       |	 * or a Packet Block.
 1118|       |	 */
 1119|  15.2k|	for (;;) {
 1120|       |		/*
 1121|       |		 * Read the block type and length; those are common
 1122|       |		 * to all blocks.
 1123|       |		 */
 1124|  15.2k|		status = read_block(fp, p, &cursor, p->errbuf);
 1125|  15.2k|		if (status == 0)
  ------------------
  |  Branch (1125:7): [True: 330, False: 14.9k]
  ------------------
 1126|    330|			return (0);	/* EOF */
 1127|  14.9k|		if (status == -1)
  ------------------
  |  Branch (1127:7): [True: 82, False: 14.8k]
  ------------------
 1128|     82|			return (-1);	/* error */
 1129|  14.8k|		switch (cursor.block_type) {
 1130|       |
 1131|    448|		case BT_EPB:
  ------------------
  |  |  141|    448|#define BT_EPB			0x00000006
  ------------------
  |  Branch (1131:3): [True: 448, False: 14.3k]
  ------------------
 1132|       |			/*
 1133|       |			 * Get a pointer to the fixed-length portion of the
 1134|       |			 * EPB.
 1135|       |			 */
 1136|    448|			epbp = get_from_block_data(&cursor, sizeof(*epbp),
 1137|    448|			    p->errbuf);
 1138|    448|			if (epbp == NULL)
  ------------------
  |  Branch (1138:8): [True: 4, False: 444]
  ------------------
 1139|      4|				return (-1);	/* error */
 1140|       |
 1141|       |			/*
 1142|       |			 * Byte-swap it if necessary.
 1143|       |			 */
 1144|    444|			if (p->swapped) {
  ------------------
  |  Branch (1144:8): [True: 223, False: 221]
  ------------------
 1145|       |				/* these were written in opposite byte order */
 1146|    223|				interface_id = PCAP_BSWAP_32(epbp->interface_id);
  ------------------
  |  |   78|    223|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1147|    223|				hdr->caplen = PCAP_BSWAP_32(epbp->caplen);
  ------------------
  |  |   78|    223|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1148|    223|				hdr->len = PCAP_BSWAP_32(epbp->len);
  ------------------
  |  |   78|    223|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1149|    223|				t = ((uint64_t)PCAP_BSWAP_32(epbp->timestamp_high)) << 32 |
  ------------------
  |  |   78|    223|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1150|    223|				    PCAP_BSWAP_32(epbp->timestamp_low);
  ------------------
  |  |   78|    223|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1151|    223|			} else {
 1152|    221|				interface_id = epbp->interface_id;
 1153|    221|				hdr->caplen = epbp->caplen;
 1154|    221|				hdr->len = epbp->len;
 1155|    221|				t = ((uint64_t)epbp->timestamp_high) << 32 |
 1156|    221|				    epbp->timestamp_low;
 1157|    221|			}
 1158|    444|			goto found;
 1159|       |
 1160|  1.36k|		case BT_SPB:
  ------------------
  |  |  155|  1.36k|#define BT_SPB			0x00000003
  ------------------
  |  Branch (1160:3): [True: 1.36k, False: 13.4k]
  ------------------
 1161|       |			/*
 1162|       |			 * Get a pointer to the fixed-length portion of the
 1163|       |			 * SPB.
 1164|       |			 */
 1165|  1.36k|			spbp = get_from_block_data(&cursor, sizeof(*spbp),
 1166|  1.36k|			    p->errbuf);
 1167|  1.36k|			if (spbp == NULL)
  ------------------
  |  Branch (1167:8): [True: 2, False: 1.36k]
  ------------------
 1168|      2|				return (-1);	/* error */
 1169|       |
 1170|       |			/*
 1171|       |			 * SPB packets are assumed to have arrived on
 1172|       |			 * the first interface.
 1173|       |			 */
 1174|  1.36k|			interface_id = 0;
 1175|       |
 1176|       |			/*
 1177|       |			 * Byte-swap it if necessary.
 1178|       |			 */
 1179|  1.36k|			if (p->swapped) {
  ------------------
  |  Branch (1179:8): [True: 677, False: 688]
  ------------------
 1180|       |				/* these were written in opposite byte order */
 1181|    677|				hdr->len = PCAP_BSWAP_32(spbp->len);
  ------------------
  |  |   78|    677|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1182|    677|			} else
 1183|    688|				hdr->len = spbp->len;
 1184|       |
 1185|       |			/*
 1186|       |			 * The SPB doesn't give the captured length;
 1187|       |			 * it's the minimum of the snapshot length
 1188|       |			 * and the packet length.
 1189|       |			 */
 1190|  1.36k|			hdr->caplen = hdr->len;
 1191|  1.36k|			if (hdr->caplen > (bpf_u_int32)p->snapshot)
  ------------------
  |  Branch (1191:8): [True: 651, False: 714]
  ------------------
 1192|    651|				hdr->caplen = p->snapshot;
 1193|  1.36k|			t = 0;	/* no time stamps */
 1194|  1.36k|			goto found;
 1195|       |
 1196|    505|		case BT_PB:
  ------------------
  |  |  165|    505|#define BT_PB			0x00000002
  ------------------
  |  Branch (1196:3): [True: 505, False: 14.3k]
  ------------------
 1197|       |			/*
 1198|       |			 * Get a pointer to the fixed-length portion of the
 1199|       |			 * PB.
 1200|       |			 */
 1201|    505|			pbp = get_from_block_data(&cursor, sizeof(*pbp),
 1202|    505|			    p->errbuf);
 1203|    505|			if (pbp == NULL)
  ------------------
  |  Branch (1203:8): [True: 4, False: 501]
  ------------------
 1204|      4|				return (-1);	/* error */
 1205|       |
 1206|       |			/*
 1207|       |			 * Byte-swap it if necessary.
 1208|       |			 */
 1209|    501|			if (p->swapped) {
  ------------------
  |  Branch (1209:8): [True: 207, False: 294]
  ------------------
 1210|       |				/* these were written in opposite byte order */
 1211|    207|				interface_id = PCAP_BSWAP_16(pbp->interface_id);
  ------------------
  |  |   88|    207|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
 1212|    207|				hdr->caplen = PCAP_BSWAP_32(pbp->caplen);
  ------------------
  |  |   78|    207|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1213|    207|				hdr->len = PCAP_BSWAP_32(pbp->len);
  ------------------
  |  |   78|    207|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1214|    207|				t = ((uint64_t)PCAP_BSWAP_32(pbp->timestamp_high)) << 32 |
  ------------------
  |  |   78|    207|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1215|    207|				    PCAP_BSWAP_32(pbp->timestamp_low);
  ------------------
  |  |   78|    207|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1216|    294|			} else {
 1217|    294|				interface_id = pbp->interface_id;
 1218|    294|				hdr->caplen = pbp->caplen;
 1219|    294|				hdr->len = pbp->len;
 1220|    294|				t = ((uint64_t)pbp->timestamp_high) << 32 |
 1221|    294|				    pbp->timestamp_low;
 1222|    294|			}
 1223|    501|			goto found;
 1224|       |
 1225|  11.3k|		case BT_IDB:
  ------------------
  |  |  112|  11.3k|#define BT_IDB			0x00000001
  ------------------
  |  Branch (1225:3): [True: 11.3k, False: 3.48k]
  ------------------
 1226|       |			/*
 1227|       |			 * Interface Description Block.  Get a pointer
 1228|       |			 * to its fixed-length portion.
 1229|       |			 */
 1230|  11.3k|			idbp = get_from_block_data(&cursor, sizeof(*idbp),
 1231|  11.3k|			    p->errbuf);
 1232|  11.3k|			if (idbp == NULL)
  ------------------
  |  Branch (1232:8): [True: 2, False: 11.3k]
  ------------------
 1233|      2|				return (-1);	/* error */
 1234|       |
 1235|       |			/*
 1236|       |			 * Byte-swap it if necessary.
 1237|       |			 */
 1238|  11.3k|			if (p->swapped) {
  ------------------
  |  Branch (1238:8): [True: 4.89k, False: 6.45k]
  ------------------
 1239|  4.89k|				idbp->linktype = PCAP_BSWAP_16(idbp->linktype);
  ------------------
  |  |   88|  4.89k|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
 1240|  4.89k|				idbp->snaplen = PCAP_BSWAP_32(idbp->snaplen);
  ------------------
  |  |   78|  4.89k|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1241|  4.89k|			}
 1242|       |
 1243|       |			/*
 1244|       |			 * If the link-layer type or snapshot length
 1245|       |			 * differ from the ones for the first IDB we
 1246|       |			 * saw, quit.
 1247|       |			 *
 1248|       |			 * XXX - just discard packets from those
 1249|       |			 * interfaces?
 1250|       |			 */
 1251|  11.3k|			if (p->linktype != idbp->linktype) {
  ------------------
  |  Branch (1251:8): [True: 10, False: 11.3k]
  ------------------
 1252|     10|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     10|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1253|     10|				    "an interface has a type %u different from the type of the first interface",
 1254|     10|				    idbp->linktype);
 1255|     10|				return (-1);
 1256|     10|			}
 1257|       |
 1258|       |			/*
 1259|       |			 * Check against the *adjusted* value of this IDB's
 1260|       |			 * snapshot length.
 1261|       |			 */
 1262|  11.3k|			if ((bpf_u_int32)p->snapshot !=
  ------------------
  |  Branch (1262:8): [True: 54, False: 11.2k]
  ------------------
 1263|  11.3k|			    pcapint_adjust_snapshot(p->linktype, idbp->snaplen)) {
 1264|     54|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     54|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1265|     54|				    "an interface has a snapshot length %u different from the snapshot length of the first interface",
 1266|     54|				    idbp->snaplen);
 1267|     54|				return (-1);
 1268|     54|			}
 1269|       |
 1270|       |			/*
 1271|       |			 * Try to add this interface.
 1272|       |			 */
 1273|  11.2k|			if (!add_interface(p, idbp, &cursor, p->errbuf))
  ------------------
  |  Branch (1273:8): [True: 6, False: 11.2k]
  ------------------
 1274|      6|				return (-1);
 1275|  11.2k|			break;
 1276|       |
 1277|  11.2k|		case BT_SHB:
  ------------------
  |  |   86|    583|#define BT_SHB			0x0A0D0D0A
  ------------------
  |  Branch (1277:3): [True: 583, False: 14.2k]
  ------------------
 1278|       |			/*
 1279|       |			 * Section Header Block.  Get a pointer
 1280|       |			 * to its fixed-length portion.
 1281|       |			 */
 1282|    583|			shbp = get_from_block_data(&cursor, sizeof(*shbp),
 1283|    583|			    p->errbuf);
 1284|    583|			if (shbp == NULL)
  ------------------
  |  Branch (1284:8): [True: 3, False: 580]
  ------------------
 1285|      3|				return (-1);	/* error */
 1286|       |
 1287|       |			/*
 1288|       |			 * Assume the byte order of this section is
 1289|       |			 * the same as that of the previous section.
 1290|       |			 * We'll check for that later.
 1291|       |			 */
 1292|    580|			if (p->swapped) {
  ------------------
  |  Branch (1292:8): [True: 201, False: 379]
  ------------------
 1293|    201|				shbp->byte_order_magic =
 1294|    201|				    PCAP_BSWAP_32(shbp->byte_order_magic);
  ------------------
  |  |   78|    201|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
 1295|    201|				shbp->major_version =
 1296|    201|				    PCAP_BSWAP_16(shbp->major_version);
  ------------------
  |  |   88|    201|#define PCAP_BSWAP_16(y) __builtin_bswap16((uint16_t)(y))
  ------------------
 1297|    201|			}
 1298|       |
 1299|       |			/*
 1300|       |			 * Make sure the byte order doesn't change;
 1301|       |			 * pcap_is_swapped() shouldn't change its
 1302|       |			 * return value in the middle of reading a capture.
 1303|       |			 */
 1304|    580|			switch (shbp->byte_order_magic) {
 1305|       |
 1306|    406|			case BYTE_ORDER_MAGIC:
  ------------------
  |  |   99|    406|#define BYTE_ORDER_MAGIC	0x1A2B3C4D
  ------------------
  |  Branch (1306:4): [True: 406, False: 174]
  ------------------
 1307|       |				/*
 1308|       |				 * OK.
 1309|       |				 */
 1310|    406|				break;
 1311|       |
 1312|      1|			case PCAP_BSWAP_32(BYTE_ORDER_MAGIC):
  ------------------
  |  |   78|      1|#define PCAP_BSWAP_32(y) __builtin_bswap32((uint32_t)(y))
  ------------------
  |  Branch (1312:4): [True: 1, False: 579]
  ------------------
 1313|       |				/*
 1314|       |				 * Byte order changes.
 1315|       |				 */
 1316|      1|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|      1|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1317|      1|				    "the file has sections with different byte orders");
 1318|      1|				return (-1);
 1319|       |
 1320|    173|			default:
  ------------------
  |  Branch (1320:4): [True: 173, False: 407]
  ------------------
 1321|       |				/*
 1322|       |				 * Not a valid SHB.
 1323|       |				 */
 1324|    173|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|    173|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1325|    173|				    "the file has a section with a bad byte order magic field");
 1326|    173|				return (-1);
 1327|    580|			}
 1328|       |
 1329|       |			/*
 1330|       |			 * Make sure the major version is the version
 1331|       |			 * we handle.
 1332|       |			 */
 1333|    406|			if (shbp->major_version != PCAP_NG_VERSION_MAJOR) {
  ------------------
  |  |  106|    406|#define PCAP_NG_VERSION_MAJOR	1
  ------------------
  |  Branch (1333:8): [True: 17, False: 389]
  ------------------
 1334|     17|				snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     17|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1335|     17|				    "unknown pcapng savefile major version number %u",
 1336|     17|				    shbp->major_version);
 1337|     17|				return (-1);
 1338|     17|			}
 1339|       |
 1340|       |			/*
 1341|       |			 * Reset the interface count; this section should
 1342|       |			 * have its own set of IDBs.  If any of them
 1343|       |			 * don't have the same interface type, snapshot
 1344|       |			 * length, or resolution as the first interface
 1345|       |			 * we saw, we'll fail.  (And if we don't see
 1346|       |			 * any IDBs, we'll fail when we see a packet
 1347|       |			 * block.)
 1348|       |			 */
 1349|    389|			ps->ifcount = 0;
 1350|    389|			break;
 1351|       |
 1352|    580|		default:
  ------------------
  |  Branch (1352:3): [True: 580, False: 14.2k]
  ------------------
 1353|       |			/*
 1354|       |			 * Not a packet block, IDB, or SHB; ignore it.
 1355|       |			 */
 1356|    580|			break;
 1357|  14.8k|		}
 1358|  14.8k|	}
 1359|       |
 1360|  2.31k|found:
 1361|       |	/*
 1362|       |	 * Is the interface ID an interface we know?
 1363|       |	 */
 1364|  2.31k|	if (interface_id >= ps->ifcount) {
  ------------------
  |  Branch (1364:6): [True: 58, False: 2.25k]
  ------------------
 1365|       |		/*
 1366|       |		 * Yes.  Fail.
 1367|       |		 */
 1368|     58|		snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     58|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1369|     58|		    "a packet arrived on interface %u, but there's no Interface Description Block for that interface",
 1370|     58|		    interface_id);
 1371|     58|		return (-1);
 1372|     58|	}
 1373|       |
 1374|  2.25k|	if (hdr->caplen > (bpf_u_int32)p->snapshot) {
  ------------------
  |  Branch (1374:6): [True: 32, False: 2.22k]
  ------------------
 1375|     32|		snprintf(p->errbuf, PCAP_ERRBUF_SIZE,
  ------------------
  |  |  149|     32|#define PCAP_ERRBUF_SIZE 256
  ------------------
 1376|     32|		    "invalid packet capture length %u, bigger than "
 1377|     32|		    "snaplen of %d", hdr->caplen, p->snapshot);
 1378|     32|		return (-1);
 1379|     32|	}
 1380|       |
 1381|       |	/*
 1382|       |	 * Convert the time stamp to seconds and fractions of a second,
 1383|       |	 * with the fractions being in units of the file-supplied resolution.
 1384|       |	 */
 1385|  2.22k|	sec = t / ps->ifaces[interface_id].tsresol + ps->ifaces[interface_id].tsoffset;
 1386|  2.22k|	frac = t % ps->ifaces[interface_id].tsresol;
 1387|       |
 1388|       |	/*
 1389|       |	 * Convert the fractions from units of the file-supplied resolution
 1390|       |	 * to units of the user-requested resolution.
 1391|       |	 */
 1392|  2.22k|	switch (ps->ifaces[interface_id].scale_type) {
  ------------------
  |  Branch (1392:10): [True: 2.22k, False: 0]
  ------------------
 1393|       |
 1394|  1.07k|	case PASS_THROUGH:
  ------------------
  |  Branch (1394:2): [True: 1.07k, False: 1.14k]
  ------------------
 1395|       |		/*
 1396|       |		 * The interface resolution is what the user wants,
 1397|       |		 * so we're done.
 1398|       |		 */
 1399|  1.07k|		break;
 1400|       |
 1401|    364|	case SCALE_UP_DEC:
  ------------------
  |  Branch (1401:2): [True: 364, False: 1.85k]
  ------------------
 1402|       |		/*
 1403|       |		 * The interface resolution is less than what the user
 1404|       |		 * wants; scale the fractional part up to the units of
 1405|       |		 * the resolution the user requested by multiplying by
 1406|       |		 * the quotient of the user-requested resolution and the
 1407|       |		 * file-supplied resolution.
 1408|       |		 *
 1409|       |		 * Those resolutions are both powers of 10, and the user-
 1410|       |		 * requested resolution is greater than the file-supplied
 1411|       |		 * resolution, so the quotient in question is an integer.
 1412|       |		 * We've calculated that quotient already, so we just
 1413|       |		 * multiply by it.
 1414|       |		 */
 1415|    364|		frac *= ps->ifaces[interface_id].scale_factor;
 1416|    364|		break;
 1417|       |
 1418|    248|	case SCALE_UP_BIN:
  ------------------
  |  Branch (1418:2): [True: 248, False: 1.97k]
  ------------------
 1419|       |		/*
 1420|       |		 * The interface resolution is less than what the user
 1421|       |		 * wants; scale the fractional part up to the units of
 1422|       |		 * the resolution the user requested by multiplying by
 1423|       |		 * the quotient of the user-requested resolution and the
 1424|       |		 * file-supplied resolution.
 1425|       |		 *
 1426|       |		 * The file-supplied resolution is a power of 2, so the
 1427|       |		 * quotient is not an integer, so, in order to do this
 1428|       |		 * entirely with integer arithmetic, we multiply by the
 1429|       |		 * user-requested resolution and divide by the file-
 1430|       |		 * supplied resolution.
 1431|       |		 *
 1432|       |		 * XXX - Is there something clever we could do here,
 1433|       |		 * given that we know that the file-supplied resolution
 1434|       |		 * is a power of 2?  Doing a multiplication followed by
 1435|       |		 * a division runs the risk of overflowing, and involves
 1436|       |		 * two non-simple arithmetic operations.
 1437|       |		 */
 1438|    248|		frac *= ps->user_tsresol;
 1439|    248|		frac /= ps->ifaces[interface_id].tsresol;
 1440|    248|		break;
 1441|       |
 1442|    194|	case SCALE_DOWN_DEC:
  ------------------
  |  Branch (1442:2): [True: 194, False: 2.02k]
  ------------------
 1443|       |		/*
 1444|       |		 * The interface resolution is greater than what the user
 1445|       |		 * wants; scale the fractional part up to the units of
 1446|       |		 * the resolution the user requested by multiplying by
 1447|       |		 * the quotient of the user-requested resolution and the
 1448|       |		 * file-supplied resolution.
 1449|       |		 *
 1450|       |		 * Those resolutions are both powers of 10, and the user-
 1451|       |		 * requested resolution is less than the file-supplied
 1452|       |		 * resolution, so the quotient in question isn't an
 1453|       |		 * integer, but its reciprocal is, and we can just divide
 1454|       |		 * by the reciprocal of the quotient.  We've calculated
 1455|       |		 * the reciprocal of that quotient already, so we must
 1456|       |		 * divide by it.
 1457|       |		 */
 1458|    194|		frac /= ps->ifaces[interface_id].scale_factor;
 1459|    194|		break;
 1460|       |
 1461|       |
 1462|    343|	case SCALE_DOWN_BIN:
  ------------------
  |  Branch (1462:2): [True: 343, False: 1.87k]
  ------------------
 1463|       |		/*
 1464|       |		 * The interface resolution is greater than what the user
 1465|       |		 * wants; convert the fractional part to units of the
 1466|       |		 * resolution the user requested by multiplying by the
 1467|       |		 * quotient of the user-requested resolution and the
 1468|       |		 * file-supplied resolution.  We do that by multiplying
 1469|       |		 * by the user-requested resolution and dividing by the
 1470|       |		 * file-supplied resolution, as the quotient might not
 1471|       |		 * fit in an integer.
 1472|       |		 *
 1473|       |		 * The file-supplied resolution is a power of 2, so the
 1474|       |		 * quotient is not an integer, and neither is its
 1475|       |		 * reciprocal, so, in order to do this entirely with
 1476|       |		 * integer arithmetic, we multiply by the user-requested
 1477|       |		 * resolution and divide by the file-supplied resolution.
 1478|       |		 *
 1479|       |		 * XXX - Is there something clever we could do here,
 1480|       |		 * given that we know that the file-supplied resolution
 1481|       |		 * is a power of 2?  Doing a multiplication followed by
 1482|       |		 * a division runs the risk of overflowing, and involves
 1483|       |		 * two non-simple arithmetic operations.
 1484|       |		 */
 1485|    343|		frac *= ps->user_tsresol;
 1486|    343|		frac /= ps->ifaces[interface_id].tsresol;
 1487|    343|		break;
 1488|  2.22k|	}
 1489|       |#ifdef _WIN32
 1490|       |	/*
 1491|       |	 * tv_sec and tv_usec in the Windows struct timeval are both
 1492|       |	 * longs.
 1493|       |	 */
 1494|       |	hdr->ts.tv_sec = (long)sec;
 1495|       |	hdr->ts.tv_usec = (long)frac;
 1496|       |#else
 1497|       |	/*
 1498|       |	 * tv_sec in the UN*X struct timeval is a time_t; tv_usec is
 1499|       |	 * suseconds_t in UN*Xes that work the way the current Single
 1500|       |	 * UNIX Standard specify - but not all older UN*Xes necessarily
 1501|       |	 * support that type, so just cast to int.
 1502|       |	 */
 1503|  2.22k|	hdr->ts.tv_sec = (time_t)sec;
 1504|  2.22k|	hdr->ts.tv_usec = (int)frac;
 1505|  2.22k|#endif
 1506|       |
 1507|       |	/*
 1508|       |	 * Get a pointer to the packet data.
 1509|       |	 */
 1510|  2.22k|	*data = get_from_block_data(&cursor, hdr->caplen, p->errbuf);
 1511|  2.22k|	if (*data == NULL)
  ------------------
  |  Branch (1511:6): [True: 76, False: 2.14k]
  ------------------
 1512|     76|		return (-1);
 1513|       |
 1514|  2.14k|	pcapint_post_process(p->linktype, p->swapped, hdr, *data);
 1515|       |
 1516|  2.14k|	return (1);
 1517|  2.22k|}

parse_mpls:
   89|  2.74k|{
   90|  2.74k|    const u_char *mpls_label; /* byte cursor, not a struct pointer - see below */
   91|  2.74k|    const u_char *end_ptr = pktdata + datalen;
   92|  2.74k|    u_char first_nibble;
   93|  2.74k|    eth_hdr_t *eth_hdr;
   94|  2.74k|    bool bos = false;
   95|  2.74k|    uint32_t label;
   96|  2.74k|    int len;
   97|       |
   98|  2.74k|    assert(next_protocol);
  ------------------
  |  Branch (98:5): [True: 0, False: 2.74k]
  |  Branch (98:5): [True: 2.74k, False: 0]
  ------------------
   99|  2.74k|    assert(l2len);
  ------------------
  |  Branch (99:5): [True: 0, False: 2.74k]
  |  Branch (99:5): [True: 2.74k, False: 0]
  ------------------
  100|  2.74k|    assert(l2offset);
  ------------------
  |  Branch (100:5): [True: 0, False: 2.74k]
  |  Branch (100:5): [True: 2.74k, False: 0]
  ------------------
  101|       |
  102|  2.74k|    len = (int)*l2len;
  103|       |
  104|       |    /*
  105|       |     * An MPLS label is four bytes at whatever offset the encapsulation puts
  106|       |     * it, which is not guaranteed to be 4-byte aligned. Casting that to a
  107|       |     * struct tcpr_mpls_label and reading ->entry is undefined behaviour, and
  108|       |     * UBSan says so:
  109|       |     *
  110|       |     *   get.c:115: member access within misaligned address ... for type
  111|       |     *   'struct tcpr_mpls_label', which requires 4 byte alignment
  112|       |     *
  113|       |     * x86 does not care, which is why this went unnoticed - but docs/INSTALL
  114|       |     * lists Solaris and the BSDs, where a misaligned load faults or is fixed
  115|       |     * up in the trap handler (#1100). Copy the four bytes out instead, and
  116|       |     * keep the cursor as a plain byte pointer so no misaligned struct pointer
  117|       |     * is ever formed.
  118|       |     */
  119|  46.4k|    while (!bos) {
  ------------------
  |  Branch (119:12): [True: 44.4k, False: 1.97k]
  ------------------
  120|  44.4k|        uint32_t entry;
  121|       |
  122|  44.4k|        if (pktdata + len + sizeof(entry) > end_ptr) {
  ------------------
  |  Branch (122:13): [True: 469, False: 43.9k]
  ------------------
  123|    469|            warnx("parse_mpls: Need at least %zu bytes for MPLS header but only %u available",
  ------------------
  |  |  123|    469|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  124|    469|                  sizeof(entry) + len,
  125|    469|                  datalen);
  126|    469|            return -1;
  127|    469|        }
  128|       |
  129|  43.9k|        mpls_label = pktdata + len;
  130|  43.9k|        memcpy(&entry, mpls_label, sizeof(entry));
  131|  43.9k|        len += sizeof(entry);
  132|       |
  133|  43.9k|        entry = ntohl(entry);
  134|  43.9k|        bos = (entry & MPLS_LS_S_MASK) != 0;
  ------------------
  |  | 1701|  43.9k|#define MPLS_LS_S_MASK 0x00000100
  ------------------
  135|  43.9k|        label = entry >> MPLS_LS_LABEL_SHIFT;
  ------------------
  |  | 1692|  43.9k|#define MPLS_LS_LABEL_SHIFT 12
  ------------------
  136|  43.9k|        if (label == MPLS_LABEL_GACH) {
  ------------------
  |  | 1685|  43.9k|#define MPLS_LABEL_GACH 13
  ------------------
  |  Branch (136:13): [True: 292, False: 43.6k]
  ------------------
  137|       |            /* Generic Associated Channel Header */
  138|    292|            warn("GACH MPLS label not supported at this time");
  ------------------
  |  |  121|    292|#define warn(x) fprintf(stderr, "Warning: %s\n", x)
  ------------------
  139|    292|            return -1;
  140|    292|        }
  141|  43.9k|    }
  142|       |
  143|       |    /* mpls_label is now a byte cursor, so step past the 4-byte label directly */
  144|  1.97k|    if (mpls_label + sizeof(uint32_t) + 1 > end_ptr) {
  ------------------
  |  Branch (144:9): [True: 198, False: 1.78k]
  ------------------
  145|    198|        warnx("parse_mpls: Need at least %zu bytes for MPLS label but only %u available",
  ------------------
  |  |  123|    198|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  146|    198|              sizeof(uint32_t) + 1,
  147|    198|              datalen);
  148|    198|        return -1;
  149|    198|    }
  150|       |
  151|  1.78k|    first_nibble = *(mpls_label + sizeof(uint32_t)) >> 4;
  152|  1.78k|    switch (first_nibble) {
  153|    336|    case 4:
  ------------------
  |  Branch (153:5): [True: 336, False: 1.44k]
  ------------------
  154|    336|        *next_protocol = ETHERTYPE_IP;
  155|    336|        break;
  156|    346|    case 6:
  ------------------
  |  Branch (156:5): [True: 346, False: 1.43k]
  ------------------
  157|    346|        *next_protocol = ETHERTYPE_IP6;
  ------------------
  |  |  534|    346|#define ETHERTYPE_IP6 0x86DD /* IPv6 */
  ------------------
  158|    346|        break;
  159|    853|    case 0:
  ------------------
  |  Branch (159:5): [True: 853, False: 928]
  ------------------
  160|       |        /* EoMPLS - jump over PW Ethernet Control Word and handle
  161|       |         * inner Ethernet header
  162|       |         */
  163|    853|        if (pktdata + len + 4 + sizeof(*eth_hdr) > end_ptr) {
  ------------------
  |  Branch (163:13): [True: 254, False: 599]
  ------------------
  164|    254|            warnx("parse_mpls: Need at least %zu bytes for EoMPLS header but only %u available",
  ------------------
  |  |  123|    254|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  165|    254|                  sizeof(*eth_hdr) + len + 4,
  166|    254|                  datalen);
  167|    254|            return -1;
  168|    254|        }
  169|       |
  170|    599|        len += 4;
  171|    599|        *l2offset = len;
  172|    599|        eth_hdr = (eth_hdr_t *)(pktdata + len);
  173|    599|        len += sizeof(*eth_hdr);
  174|    599|        *next_protocol = ntohs(eth_hdr->ether_type);
  175|    599|        break;
  176|    246|    default:
  ------------------
  |  Branch (176:5): [True: 246, False: 1.53k]
  ------------------
  177|    246|        warn("parse_mpls:suspect Generic Associated Channel Header");
  ------------------
  |  |  121|    246|#define warn(x) fprintf(stderr, "Warning: %s\n", x)
  ------------------
  178|    246|        return -1;
  179|  1.78k|    }
  180|       |
  181|  1.28k|    *l2len = (uint32_t)len;
  182|  1.28k|    return 0;
  183|  1.78k|}
parse_vlan:
  198|  1.74k|{
  199|  1.74k|    vlan_hdr_t *vlan_hdr;
  200|  1.74k|    if ((size_t)datalen < *l2len + sizeof(*vlan_hdr)) {
  ------------------
  |  Branch (200:9): [True: 390, False: 1.35k]
  ------------------
  201|    390|        warnx("parse_vlan: Need at least %zu bytes for VLAN header but only %u available", sizeof(*vlan_hdr), datalen);
  ------------------
  |  |  123|    390|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  202|    390|        return -1;
  203|    390|    }
  204|  1.35k|    vlan_hdr = (vlan_hdr_t *)(pktdata + *l2len);
  205|  1.35k|    *next_protocol = ntohs(vlan_hdr->vlan_tpid);
  206|  1.35k|    *l2len += sizeof(vlan_hdr_t);
  207|       |
  208|  1.35k|    return 0;
  209|  1.74k|}
get_l2len_protocol:
  290|  32.4k|{
  291|  32.4k|    assert(protocol);
  ------------------
  |  Branch (291:5): [True: 0, False: 32.4k]
  |  Branch (291:5): [True: 32.4k, False: 0]
  ------------------
  292|  32.4k|    assert(l2len);
  ------------------
  |  Branch (292:5): [True: 0, False: 32.4k]
  |  Branch (292:5): [True: 32.4k, False: 0]
  ------------------
  293|  32.4k|    assert(l2offset);
  ------------------
  |  Branch (293:5): [True: 0, False: 32.4k]
  |  Branch (293:5): [True: 32.4k, False: 0]
  ------------------
  294|  32.4k|    assert(vlan_offset);
  ------------------
  |  Branch (294:5): [True: 0, False: 32.4k]
  |  Branch (294:5): [True: 32.4k, False: 0]
  ------------------
  295|       |
  296|  32.4k|    if (!pktdata || !datalen) {
  ------------------
  |  Branch (296:9): [True: 0, False: 32.4k]
  |  Branch (296:21): [True: 0, False: 32.4k]
  ------------------
  297|      0|        err_no_exitx("get_l2len_protocol: invalid L2 parameters: pktdata=0x%p len=%d", pktdata, datalen);
  ------------------
  |  |  142|      0|#define err_no_exitx(y, ...) do {\
  |  |  143|      0|        fprintf(stderr, "\nFatal Error: " y "\n", __VA_ARGS__); \
  |  |  144|      0|        fflush(NULL); \
  |  |  145|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (145:14): [Folded, False: 0]
  |  |  ------------------
  ------------------
  298|      0|        return -1;
  299|      0|    }
  300|       |
  301|  32.4k|    *protocol = 0;
  302|  32.4k|    *l2len = 0;
  303|  32.4k|    *l2offset = 0;
  304|  32.4k|    *vlan_offset = 0;
  305|       |
  306|  32.4k|    switch (datalink) {
  307|  5.52k|    case DLT_NULL:
  ------------------
  |  Branch (307:5): [True: 5.52k, False: 26.8k]
  ------------------
  308|  6.76k|    case DLT_RAW:
  ------------------
  |  Branch (308:5): [True: 1.24k, False: 31.1k]
  ------------------
  309|  6.76k|        if ((pktdata[0] >> 4) == 4)
  ------------------
  |  Branch (309:13): [True: 560, False: 6.20k]
  ------------------
  310|    560|            *protocol = ETHERTYPE_IP;
  311|  6.20k|        else if ((pktdata[0] >> 4) == 6)
  ------------------
  |  Branch (311:18): [True: 5.51k, False: 691]
  ------------------
  312|  5.51k|            *protocol = ETHERTYPE_IP6;
  ------------------
  |  |  534|  5.51k|#define ETHERTYPE_IP6 0x86DD /* IPv6 */
  ------------------
  313|  6.76k|        break;
  314|  1.95k|    case DLT_JUNIPER_ETHER:
  ------------------
  |  Branch (314:5): [True: 1.95k, False: 30.4k]
  ------------------
  315|  1.95k|        if (datalen < 4) {
  ------------------
  |  Branch (315:13): [True: 196, False: 1.76k]
  ------------------
  316|    196|            warnx("%s (0x%x): Need at least 4 bytes for DLT_JUNIPER_ETHER but only %u available",
  ------------------
  |  |  123|    196|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  317|    196|                  pcap_datalink_val_to_description(datalink),
  318|    196|                  datalink,
  319|    196|                  datalen);
  320|    196|            return -1;
  321|    196|        }
  322|       |
  323|  1.76k|        if (memcmp(pktdata, JUNIPER_PCAP_MAGIC, 3) != 0) {
  ------------------
  |  |   39|  1.76k|#define JUNIPER_PCAP_MAGIC "MGC"
  ------------------
  |  Branch (323:13): [True: 260, False: 1.50k]
  ------------------
  324|    260|            warnx("%s (0x%x): No JUNIPER_PCAP_MAGIC Magic Number found during protocol lookup",
  ------------------
  |  |  123|    260|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  325|    260|                  pcap_datalink_val_to_description(datalink),
  326|    260|                  datalink);
  327|    260|            return -1;
  328|    260|        }
  329|       |
  330|  1.50k|        if ((pktdata[3] & JUNIPER_FLAG_EXT) == JUNIPER_FLAG_EXT) {
  ------------------
  |  |   38|  1.50k|#define JUNIPER_FLAG_EXT 0x80   /* Juniper extensions present */
  ------------------
                      if ((pktdata[3] & JUNIPER_FLAG_EXT) == JUNIPER_FLAG_EXT) {
  ------------------
  |  |   38|  1.50k|#define JUNIPER_FLAG_EXT 0x80   /* Juniper extensions present */
  ------------------
  |  Branch (330:13): [True: 501, False: 1.00k]
  ------------------
  331|    501|            if (datalen < 6) {
  ------------------
  |  Branch (331:17): [True: 204, False: 297]
  ------------------
  332|    204|                warnx("%s (0x%x): Need at least 6 bytes for JUNIPER_FLAG_EXT but only %u available",
  ------------------
  |  |  123|    204|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  333|    204|                      pcap_datalink_val_to_description(datalink),
  334|    204|                      datalink,
  335|    204|                      datalen);
  336|    204|                return -1;
  337|    204|            }
  338|       |
  339|    297|            *l2offset = ntohs(*((uint16_t *)&pktdata[4]));
  340|    297|            *l2offset += 6; /* MGC + flags + ext_total_len */
  341|  1.00k|        } else {
  342|  1.00k|            *l2offset = 4; /* MGC + flags (no header extensions) */
  343|  1.00k|        }
  344|       |
  345|  1.29k|        if ((pktdata[3] & JUNIPER_FLAG_NO_L2) == JUNIPER_FLAG_NO_L2) {
  ------------------
  |  |   37|  1.29k|#define JUNIPER_FLAG_NO_L2 0x02 /* L2 header */
  ------------------
                      if ((pktdata[3] & JUNIPER_FLAG_NO_L2) == JUNIPER_FLAG_NO_L2) {
  ------------------
  |  |   37|  1.29k|#define JUNIPER_FLAG_NO_L2 0x02 /* L2 header */
  ------------------
  |  Branch (345:13): [True: 1.07k, False: 221]
  ------------------
  346|       |            /* no L2 header present - *l2offset is actually IP offset */
  347|  1.07k|            uint32_t ip_hdr_offset = *l2offset;
  348|  1.07k|            uint32_t hdrSpaceNeeded = ip_hdr_offset + 1;
  349|  1.07k|            if (datalen < hdrSpaceNeeded) {
  ------------------
  |  Branch (349:17): [True: 375, False: 702]
  ------------------
  350|    375|                warnx("%s (0x%x): Need at least %u bytes for JUNIPER_FLAG_NO_L2 but only %u available",
  ------------------
  |  |  123|    375|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  351|    375|                      pcap_datalink_val_to_description(datalink),
  352|    375|                      hdrSpaceNeeded,
  353|    375|                      datalink,
  354|    375|                      datalen);
  355|    375|                return -1;
  356|    375|            }
  357|       |
  358|    702|            if ((pktdata[ip_hdr_offset] >> 4) == 4)
  ------------------
  |  Branch (358:17): [True: 260, False: 442]
  ------------------
  359|    260|                *protocol = ETHERTYPE_IP;
  360|    442|            else if ((pktdata[ip_hdr_offset] >> 4) == 6)
  ------------------
  |  Branch (360:22): [True: 224, False: 218]
  ------------------
  361|    224|                *protocol = ETHERTYPE_IP6;
  ------------------
  |  |  534|    224|#define ETHERTYPE_IP6 0x86DD /* IPv6 */
  ------------------
  362|       |
  363|    702|            return 0;
  364|  1.07k|        }
  365|       |
  366|       |        /* fall through */
  367|  4.09k|    case DLT_EN10MB: {
  ------------------
  |  Branch (367:5): [True: 3.86k, False: 28.5k]
  ------------------
  368|  4.09k|        eth_hdr_t *eth_hdr;
  369|  4.09k|        uint16_t ether_type;
  370|  4.09k|        uint32_t l2_net_off = sizeof(*eth_hdr) + *l2offset;
  371|       |
  372|  4.09k|        if (datalen <= l2_net_off + 4) {
  ------------------
  |  Branch (372:13): [True: 497, False: 3.59k]
  ------------------
  373|    497|            warnx("%s (0x%x): Need at least %u bytes for DLT_EN10MB but only %u available",
  ------------------
  |  |  123|    497|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  374|    497|                  pcap_datalink_val_to_description(datalink),
  375|    497|                  datalink,
  376|    497|                  l2_net_off + 4,
  377|    497|                  datalen);
  378|    497|            return -1;
  379|    497|        }
  380|       |
  381|  3.59k|        eth_hdr = (eth_hdr_t *)(pktdata + *l2offset);
  382|  3.59k|        ether_type = ntohs(eth_hdr->ether_type);
  383|  3.59k|        if (parse_metadata(pktdata, datalen, &ether_type, &l2_net_off, l2offset, vlan_offset))
  ------------------
  |  Branch (383:13): [True: 1.84k, False: 1.74k]
  ------------------
  384|  1.84k|            return -1;
  385|       |
  386|  1.74k|        *l2len = l2_net_off;
  387|  1.74k|        if (ether_type >= 1536) {
  ------------------
  |  Branch (387:13): [True: 1.13k, False: 612]
  ------------------
  388|       |            /* Ethernet II frame - return in host order */
  389|  1.13k|            *protocol = ether_type;
  390|  1.13k|        } else if (ether_type > 1500) {
  ------------------
  |  Branch (390:20): [True: 198, False: 414]
  ------------------
  391|    198|            warnx("%s (0x%x): unsupported 802.3 length %u",
  ------------------
  |  |  123|    198|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  392|    198|                  pcap_datalink_val_to_description(datalink),
  393|    198|                  datalink,
  394|    198|                  ether_type);
  395|    198|            return -1;
  396|    414|        } else {
  397|       |            /* 803.3 frame */
  398|       |            /* we don't modify 802.3 protocols */
  399|    414|            return -1;
  400|    414|        }
  401|  1.13k|        break;
  402|  1.74k|    }
  403|  1.13k|    case DLT_PPP_SERIAL:
  ------------------
  |  Branch (403:5): [True: 659, False: 31.7k]
  ------------------
  404|    659|        if ((size_t)datalen < sizeof(struct tcpr_pppserial_hdr)) {
  ------------------
  |  Branch (404:13): [True: 199, False: 460]
  ------------------
  405|    199|            warnx("%s (0x%x): Need at least %zu bytes for DLT_PPP_SERIAL but only %u available",
  ------------------
  |  |  123|    199|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  406|    199|                  pcap_datalink_val_to_description(datalink),
  407|    199|                  datalink,
  408|    199|                  sizeof(struct tcpr_pppserial_hdr),
  409|    199|                  datalen);
  410|    199|            return -1;
  411|    199|        }
  412|       |
  413|    460|        struct tcpr_pppserial_hdr *ppp = (struct tcpr_pppserial_hdr *)pktdata;
  414|    460|        *l2len = sizeof(*ppp);
  415|    460|        if (ntohs(ppp->protocol) == 0x0021)
  ------------------
  |  Branch (415:13): [True: 199, False: 261]
  ------------------
  416|    199|            *protocol = ETHERTYPE_IP;
  417|    261|        else
  418|    261|            *protocol = ntohs(ppp->protocol);
  419|       |
  420|    460|        break;
  421|    432|    case DLT_C_HDLC:
  ------------------
  |  Branch (421:5): [True: 432, False: 31.9k]
  ------------------
  422|    432|        if (datalen < CISCO_HDLC_LEN) {
  ------------------
  |  |   28|    432|#define CISCO_HDLC_LEN 4
  ------------------
  |  Branch (422:13): [True: 213, False: 219]
  ------------------
  423|    213|            warnx("%s (0x%x): Need at least %u bytes for DLT_C_HDLC but only %u available",
  ------------------
  |  |  123|    213|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  424|    213|                  pcap_datalink_val_to_description(datalink),
  425|    213|                  datalink,
  426|    213|                  CISCO_HDLC_LEN,
  427|    213|                  datalen);
  428|    213|            return -1;
  429|    213|        }
  430|       |
  431|    219|        hdlc_hdr_t *hdlc_hdr = (hdlc_hdr_t *)pktdata;
  432|    219|        *l2len = sizeof(*hdlc_hdr);
  433|    219|        *protocol = ntohs(hdlc_hdr->protocol);
  434|    219|        break;
  435|  3.08k|    case DLT_LINUX_SLL:
  ------------------
  |  Branch (435:5): [True: 3.08k, False: 29.3k]
  ------------------
  436|  3.08k|        if (datalen < SLL_HDR_LEN) {
  ------------------
  |  |   86|  3.08k|#define SLL_HDR_LEN    16           /* total header length */
  ------------------
  |  Branch (436:13): [True: 293, False: 2.79k]
  ------------------
  437|    293|            warnx("%s (0x%x): Need at least %u bytes for DLT_LINUX_SLL but only %u available",
  ------------------
  |  |  123|    293|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  438|    293|                  pcap_datalink_val_to_description(datalink),
  439|    293|                  datalink,
  440|    293|                  SLL_HDR_LEN,
  441|    293|                  datalen);
  442|    293|            return -1;
  443|    293|        }
  444|       |
  445|  2.79k|        *l2len = SLL_HDR_LEN;
  ------------------
  |  |   86|  2.79k|#define SLL_HDR_LEN    16           /* total header length */
  ------------------
  446|  2.79k|        sll_hdr_t *sll_hdr = (sll_hdr_t *)pktdata;
  447|  2.79k|        *protocol = ntohs(sll_hdr->sll_protocol);
  448|  2.79k|        break;
  449|  3.40k|    case DLT_LINUX_SLL2:
  ------------------
  |  Branch (449:5): [True: 3.40k, False: 29.0k]
  ------------------
  450|  3.40k|        if (datalen < SLL2_HDR_LEN) {
  ------------------
  |  |  100|  3.40k|#define SLL2_HDR_LEN    20              /* total header length */
  ------------------
  |  Branch (450:13): [True: 366, False: 3.03k]
  ------------------
  451|    366|            warnx("%s (0x%x): Need at least %u bytes for DLT_LINUX_SLL2 but only %u available",
  ------------------
  |  |  123|    366|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  452|    366|                  pcap_datalink_val_to_description(datalink),
  453|    366|                  datalink,
  454|    366|                  SLL2_HDR_LEN,
  455|    366|                  datalen);
  456|    366|            return -1;
  457|    366|        }
  458|       |
  459|  3.03k|        *l2len = SLL2_HDR_LEN;
  ------------------
  |  |  100|  3.03k|#define SLL2_HDR_LEN    20              /* total header length */
  ------------------
  460|  3.03k|        sll2_hdr_t *sll2_hdr = (sll2_hdr_t *)pktdata;
  461|  3.03k|        *protocol = ntohs(sll2_hdr->sll2_protocol);
  462|  3.03k|        break;
  463|  12.2k|    default:
  ------------------
  |  Branch (463:5): [True: 12.2k, False: 20.1k]
  ------------------
  464|  12.2k|        warnx("Unable to process unsupported DLT type: %s (0x%x)",
  ------------------
  |  |  123|  12.2k|#define warnx(x, ...) fprintf(stderr, "Warning: " x "\n", __VA_ARGS__)
  ------------------
  465|  12.2k|              pcap_datalink_val_to_description(datalink),
  466|  12.2k|              datalink);
  467|  12.2k|        return -1;
  468|  32.4k|    }
  469|       |
  470|  14.4k|    return 0;
  471|  32.4k|}
get_layer4_v4:
  633|    575|{
  634|    575|    void *ptr;
  635|       |
  636|    575|    assert(ip_hdr);
  ------------------
  |  Branch (636:5): [True: 0, False: 575]
  |  Branch (636:5): [True: 575, False: 0]
  ------------------
  637|    575|    assert(end_ptr);
  ------------------
  |  Branch (637:5): [True: 0, False: 575]
  |  Branch (637:5): [True: 575, False: 0]
  ------------------
  638|       |
  639|    575|    ptr = (u_char *)ip_hdr + (ip_hdr->ip_hl << 2);
  640|       |    /* make sure we don't jump over the end of the buffer */
  641|    575|    if ((u_char *)ptr > end_ptr)
  ------------------
  |  Branch (641:9): [True: 267, False: 308]
  ------------------
  642|    267|        return NULL;
  643|       |
  644|    308|    return ((void *)ptr);
  645|    575|}
get_layer4_v6:
  668|  91.7k|{
  669|  91.7k|    struct tcpr_ipv6_ext_hdr_base *next, *exthdr;
  670|  91.7k|    bool done = false;
  671|  91.7k|    uint8_t proto;
  672|       |
  673|  91.7k|    assert(ip6_hdr);
  ------------------
  |  Branch (673:5): [True: 0, False: 91.7k]
  |  Branch (673:5): [True: 91.7k, False: 0]
  ------------------
  674|  91.7k|    assert(end_ptr);
  ------------------
  |  Branch (674:5): [True: 0, False: 91.7k]
  |  Branch (674:5): [True: 91.7k, False: 0]
  ------------------
  675|       |
  676|       |    /* jump to the end of the IPv6 header */
  677|  91.7k|    next = (struct tcpr_ipv6_ext_hdr_base *)((u_char *)ip6_hdr + TCPR_IPV6_H);
  ------------------
  |  |   97|  91.7k|#define TCPR_IPV6_H 0x28              /**< IPv6 header:         40 bytes */
  ------------------
  678|  91.7k|    if ((u_char *)next > end_ptr)
  ------------------
  |  Branch (678:9): [True: 386, False: 91.3k]
  ------------------
  679|    386|        return NULL;
  680|       |
  681|  91.3k|    proto = ip6_hdr->ip_nh;
  682|   192k|    while (!done) {
  ------------------
  |  Branch (682:12): [True: 102k, False: 90.5k]
  ------------------
  683|   102k|        dbgx(3, "Processing proto: 0x%hx", (uint16_t)proto);
  ------------------
  |  |  119|   102k|#define dbgx(x, y, ...) { }
  ------------------
  684|       |
  685|   102k|        switch (proto) {
  686|       |        /* recurse due to v6-in-v6, need to recast next as an IPv6 Header */
  687|  86.3k|        case TCPR_IPV6_NH_IPV6:
  ------------------
  |  |  788|  86.3k|#define TCPR_IPV6_NH_IPV6 41
  ------------------
  |  Branch (687:9): [True: 86.3k, False: 16.0k]
  ------------------
  688|  86.3k|            dbg(3, "recursing due to v6-in-v6");
  ------------------
  |  |  118|  86.3k|#define dbg(x, y) { }
  ------------------
  689|  86.3k|            next = get_layer4_v6((ipv6_hdr_t *)next, end_ptr);
  690|  86.3k|            break;
  691|       |
  692|       |        /* loop again */
  693|    622|        case TCPR_IPV6_NH_AH:
  ------------------
  |  |  790|    622|#define TCPR_IPV6_NH_AH 51
  ------------------
  |  Branch (693:9): [True: 622, False: 101k]
  ------------------
  694|  1.41k|        case TCPR_IPV6_NH_ROUTING:
  ------------------
  |  |  810|  1.41k|#define TCPR_IPV6_NH_ROUTING 43
  ------------------
  |  Branch (694:9): [True: 794, False: 101k]
  ------------------
  695|  2.12k|        case TCPR_IPV6_NH_DESTOPTS:
  ------------------
  |  |  824|  2.12k|#define TCPR_IPV6_NH_DESTOPTS 60
  ------------------
  |  Branch (695:9): [True: 705, False: 101k]
  ------------------
  696|  8.03k|        case TCPR_IPV6_NH_HBH:
  ------------------
  |  |  836|  8.03k|#define TCPR_IPV6_NH_HBH 0
  ------------------
  |  Branch (696:9): [True: 5.90k, False: 96.4k]
  ------------------
  697|  8.03k|            dbgx(3, "Going deeper due to extension header 0x%02X", proto);
  ------------------
  |  |  119|  8.03k|#define dbgx(x, y, ...) { }
  ------------------
  698|  8.03k|            exthdr = get_ipv6_next(next, end_ptr);
  699|  8.03k|            if (!ipv6_exthdr_fits(exthdr, end_ptr)) {
  ------------------
  |  Branch (699:17): [True: 2.02k, False: 6.00k]
  ------------------
  700|  2.02k|                next = NULL;
  701|  2.02k|                done = true;
  702|  2.02k|                break;
  703|  2.02k|            }
  704|  6.00k|            proto = exthdr->ip_nh;
  705|  6.00k|            next = exthdr;
  706|  6.00k|            break;
  707|       |
  708|       |        /*
  709|       |         * handle (unparsable) IPv6 fragment data
  710|       |         */
  711|  3.06k|        case TCPR_IPV6_NH_FRAGMENT:
  ------------------
  |  |  797|  3.06k|#define TCPR_IPV6_NH_FRAGMENT 44
  ------------------
  |  Branch (711:9): [True: 3.06k, False: 99.2k]
  ------------------
  712|       |            // next points to l4 data
  713|  3.06k|            dbgx(3, "Go deeper due to fragment extension header 0x%02X", proto);
  ------------------
  |  |  119|  3.06k|#define dbgx(x, y, ...) { }
  ------------------
  714|  3.06k|            exthdr = get_ipv6_next(next, end_ptr);
  715|  3.06k|            if (!ipv6_exthdr_fits(exthdr, end_ptr)) {
  ------------------
  |  Branch (715:17): [True: 2.02k, False: 1.04k]
  ------------------
  716|  2.02k|                next = NULL;
  717|  2.02k|                done = true;
  718|  2.02k|                break;
  719|  2.02k|            }
  720|  1.04k|            proto = exthdr->ip_nh;
  721|  1.04k|            next = exthdr;
  722|       |            // done = true;
  723|  1.04k|            break;
  724|       |
  725|       |        /*
  726|       |         * Can't handle.  Unparsable IPv6 encrypted data
  727|       |         */
  728|     84|        case TCPR_IPV6_NH_ESP:
  ------------------
  |  |  789|     84|#define TCPR_IPV6_NH_ESP 50
  ------------------
  |  Branch (728:9): [True: 84, False: 102k]
  ------------------
  729|     84|            next = NULL;
  730|     84|            done = true;
  731|     84|            break;
  732|       |
  733|       |        /*
  734|       |         * no further processing, either TCP, UDP, ICMP, etc...
  735|       |         */
  736|  4.84k|        default:
  ------------------
  |  Branch (736:9): [True: 4.84k, False: 97.4k]
  ------------------
  737|  4.84k|            if (proto != ip6_hdr->ip_nh && next) {
  ------------------
  |  Branch (737:17): [True: 1.97k, False: 2.87k]
  |  Branch (737:44): [True: 1.97k, False: 0]
  ------------------
  738|       |                /* reading next->ip_len needs the base header to be present */
  739|  1.97k|                if (!ipv6_exthdr_fits(next, end_ptr)) {
  ------------------
  |  Branch (739:21): [True: 0, False: 1.97k]
  ------------------
  740|      0|                    return NULL;
  741|      0|                }
  742|       |
  743|  1.97k|                dbgx(3, "Returning byte offset of this ext header: %u", IPV6_EXTLEN_TO_BYTES(next->ip_len));
  ------------------
  |  |  119|  1.97k|#define dbgx(x, y, ...) { }
  ------------------
  744|  1.97k|                next = (void *)((u_char *)next + IPV6_EXTLEN_TO_BYTES(next->ip_len));
  ------------------
  |  |  292|  1.97k|#define IPV6_EXTLEN_TO_BYTES(x) ((x * 4) + 8)
  ------------------
  745|  1.97k|                if ((u_char*)next > end_ptr)
  ------------------
  |  Branch (745:21): [True: 833, False: 1.13k]
  ------------------
  746|    833|                    return NULL;
  747|  2.87k|            } else {
  748|  2.87k|                dbgx(3, "%s", "Returning end of IPv6 Header");
  ------------------
  |  |  119|  2.87k|#define dbgx(x, y, ...) { }
  ------------------
  749|  2.87k|            }
  750|       |
  751|  4.01k|            done = true;
  752|   102k|        } /* switch */
  753|       |
  754|   101k|        if (next == NULL)
  ------------------
  |  Branch (754:13): [True: 86.5k, False: 14.9k]
  ------------------
  755|  86.5k|            done = true;
  756|   101k|    } /* while */
  757|       |
  758|  90.5k|    return next;
  759|  91.3k|}
get_ipv6_l4proto:
  828|  9.20k|{
  829|  9.20k|    u_char *ptr = (u_char *)ip6_hdr + TCPR_IPV6_H; /* jump to the end of the IPv6 header */
  ------------------
  |  |   97|  9.20k|#define TCPR_IPV6_H 0x28              /**< IPv6 header:         40 bytes */
  ------------------
  830|  9.20k|    uint8_t proto;
  831|  9.20k|    struct tcpr_ipv6_ext_hdr_base *exthdr = NULL;
  832|       |
  833|  9.20k|    assert(ip6_hdr);
  ------------------
  |  Branch (833:5): [True: 0, False: 9.20k]
  |  Branch (833:5): [True: 9.20k, False: 0]
  ------------------
  834|       |
  835|  9.20k|    if (ptr > end_ptr)
  ------------------
  |  Branch (835:9): [True: 308, False: 8.89k]
  ------------------
  836|    308|        return TCPR_IPV6_NH_NO_NEXT;
  ------------------
  |  |  787|    308|#define TCPR_IPV6_NH_NO_NEXT 59
  ------------------
  837|       |
  838|  8.89k|    proto = ip6_hdr->ip_nh;
  839|  11.1k|    while (TRUE) {
  ------------------
  |  Branch (839:12): [True: 11.1k, Folded]
  ------------------
  840|  11.1k|        dbgx(3, "Processing next proto 0x%02X", proto);
  ------------------
  |  |  119|  11.1k|#define dbgx(x, y, ...) { }
  ------------------
  841|  11.1k|        switch (proto) {
  842|       |        /* no further processing for IPV6 types with nothing beyond them */
  843|      0|        case TCPR_IPV6_NH_NO_NEXT:
  ------------------
  |  |  787|      0|#define TCPR_IPV6_NH_NO_NEXT 59
  ------------------
  |  Branch (843:9): [True: 0, False: 11.1k]
  ------------------
  844|  2.63k|        case TCPR_IPV6_NH_FRAGMENT:
  ------------------
  |  |  797|  2.63k|#define TCPR_IPV6_NH_FRAGMENT 44
  ------------------
  |  Branch (844:9): [True: 2.63k, False: 8.50k]
  ------------------
  845|  2.71k|        case TCPR_IPV6_NH_ESP:
  ------------------
  |  |  789|  2.71k|#define TCPR_IPV6_NH_ESP 50
  ------------------
  |  Branch (845:9): [True: 83, False: 11.0k]
  ------------------
  846|  2.71k|            dbg(3, "No-Next or ESP... can't go any further...");
  ------------------
  |  |  118|  2.71k|#define dbg(x, y) { }
  ------------------
  847|  2.71k|            return proto;
  848|       |
  849|       |        /* recurse */
  850|  3.75k|        case TCPR_IPV6_NH_IPV6:
  ------------------
  |  |  788|  3.75k|#define TCPR_IPV6_NH_IPV6 41
  ------------------
  |  Branch (850:9): [True: 3.75k, False: 7.38k]
  ------------------
  851|  3.75k|            dbg(3, "Recursing due to v6 in v6");
  ------------------
  |  |  118|  3.75k|#define dbg(x, y) { }
  ------------------
  852|  3.75k|            return get_ipv6_l4proto((ipv6_hdr_t *)ptr, end_ptr);
  853|       |
  854|       |        /* loop again */
  855|    577|        case TCPR_IPV6_NH_AH:
  ------------------
  |  |  790|    577|#define TCPR_IPV6_NH_AH 51
  ------------------
  |  Branch (855:9): [True: 577, False: 10.5k]
  ------------------
  856|  1.28k|        case TCPR_IPV6_NH_ROUTING:
  ------------------
  |  |  810|  1.28k|#define TCPR_IPV6_NH_ROUTING 43
  ------------------
  |  Branch (856:9): [True: 706, False: 10.4k]
  ------------------
  857|  1.74k|        case TCPR_IPV6_NH_DESTOPTS:
  ------------------
  |  |  824|  1.74k|#define TCPR_IPV6_NH_DESTOPTS 60
  ------------------
  |  Branch (857:9): [True: 461, False: 10.6k]
  ------------------
  858|  4.10k|        case TCPR_IPV6_NH_HBH:
  ------------------
  |  |  836|  4.10k|#define TCPR_IPV6_NH_HBH 0
  ------------------
  |  Branch (858:9): [True: 2.36k, False: 8.77k]
  ------------------
  859|  4.10k|            dbgx(3, "Jumping to next extension header (0x%hhx)", proto);
  ------------------
  |  |  119|  4.10k|#define dbgx(x, y, ...) { }
  ------------------
  860|  4.10k|            exthdr = get_ipv6_next((struct tcpr_ipv6_ext_hdr_base *)ptr, end_ptr);
  861|  4.10k|            if (exthdr == NULL || (u_char *)exthdr + sizeof(*exthdr) > end_ptr)
  ------------------
  |  Branch (861:17): [True: 1.61k, False: 2.49k]
  |  Branch (861:35): [True: 253, False: 2.24k]
  ------------------
  862|  1.86k|                return TCPR_IPV6_NH_NO_NEXT;
  ------------------
  |  |  787|  1.86k|#define TCPR_IPV6_NH_NO_NEXT 59
  ------------------
  863|  2.24k|            proto = exthdr->ip_nh;
  864|  2.24k|            ptr = (u_char *)exthdr;
  865|  2.24k|            break;
  866|       |
  867|       |        /* should be TCP, UDP or the like */
  868|    565|        default:
  ------------------
  |  Branch (868:9): [True: 565, False: 10.5k]
  ------------------
  869|    565|            dbgx(3, "Selecting next L4 Proto as: 0x%02x", proto);
  ------------------
  |  |  119|    565|#define dbgx(x, y, ...) { }
  ------------------
  870|    565|            return proto;
  871|  11.1k|        } /* switch */
  872|  11.1k|    }     /* while */
  873|  8.89k|}
get.c:parse_metadata:
  230|  3.59k|{
  231|  3.59k|    bool done = false;
  232|  3.59k|    assert(next_protocol);
  ------------------
  |  Branch (232:5): [True: 0, False: 3.59k]
  |  Branch (232:5): [True: 3.59k, False: 0]
  ------------------
  233|  3.59k|    assert(l2len);
  ------------------
  |  Branch (233:5): [True: 0, False: 3.59k]
  |  Branch (233:5): [True: 3.59k, False: 0]
  ------------------
  234|  3.59k|    assert(l2offset);
  ------------------
  |  Branch (234:5): [True: 0, False: 3.59k]
  |  Branch (234:5): [True: 3.59k, False: 0]
  ------------------
  235|  3.59k|    assert(vlan_offset);
  ------------------
  |  Branch (235:5): [True: 0, False: 3.59k]
  |  Branch (235:5): [True: 3.59k, False: 0]
  ------------------
  236|       |
  237|  3.59k|    if (!pktdata || !datalen)
  ------------------
  |  Branch (237:9): [True: 0, False: 3.59k]
  |  Branch (237:21): [True: 0, False: 3.59k]
  ------------------
  238|      0|        errx(-1, "parse_metadata: invalid L2 parameters: pktdata=0x%p len=%d", pktdata, datalen);
  ------------------
  |  |  131|      0|#define errx(x, y, ...) do {\
  |  |  132|      0|        fprintf(stderr, "\nFatal Error: " y "\n", __VA_ARGS__); \
  |  |  133|      0|        fflush(NULL); \
  |  |  134|      0|        exit(x); \
  |  |  135|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (135:14): [Folded, False: 0]
  |  |  ------------------
  ------------------
  239|       |
  240|  7.96k|    while (!done) {
  ------------------
  |  Branch (240:12): [True: 6.22k, False: 1.74k]
  ------------------
  241|  6.22k|        switch (*next_protocol) {
  242|    556|        case ETHERTYPE_VLAN:
  ------------------
  |  Branch (242:9): [True: 556, False: 5.66k]
  ------------------
  243|  1.35k|        case ETHERTYPE_Q_IN_Q:
  ------------------
  |  |  537|  1.35k|#define ETHERTYPE_Q_IN_Q 0x88A8 /* 802.1ad Service VLAN */
  ------------------
  |  Branch (243:9): [True: 803, False: 5.42k]
  ------------------
  244|  1.74k|        case ETHERTYPE_8021QINQ:
  ------------------
  |  |  540|  1.74k|#define ETHERTYPE_8021QINQ 0x9100 /* 802.1Q in Q VLAN */
  ------------------
  |  Branch (244:9): [True: 381, False: 5.84k]
  ------------------
  245|  1.74k|            if (*vlan_offset == 0)
  ------------------
  |  Branch (245:17): [True: 657, False: 1.08k]
  ------------------
  246|    657|                *vlan_offset = *l2len;
  247|       |
  248|  1.74k|            if (parse_vlan(pktdata, datalen, next_protocol, l2len))
  ------------------
  |  Branch (248:17): [True: 390, False: 1.35k]
  ------------------
  249|    390|                return -1;
  250|       |
  251|  1.35k|            break;
  252|  2.03k|        case ETHERTYPE_MPLS:
  ------------------
  |  |  528|  2.03k|#define ETHERTYPE_MPLS 0x8847 /* MPLS */
  ------------------
  |  Branch (252:9): [True: 2.03k, False: 4.18k]
  ------------------
  253|  2.74k|        case ETHERTYPE_MPLS_MULTI:
  ------------------
  |  |  543|  2.74k|#define ETHERTYPE_MPLS_MULTI 0x8848 /* MPLS multicast packet */
  ------------------
  |  Branch (253:9): [True: 702, False: 5.52k]
  ------------------
  254|  2.74k|            if (parse_mpls(pktdata, datalen, next_protocol, l2len, l2offset))
  ------------------
  |  Branch (254:17): [True: 1.45k, False: 1.28k]
  ------------------
  255|  1.45k|                return -1;
  256|       |
  257|  1.28k|            break;
  258|  1.74k|        default:
  ------------------
  |  Branch (258:9): [True: 1.74k, False: 4.48k]
  ------------------
  259|  1.74k|            done = true;
  260|  6.22k|        }
  261|  6.22k|    }
  262|       |
  263|  1.74k|    return 0;
  264|  3.59k|}
get.c:ipv6_exthdr_fits:
  657|  13.0k|{
  658|  13.0k|    return hdr != NULL && (const u_char *)hdr + sizeof(*hdr) <= end_ptr;
  ------------------
  |  Branch (658:12): [True: 9.33k, False: 3.73k]
  |  Branch (658:27): [True: 9.01k, False: 321]
  ------------------
  659|  13.0k|}
get.c:get_ipv6_next:
  767|  15.1k|{
  768|  15.1k|    uint8_t extlen;
  769|  15.1k|    u_char *ptr;
  770|  15.1k|    assert(exthdr);
  ------------------
  |  Branch (770:5): [True: 0, False: 15.1k]
  |  Branch (770:5): [True: 15.1k, False: 0]
  ------------------
  771|       |
  772|  15.1k|    if ((u_char *)exthdr + sizeof(*exthdr) > end_ptr)
  ------------------
  |  Branch (772:9): [True: 776, False: 14.4k]
  ------------------
  773|    776|        return NULL;
  774|       |
  775|  14.4k|    dbgx(3, "Jumping to next IPv6 header.  Processing 0x%02x", exthdr->ip_nh);
  ------------------
  |  |  119|  14.4k|#define dbgx(x, y, ...) { }
  ------------------
  776|  14.4k|    switch (exthdr->ip_nh) {
  777|       |    /* no further processing */
  778|    586|    case TCPR_IPV6_NH_NO_NEXT:
  ------------------
  |  |  787|    586|#define TCPR_IPV6_NH_NO_NEXT 59
  ------------------
  |  Branch (778:5): [True: 586, False: 13.8k]
  ------------------
  779|  1.16k|    case TCPR_IPV6_NH_ESP:
  ------------------
  |  |  789|  1.16k|#define TCPR_IPV6_NH_ESP 50
  ------------------
  |  Branch (779:5): [True: 583, False: 13.8k]
  ------------------
  780|  1.16k|        dbg(3, "No-Next or ESP... can't go any further...");
  ------------------
  |  |  118|  1.16k|#define dbg(x, y) { }
  ------------------
  781|  1.16k|        return NULL;
  782|       |
  783|       |    /*
  784|       |     * fragment header is fixed size
  785|       |     * FIXME: Frag header has further ext headers (has a ip_nh field)
  786|       |     * but I don't support it because there's never a full L4 + payload beyond.
  787|       |     */
  788|  1.70k|    case TCPR_IPV6_NH_FRAGMENT:
  ------------------
  |  |  797|  1.70k|#define TCPR_IPV6_NH_FRAGMENT 44
  ------------------
  |  Branch (788:5): [True: 1.70k, False: 12.7k]
  ------------------
  789|  1.70k|        dbg(3, "Looks like were a fragment header. Returning some frag'd data.");
  ------------------
  |  |  118|  1.70k|#define dbg(x, y) { }
  ------------------
  790|  1.70k|        ptr = (void *)((u_char *)exthdr + sizeof(struct tcpr_ipv6_frag_hdr));
  791|  1.70k|        if (ptr > end_ptr)
  ------------------
  |  Branch (791:13): [True: 603, False: 1.10k]
  ------------------
  792|    603|            return NULL;
  793|  1.10k|        return (void *)ptr;
  794|       |
  795|       |    /* all the rest require us to go deeper using the ip_len field */
  796|  1.15k|    case TCPR_IPV6_NH_IPV6:
  ------------------
  |  |  788|  1.15k|#define TCPR_IPV6_NH_IPV6 41
  ------------------
  |  Branch (796:5): [True: 1.15k, False: 13.2k]
  ------------------
  797|  1.98k|    case TCPR_IPV6_NH_ROUTING:
  ------------------
  |  |  810|  1.98k|#define TCPR_IPV6_NH_ROUTING 43
  ------------------
  |  Branch (797:5): [True: 839, False: 13.5k]
  ------------------
  798|  3.26k|    case TCPR_IPV6_NH_DESTOPTS:
  ------------------
  |  |  824|  3.26k|#define TCPR_IPV6_NH_DESTOPTS 60
  ------------------
  |  Branch (798:5): [True: 1.27k, False: 13.1k]
  ------------------
  799|  8.93k|    case TCPR_IPV6_NH_HBH:
  ------------------
  |  |  836|  8.93k|#define TCPR_IPV6_NH_HBH 0
  ------------------
  |  Branch (799:5): [True: 5.67k, False: 8.74k]
  ------------------
  800|  9.98k|    case TCPR_IPV6_NH_AH:
  ------------------
  |  |  790|  9.98k|#define TCPR_IPV6_NH_AH 51
  ------------------
  |  Branch (800:5): [True: 1.04k, False: 13.3k]
  ------------------
  801|  9.98k|        extlen = IPV6_EXTLEN_TO_BYTES(exthdr->ip_len);
  ------------------
  |  |  292|  9.98k|#define IPV6_EXTLEN_TO_BYTES(x) ((x * 4) + 8)
  ------------------
  802|  9.98k|        if (extlen == 0) {
  ------------------
  |  Branch (802:13): [True: 1.00k, False: 8.98k]
  ------------------
  803|  1.00k|            dbg(3, "Malformed IPv6 extension header...");
  ------------------
  |  |  118|  1.00k|#define dbg(x, y) { }
  ------------------
  804|  1.00k|            return NULL;
  805|  1.00k|        }
  806|  8.98k|        dbgx(3,
  ------------------
  |  |  119|  8.98k|#define dbgx(x, y, ...) { }
  ------------------
  807|  8.98k|             "Looks like we're an ext header (0x%hhx).  Jumping %u bytes"
  808|  8.98k|             " to the next",
  809|  8.98k|             exthdr->ip_nh,
  810|  8.98k|             extlen);
  811|  8.98k|        ptr = (u_char *)exthdr + extlen;
  812|  8.98k|        if (ptr > end_ptr)
  ------------------
  |  Branch (812:13): [True: 1.79k, False: 7.19k]
  ------------------
  813|  1.79k|            return NULL;
  814|  7.19k|        return (void *)ptr;
  815|       |
  816|  1.56k|    default:
  ------------------
  |  Branch (816:5): [True: 1.56k, False: 12.8k]
  ------------------
  817|  1.56k|        dbg(3, "Must not be a v6 extension header... returning self");
  ------------------
  |  |  118|  1.56k|#define dbg(x, y) { }
  ------------------
  818|  1.56k|        return (void *)exthdr;
  819|  14.4k|    }
  820|  14.4k|}

LLVMFuzzerTestOneInput:
   53|  5.56k|{
   54|  5.56k|    FILE *fp;
   55|  5.56k|    pcap_t *pcap;
   56|  5.56k|    char errbuf[PCAP_ERRBUF_SIZE];
   57|  5.56k|    struct pcap_pkthdr *pkthdr;
   58|  5.56k|    const u_char *pktdata;
   59|  5.56k|    int datalink;
   60|  5.56k|    int rc;
   61|  5.56k|    unsigned int packets = 0;
   62|       |
   63|       |    /* a pcap file header is 24 bytes; below that there is nothing to open */
   64|  5.56k|    if (size < 24)
  ------------------
  |  Branch (64:9): [True: 8, False: 5.56k]
  ------------------
   65|      8|        return 0;
   66|       |
   67|       |    /*
   68|       |     * fmemopen wants a writable pointer but libpcap only reads. Casting away
   69|       |     * const on the fuzzer's buffer is not on - copy it.
   70|       |     */
   71|  5.56k|    void *copy = malloc(size);
   72|  5.56k|    if (copy == NULL)
  ------------------
  |  Branch (72:9): [True: 0, False: 5.56k]
  ------------------
   73|      0|        return 0;
   74|  5.56k|    memcpy(copy, data, size);
   75|       |
   76|  5.56k|    fp = fmemopen(copy, size, "rb");
   77|  5.56k|    if (fp == NULL) {
  ------------------
  |  Branch (77:9): [True: 0, False: 5.56k]
  ------------------
   78|      0|        free(copy);
   79|      0|        return 0;
   80|      0|    }
   81|       |
   82|  5.56k|    pcap = pcap_fopen_offline(fp, errbuf);
   83|  5.56k|    if (pcap == NULL) {
  ------------------
  |  Branch (83:9): [True: 805, False: 4.75k]
  ------------------
   84|       |        /* malformed header: libpcap rejected it, which is the correct outcome */
   85|    805|        fclose(fp);
   86|    805|        free(copy);
   87|    805|        return 0;
   88|    805|    }
   89|       |    /* from here on the pcap_t owns fp and closes it in pcap_close() - closing
   90|       |     * it again here is a double free, and it is the harness that would be
   91|       |     * wrong, not libpcap */
   92|       |
   93|  4.75k|    datalink = pcap_datalink(pcap);
   94|       |
   95|  45.4k|    while ((rc = pcap_next_ex(pcap, &pkthdr, &pktdata)) == 1) {
  ------------------
  |  Branch (95:12): [True: 40.6k, False: 4.75k]
  ------------------
   96|  40.6k|        uint16_t ethertype;
   97|  40.6k|        uint32_t l2len, l2offset, vlan_offset;
   98|       |
   99|       |        /*
  100|       |         * Cap the work per input. A crafted pcap can claim an enormous packet
  101|       |         * count, and the fuzzer's time is better spent on new shapes than on
  102|       |         * one pathological file.
  103|       |         */
  104|  40.6k|        if (++packets > 512)
  ------------------
  |  Branch (104:13): [True: 1, False: 40.6k]
  ------------------
  105|      1|            break;
  106|       |
  107|  40.6k|        if (pkthdr->caplen == 0)
  ------------------
  |  Branch (107:13): [True: 8.24k, False: 32.4k]
  ------------------
  108|  8.24k|            continue;
  109|       |
  110|       |        /*
  111|       |         * The parsers take an end pointer computed from caplen. Deliberately
  112|       |         * use caplen, not len: the gap between them is what GHSA-m6w7-8497-g9c9
  113|       |         * was about, and a harness that papered over it would hide the bug
  114|       |         * class it exists to find.
  115|       |         */
  116|  32.4k|        if (get_l2len_protocol(pktdata,
  ------------------
  |  Branch (116:13): [True: 17.2k, False: 15.1k]
  ------------------
  117|  32.4k|                               pkthdr->caplen,
  118|  32.4k|                               datalink,
  119|  32.4k|                               &ethertype,
  120|  32.4k|                               &l2len,
  121|  32.4k|                               &l2offset,
  122|  32.4k|                               &vlan_offset) < 0)
  123|  17.2k|            continue;
  124|       |
  125|  15.1k|        if (l2len > pkthdr->caplen)
  ------------------
  |  Branch (125:13): [True: 0, False: 15.1k]
  ------------------
  126|      0|            continue;
  127|       |
  128|  15.1k|        switch (ethertype) {
  129|  1.41k|        case ETHERTYPE_IP: {
  ------------------
  |  Branch (129:9): [True: 1.41k, False: 13.6k]
  ------------------
  130|  1.41k|            ipv4_hdr_t *ip_hdr = (ipv4_hdr_t *)(pktdata + l2len);
  131|       |
  132|  1.41k|            if (pkthdr->caplen < l2len + sizeof(ipv4_hdr_t))
  ------------------
  |  Branch (132:17): [True: 838, False: 575]
  ------------------
  133|    838|                break;
  134|       |
  135|    575|            (void)get_layer4_v4(ip_hdr, pktdata + pkthdr->caplen - 1);
  136|    575|            break;
  137|  1.41k|        }
  138|       |
  139|  6.08k|        case ETHERTYPE_IP6: {
  ------------------
  |  |  534|  6.08k|#define ETHERTYPE_IP6 0x86DD /* IPv6 */
  ------------------
  |  Branch (139:9): [True: 6.08k, False: 9.02k]
  ------------------
  140|  6.08k|            ipv6_hdr_t *ip6_hdr = (ipv6_hdr_t *)(pktdata + l2len);
  141|       |
  142|  6.08k|            if (pkthdr->caplen < l2len + sizeof(ipv6_hdr_t))
  ------------------
  |  Branch (142:17): [True: 638, False: 5.44k]
  ------------------
  143|    638|                break;
  144|       |
  145|       |            /* GHSA-jj65-mrgg-f5fx */
  146|  5.44k|            (void)get_layer4_v6(ip6_hdr, pktdata + pkthdr->caplen - 1);
  147|  5.44k|            (void)get_ipv6_l4proto(ip6_hdr, pktdata + pkthdr->caplen - 1);
  148|  5.44k|            break;
  149|  6.08k|        }
  150|       |
  151|  7.61k|        default:
  ------------------
  |  Branch (151:9): [True: 7.61k, False: 7.50k]
  ------------------
  152|  7.61k|            break;
  153|  15.1k|        }
  154|  15.1k|    }
  155|       |
  156|  4.75k|    pcap_close(pcap);
  157|  4.75k|    free(copy);
  158|  4.75k|    return 0;
  159|  4.75k|}

