Wireshark 4.7.3
The Wireshark network protocol analyzer
Loading...
Searching...
No Matches
capture_sync.h File Reference
#include <wsutil/processes.h>

Go to the source code of this file.

Typedefs

typedef struct capture_options_tag capture_options

Functions

bool sync_pipe_start (capture_options *capture_opts, GPtrArray *capture_comments, capture_session *cap_session, struct _info_data *cap_data, void(*update_cb)(void))
 Start a new capture session.
void sync_pipe_stop (capture_session *cap_session)
 Request that the capture child stop capturing and shut down cleanly.
void sync_pipe_kill (ws_process_id fork_child)
 Forcefully terminate the capture child process as quickly as possible.
int sync_interface_set_80211_chan (const char *iface, const char *freq, const char *type, const char *center_freq1, const char *center_freq2, char **data, char **primary_msg, char **secondary_msg, void(*update_cb)(void))
 Set wireless channel using dumpcap.
int sync_if_bpf_filter_open (const char *ifname, const char *filter, int linktype, bool optimize, char **data, char **primary_msg, char **secondary_msg, void(*update_cb)(void))
 Compile a capture filter and get its BPF bytecode (in human-readable form.).
int sync_interface_list_open (char **data, char **primary_msg, char **secondary_msg, void(*update_cb)(void))
 Get an interface list using dumpcap.
int sync_if_capabilities_open (const char *ifname, bool monitor_mode, const char *auth, char **data, char **primary_msg, char **secondary_msg, void(*update_cb)(void))
 Get interface capabilities using dumpcap.
int sync_if_list_capabilities_open (GList *ifqueries, char **data, char **primary_msg, char **secondary_msg, void(*update_cb)(void))
 Start getting interface statistics using dumpcap.
int sync_interface_stats_open (int *read_fd, ws_process_id *fork_child, char **data, char **msg, void(*update_cb)(void))
 Open an interface statistics stream using dumpcap.
int sync_interface_stats_close (int *read_fd, ws_process_id *fork_child, char **msg)
 Close an interface statistics stream previously opened with dumpcap.
int sync_pipe_gets_nonblock (int pipe_fd, char *bytes, int max)
 Read a line from a pipe in non‑blocking mode.
void capture_sync_set_fetch_dumpcap_pid_cb (void(*cb)(ws_process_id pid))
 Set a callback function to to be called with the PID of the forked child.

Detailed Description

Sync mode capture (internal interface).

Will start a new Wireshark child instance which will do the actual capture work.

Function Documentation

◆ capture_sync_set_fetch_dumpcap_pid_cb()

void capture_sync_set_fetch_dumpcap_pid_cb ( void(* cb )(ws_process_id pid))
extern

Set a callback function to to be called with the PID of the forked child.

Parameters
cbCallback function that will be called with the PID of the dumpcap process.

◆ sync_if_bpf_filter_open()

int sync_if_bpf_filter_open ( const char * ifname,
const char * filter,
int linktype,
bool optimize,
char ** data,
char ** primary_msg,
char ** secondary_msg,
void(* update_cb )(void) )
extern

Compile a capture filter and get its BPF bytecode (in human-readable form.).

This is necessary on Linux because, as pcap_compile(3PCAP) says: "On Linux, if the pcap_t handle corresponds to a live packet capture, the resulting filter program may use Linux BPF extensions;" this will produce the actual filter used for a live capture as opposed to the compiled version without extensions that pcap_open_dead(3PCAP) produces. (However, it requires permissions to open the device.)

Parameters
ifnamenetwork interface name
filtercapture filter string
linktypelink layer type (-1 to use device default)
optimizewhether to optimize the filter
dataOn success, *data points to a buffer containing the dumpcap output, On failure *data is NULL
primary_msgOn success NULL, On failure points to an error message
secondary_msgOn success NULL, On failure either points to an additional error message or is NULL
update_cbupdate callback

◆ sync_if_capabilities_open()

int sync_if_capabilities_open ( const char * ifname,
bool monitor_mode,
const char * auth,
char ** data,
char ** primary_msg,
char ** secondary_msg,
void(* update_cb )(void) )
extern

Get interface capabilities using dumpcap.

Parameters
ifnameInterface name for which capabilities are requested.
monitor_modeWhether to query capabilities in monitor mode.
authAuthentication string, or NULL if unused.
dataOn success, set to dumpcap output; on failure, set to NULL.
primary_msgOn success NULL; on failure, set to an error message.
secondary_msgOn success NULL; on failure, set to an additional error message or NULL.
update_cbCallback invoked to update status.
Returns
0 on success, or -1/errno on failure.

◆ sync_if_list_capabilities_open()

int sync_if_list_capabilities_open ( GList * ifqueries,
char ** data,
char ** primary_msg,
char ** secondary_msg,
void(* update_cb )(void) )
extern

Start getting interface statistics using dumpcap.

Parameters
ifqueriesList of interface queries.
dataPointer to store additional data.
primary_msgPointer to store primary message.
secondary_msgPointer to store secondary message.
update_cbCallback function for updates.
Returns
Result code (-1 on error, otherwise on success).

◆ sync_interface_list_open()

int sync_interface_list_open ( char ** data,
char ** primary_msg,
char ** secondary_msg,
void(* update_cb )(void) )
extern

Get an interface list using dumpcap.

Parameters
dataOn success, set to dumpcap output; on failure, set to NULL.
primary_msgOn success NULL; on failure, set to an error message.
secondary_msgOn success NULL; on failure, set to an additional error message or NULL.
update_cbCallback invoked to update status.
Returns
0 on success, or -1/errno on failure.

◆ sync_interface_set_80211_chan()

int sync_interface_set_80211_chan ( const char * iface,
const char * freq,
const char * type,
const char * center_freq1,
const char * center_freq2,
char ** data,
char ** primary_msg,
char ** secondary_msg,
void(* update_cb )(void) )
extern

Set wireless channel using dumpcap.

On success, *data points to a buffer containing the dumpcap output, *primary_msg and *secondary_msg are NULL, and 0 is returned. *data must be freed with g_free().

On failure, *data is NULL, *primary_msg points to an error message, *secondary_msg either points to an additional error message or is NULL, and -1 or errno value is returned; *primary_msg, and *secondary_msg if not NULL must be freed with g_free().

Parameters
iface(monitor) network interface name
freqchannel control frequency string (in MHz)
typechannel type string (or NULL if not used)
center_freq1VHT channel center frequency (or NULL if not used)
center_freq2VHT channel center frequency 2 (or NULL if not used)
dataOn success, *data points to a buffer containing the dumpcap output, On failure *data is NULL
primary_msgOn success NULL, On failure points to an error message
secondary_msgOn success NULL, On failure either points to an additional error message or is NULL
update_cbupdate callback
Returns
0 on success

◆ sync_interface_stats_close()

int sync_interface_stats_close ( int * read_fd,
ws_process_id * fork_child,
char ** msg )
extern

Close an interface statistics stream previously opened with dumpcap.

Parameters
read_fdFile descriptor used to read statistics; closed on success.
fork_childProcess ID of the dumpcap child to terminate.
msgOn success NULL; on failure, an error message.
Returns
0 on success, or -1/errno on failure.

◆ sync_interface_stats_open()

int sync_interface_stats_open ( int * read_fd,
ws_process_id * fork_child,
char ** data,
char ** msg,
void(* update_cb )(void) )
extern

Open an interface statistics stream using dumpcap.

Parameters
read_fdOn success, set to a file descriptor for reading stats.
fork_childOn success, set to the PID of the dumpcap child process.
dataOn success, initial dumpcap output; on failure, NULL.
msgOn success NULL; on failure, an error message.
update_cbCallback invoked to update status.
Returns
0 on success, or -1/errno on failure.

◆ sync_pipe_gets_nonblock()

int sync_pipe_gets_nonblock ( int pipe_fd,
char * bytes,
int max )
extern

Read a line from a pipe in non‑blocking mode.

Attempts to read up to max bytes from pipe_fd into bytes without blocking. A terminating NUL is not guaranteed to be added.

Parameters
pipe_fdFile descriptor of the pipe to read from.
bytesBuffer into which data is read.
maxMaximum number of bytes to read.
Returns
The number of bytes read, 0 if no data is available, or -1 on error.

◆ sync_pipe_kill()

void sync_pipe_kill ( ws_process_id fork_child)
extern

Forcefully terminate the capture child process as quickly as possible.

When the user wants to stop the program, just kill the child as soon as possible

Parameters
fork_childThe process ID of the capture child to kill.

◆ sync_pipe_start()

bool sync_pipe_start ( capture_options * capture_opts,
GPtrArray * capture_comments,
capture_session * cap_session,
struct _info_data * cap_data,
void(* update_cb )(void) )
extern

Start a new capture session.

Create a capture child which is doing the real capture work. The various capture_input_... functions will be called, if something had happened.

Most of the parameters are passed through the global capture_opts.

Parameters
capture_optsthe options
capture_commentsif not NULL, a GPtrArray * to a set of comments to put in the capture file's Section Header Block if it's a pcapng file
cap_sessiona handle for the capture session
cap_dataa struct with capture info data
update_cbupdate screen
Returns
true if a capture could be started, false if not

◆ sync_pipe_stop()

void sync_pipe_stop ( capture_session * cap_session)
extern

Request that the capture child stop capturing and shut down cleanly.

When the user wants to stop capturing, gracefully close the capture child

Parameters
cap_sessionThe active capture session to be stopped.