|
Packit |
209cc3 |
/*
|
|
Packit |
209cc3 |
* Copyright (c) 1988, 1989, 1990, 1991, 1992, 1993, 1994, 1995, 1996, 1997, 2000
|
|
Packit |
209cc3 |
* The Regents of the University of California. All rights reserved.
|
|
Packit |
209cc3 |
*
|
|
Packit |
209cc3 |
* Redistribution and use in source and binary forms, with or without
|
|
Packit |
209cc3 |
* modification, are permitted provided that: (1) source code distributions
|
|
Packit |
209cc3 |
* retain the above copyright notice and this paragraph in its entirety, (2)
|
|
Packit |
209cc3 |
* distributions including binary code include the above copyright notice and
|
|
Packit |
209cc3 |
* this paragraph in its entirety in the documentation or other materials
|
|
Packit |
209cc3 |
* provided with the distribution, and (3) all advertising materials mentioning
|
|
Packit |
209cc3 |
* features or use of this software display the following acknowledgement:
|
|
Packit |
209cc3 |
* ``This product includes software developed by the University of California,
|
|
Packit |
209cc3 |
* Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
|
|
Packit |
209cc3 |
* the University nor the names of its contributors may be used to endorse
|
|
Packit |
209cc3 |
* or promote products derived from this software without specific prior
|
|
Packit |
209cc3 |
* written permission.
|
|
Packit |
209cc3 |
* THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
|
|
Packit |
209cc3 |
* WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
|
|
Packit |
209cc3 |
* MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
|
|
Packit |
209cc3 |
*/
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#include "varattrs.h"
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifndef lint
|
|
Packit |
209cc3 |
static const char copyright[] _U_ =
|
|
Packit |
209cc3 |
"@(#) Copyright (c) 1988, 1989, 1990, 1991, 1992, 1993, 1994, 1995, 1996, 1997, 2000\n\
|
|
Packit |
209cc3 |
The Regents of the University of California. All rights reserved.\n";
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifdef HAVE_CONFIG_H
|
|
Packit |
209cc3 |
#include <config.h>
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#include <pcap.h>
|
|
Packit |
209cc3 |
#include <stdio.h>
|
|
Packit |
209cc3 |
#include <stdlib.h>
|
|
Packit |
209cc3 |
#include <string.h>
|
|
Packit |
209cc3 |
#include <stdarg.h>
|
|
Packit |
209cc3 |
#ifdef _WIN32
|
|
Packit |
209cc3 |
#include "getopt.h"
|
|
Packit |
209cc3 |
#include "unix.h"
|
|
Packit |
209cc3 |
#else
|
|
Packit |
209cc3 |
#include <unistd.h>
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
#include <fcntl.h>
|
|
Packit |
209cc3 |
#include <errno.h>
|
|
Packit |
209cc3 |
#ifdef _WIN32
|
|
Packit |
209cc3 |
#include <winsock2.h>
|
|
Packit |
209cc3 |
#include <ws2tcpip.h>
|
|
Packit |
209cc3 |
#else
|
|
Packit |
209cc3 |
#include <sys/socket.h>
|
|
Packit |
209cc3 |
#include <arpa/inet.h>
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
#include <sys/types.h>
|
|
Packit |
209cc3 |
#include <sys/stat.h>
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#include "pcap/funcattrs.h"
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifdef BDEBUG
|
|
Packit |
209cc3 |
/*
|
|
Packit |
209cc3 |
* We have pcap_set_optimizer_debug() and pcap_set_print_dot_graph() in
|
|
Packit |
209cc3 |
* libpcap; declare them (they're not declared by any libpcap header,
|
|
Packit |
209cc3 |
* because they're special hacks, only available if libpcap was configured
|
|
Packit |
209cc3 |
* to include them, and only intended for use by libpcap developers trying
|
|
Packit |
209cc3 |
* to debug the optimizer for filter expressions).
|
|
Packit |
209cc3 |
*/
|
|
Packit |
209cc3 |
PCAP_API void pcap_set_optimizer_debug(int);
|
|
Packit |
209cc3 |
PCAP_API void pcap_set_print_dot_graph(int);
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
static char *program_name;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
/* Forwards */
|
|
Packit |
209cc3 |
static void PCAP_NORETURN usage(void);
|
|
Packit |
209cc3 |
static void PCAP_NORETURN error(const char *, ...) PCAP_PRINTFLIKE(1, 2);
|
|
Packit |
209cc3 |
static void warn(const char *, ...) PCAP_PRINTFLIKE(1, 2);
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
/*
|
|
Packit |
209cc3 |
* On Windows, we need to open the file in binary mode, so that
|
|
Packit |
209cc3 |
* we get all the bytes specified by the size we get from "fstat()".
|
|
Packit |
209cc3 |
* On UNIX, that's not necessary. O_BINARY is defined on Windows;
|
|
Packit |
209cc3 |
* we define it as 0 if it's not defined, so it does nothing.
|
|
Packit |
209cc3 |
*/
|
|
Packit |
209cc3 |
#ifndef O_BINARY
|
|
Packit |
209cc3 |
#define O_BINARY 0
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
static char *
|
|
Packit |
209cc3 |
read_infile(char *fname)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
register int i, fd, cc;
|
|
Packit |
209cc3 |
register char *cp;
|
|
Packit |
209cc3 |
struct stat buf;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
fd = open(fname, O_RDONLY|O_BINARY);
|
|
Packit |
209cc3 |
if (fd < 0)
|
|
Packit |
209cc3 |
error("can't open %s: %s", fname, pcap_strerror(errno));
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
if (fstat(fd, &buf) < 0)
|
|
Packit |
209cc3 |
error("can't stat %s: %s", fname, pcap_strerror(errno));
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
cp = malloc((u_int)buf.st_size + 1);
|
|
Packit |
209cc3 |
if (cp == NULL)
|
|
Packit |
209cc3 |
error("malloc(%d) for %s: %s", (u_int)buf.st_size + 1,
|
|
Packit |
209cc3 |
fname, pcap_strerror(errno));
|
|
Packit |
209cc3 |
cc = read(fd, cp, (u_int)buf.st_size);
|
|
Packit |
209cc3 |
if (cc < 0)
|
|
Packit |
209cc3 |
error("read %s: %s", fname, pcap_strerror(errno));
|
|
Packit |
209cc3 |
if (cc != buf.st_size)
|
|
Packit |
209cc3 |
error("short read %s (%d != %d)", fname, cc, (int)buf.st_size);
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
close(fd);
|
|
Packit |
209cc3 |
/* replace "# comment" with spaces */
|
|
Packit |
209cc3 |
for (i = 0; i < cc; i++) {
|
|
Packit |
209cc3 |
if (cp[i] == '#')
|
|
Packit |
209cc3 |
while (i < cc && cp[i] != '\n')
|
|
Packit |
209cc3 |
cp[i++] = ' ';
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
cp[cc] = '\0';
|
|
Packit |
209cc3 |
return (cp);
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
/* VARARGS */
|
|
Packit |
209cc3 |
static void
|
|
Packit |
209cc3 |
error(const char *fmt, ...)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
va_list ap;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
(void)fprintf(stderr, "%s: ", program_name);
|
|
Packit |
209cc3 |
va_start(ap, fmt);
|
|
Packit |
209cc3 |
(void)vfprintf(stderr, fmt, ap);
|
|
Packit |
209cc3 |
va_end(ap);
|
|
Packit |
209cc3 |
if (*fmt) {
|
|
Packit |
209cc3 |
fmt += strlen(fmt);
|
|
Packit |
209cc3 |
if (fmt[-1] != '\n')
|
|
Packit |
209cc3 |
(void)fputc('\n', stderr);
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
exit(1);
|
|
Packit |
209cc3 |
/* NOTREACHED */
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
/* VARARGS */
|
|
Packit |
209cc3 |
static void
|
|
Packit |
209cc3 |
warn(const char *fmt, ...)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
va_list ap;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
(void)fprintf(stderr, "%s: WARNING: ", program_name);
|
|
Packit |
209cc3 |
va_start(ap, fmt);
|
|
Packit |
209cc3 |
(void)vfprintf(stderr, fmt, ap);
|
|
Packit |
209cc3 |
va_end(ap);
|
|
Packit |
209cc3 |
if (*fmt) {
|
|
Packit |
209cc3 |
fmt += strlen(fmt);
|
|
Packit |
209cc3 |
if (fmt[-1] != '\n')
|
|
Packit |
209cc3 |
(void)fputc('\n', stderr);
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
/*
|
|
Packit |
209cc3 |
* Copy arg vector into a new buffer, concatenating arguments with spaces.
|
|
Packit |
209cc3 |
*/
|
|
Packit |
209cc3 |
static char *
|
|
Packit |
209cc3 |
copy_argv(register char **argv)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
register char **p;
|
|
Packit |
209cc3 |
register u_int len = 0;
|
|
Packit |
209cc3 |
char *buf;
|
|
Packit |
209cc3 |
char *src, *dst;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
p = argv;
|
|
Packit |
209cc3 |
if (*p == 0)
|
|
Packit |
209cc3 |
return 0;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
while (*p)
|
|
Packit |
209cc3 |
len += strlen(*p++) + 1;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
buf = (char *)malloc(len);
|
|
Packit |
209cc3 |
if (buf == NULL)
|
|
Packit |
209cc3 |
error("copy_argv: malloc");
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
p = argv;
|
|
Packit |
209cc3 |
dst = buf;
|
|
Packit |
209cc3 |
while ((src = *p++) != NULL) {
|
|
Packit |
209cc3 |
while ((*dst++ = *src++) != '\0')
|
|
Packit |
209cc3 |
;
|
|
Packit |
209cc3 |
dst[-1] = ' ';
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
dst[-1] = '\0';
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
return buf;
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
int
|
|
Packit |
209cc3 |
main(int argc, char **argv)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
char *cp;
|
|
Packit |
209cc3 |
int op;
|
|
Packit |
209cc3 |
int dflag;
|
|
Packit |
209cc3 |
int gflag;
|
|
Packit |
209cc3 |
char *infile;
|
|
Packit |
209cc3 |
int Oflag;
|
|
Packit |
209cc3 |
long snaplen;
|
|
Packit |
209cc3 |
char *p;
|
|
Packit |
209cc3 |
int dlt;
|
|
Packit |
209cc3 |
int have_fcode = 0;
|
|
Packit |
209cc3 |
bpf_u_int32 netmask = PCAP_NETMASK_UNKNOWN;
|
|
Packit |
209cc3 |
char *cmdbuf;
|
|
Packit |
209cc3 |
pcap_t *pd;
|
|
Packit |
209cc3 |
struct bpf_program fcode;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifdef _WIN32
|
|
Packit |
209cc3 |
if (pcap_wsockinit() != 0)
|
|
Packit |
209cc3 |
return 1;
|
|
Packit |
209cc3 |
#endif /* _WIN32 */
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
dflag = 1;
|
|
Packit |
209cc3 |
gflag = 0;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
infile = NULL;
|
|
Packit |
209cc3 |
Oflag = 1;
|
|
Packit |
209cc3 |
snaplen = 68;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
if ((cp = strrchr(argv[0], '/')) != NULL)
|
|
Packit |
209cc3 |
program_name = cp + 1;
|
|
Packit |
209cc3 |
else
|
|
Packit |
209cc3 |
program_name = argv[0];
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
opterr = 0;
|
|
Packit |
209cc3 |
while ((op = getopt(argc, argv, "dF:gm:Os:")) != -1) {
|
|
Packit |
209cc3 |
switch (op) {
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 'd':
|
|
Packit |
209cc3 |
++dflag;
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 'g':
|
|
Packit |
209cc3 |
#ifdef BDEBUG
|
|
Packit |
209cc3 |
++gflag;
|
|
Packit |
209cc3 |
#else
|
|
Packit |
209cc3 |
error("libpcap and filtertest not built with optimizer debugging enabled");
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 'F':
|
|
Packit |
209cc3 |
infile = optarg;
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 'O':
|
|
Packit |
209cc3 |
Oflag = 0;
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 'm': {
|
|
Packit |
209cc3 |
bpf_u_int32 addr;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
switch (inet_pton(AF_INET, optarg, &addr)) {
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 0:
|
|
Packit |
209cc3 |
error("invalid netmask %s", optarg);
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case -1:
|
|
Packit |
209cc3 |
error("invalid netmask %s: %s", optarg,
|
|
Packit |
209cc3 |
pcap_strerror(errno));
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 1:
|
|
Packit |
209cc3 |
netmask = addr;
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
case 's': {
|
|
Packit |
209cc3 |
char *end;
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
snaplen = strtol(optarg, &end, 0);
|
|
Packit |
209cc3 |
if (optarg == end || *end != '\0'
|
|
Packit |
209cc3 |
|| snaplen < 0 || snaplen > 65535)
|
|
Packit |
209cc3 |
error("invalid snaplen %s", optarg);
|
|
Packit |
209cc3 |
else if (snaplen == 0)
|
|
Packit |
209cc3 |
snaplen = 65535;
|
|
Packit |
209cc3 |
break;
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
default:
|
|
Packit |
209cc3 |
usage();
|
|
Packit |
209cc3 |
/* NOTREACHED */
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
if (optind >= argc) {
|
|
Packit |
209cc3 |
usage();
|
|
Packit |
209cc3 |
/* NOTREACHED */
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
dlt = pcap_datalink_name_to_val(argv[optind]);
|
|
Packit |
209cc3 |
if (dlt < 0) {
|
|
Packit |
209cc3 |
dlt = (int)strtol(argv[optind], &p, 10);
|
|
Packit |
209cc3 |
if (p == argv[optind] || *p != '\0')
|
|
Packit |
209cc3 |
error("invalid data link type %s", argv[optind]);
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
if (infile)
|
|
Packit |
209cc3 |
cmdbuf = read_infile(infile);
|
|
Packit |
209cc3 |
else
|
|
Packit |
209cc3 |
cmdbuf = copy_argv(&argv[optind+1]);
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifdef BDEBUG
|
|
Packit |
209cc3 |
pcap_set_optimizer_debug(dflag);
|
|
Packit |
209cc3 |
pcap_set_print_dot_graph(gflag);
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
pd = pcap_open_dead(dlt, snaplen);
|
|
Packit |
209cc3 |
if (pd == NULL)
|
|
Packit |
209cc3 |
error("Can't open fake pcap_t");
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
if (pcap_compile(pd, &fcode, cmdbuf, Oflag, netmask) < 0)
|
|
Packit |
209cc3 |
error("%s", pcap_geterr(pd));
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
have_fcode = 1;
|
|
Packit |
209cc3 |
if (!bpf_validate(fcode.bf_insns, fcode.bf_len))
|
|
Packit |
209cc3 |
warn("Filter doesn't pass validation");
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
#ifdef BDEBUG
|
|
Packit |
209cc3 |
if (cmdbuf != NULL) {
|
|
Packit |
209cc3 |
// replace line feed with space
|
|
Packit |
209cc3 |
for (cp = cmdbuf; *cp != '\0'; ++cp) {
|
|
Packit |
209cc3 |
if (*cp == '\r' || *cp == '\n') {
|
|
Packit |
209cc3 |
*cp = ' ';
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
// only show machine code if BDEBUG defined, since dflag > 3
|
|
Packit |
209cc3 |
printf("machine codes for filter: %s\n", cmdbuf);
|
|
Packit |
209cc3 |
} else
|
|
Packit |
209cc3 |
printf("machine codes for empty filter:\n");
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
bpf_dump(&fcode, dflag);
|
|
Packit |
209cc3 |
free(cmdbuf);
|
|
Packit |
209cc3 |
if (have_fcode)
|
|
Packit |
209cc3 |
pcap_freecode (&fcode);
|
|
Packit |
209cc3 |
pcap_close(pd);
|
|
Packit |
209cc3 |
exit(0);
|
|
Packit |
209cc3 |
}
|
|
Packit |
209cc3 |
|
|
Packit |
209cc3 |
static void
|
|
Packit |
209cc3 |
usage(void)
|
|
Packit |
209cc3 |
{
|
|
Packit |
209cc3 |
(void)fprintf(stderr, "%s, with %s\n", program_name,
|
|
Packit |
209cc3 |
pcap_lib_version());
|
|
Packit |
209cc3 |
(void)fprintf(stderr,
|
|
Packit |
209cc3 |
#ifdef BDEBUG
|
|
Packit |
209cc3 |
"Usage: %s [-dgO] [ -F file ] [ -m netmask] [ -s snaplen ] dlt [ expression ]\n",
|
|
Packit |
209cc3 |
#else
|
|
Packit |
209cc3 |
"Usage: %s [-dO] [ -F file ] [ -m netmask] [ -s snaplen ] dlt [ expression ]\n",
|
|
Packit |
209cc3 |
#endif
|
|
Packit |
209cc3 |
program_name);
|
|
Packit |
209cc3 |
exit(1);
|
|
Packit |
209cc3 |
}
|