Wireshark 4.7.0
The Wireshark network protocol analyzer
Loading...
Searching...
No Matches
epan.h
Go to the documentation of this file.
1
10#ifndef __EPAN_H__
11#define __EPAN_H__
12
13#include <wsutil/feature_list.h>
14#include <epan/tvbuff.h>
15#include <epan/prefs.h>
16#include <epan/frame_data.h>
17#include <epan/register.h>
19
20#ifdef __cplusplus
21extern "C" {
22#endif /* __cplusplus */
23
32
41
48WS_DLL_PUBLIC void ws_dissector_bug(const char *format, ...)
49 G_GNUC_PRINTF(1,2);
50
57#define ws_dissector_oops(_fmt, ...) ws_dissector_bug("OOPS: " _fmt, __VA_ARGS__)
58
66
67struct epan_dfilter;
68struct epan_column_info;
69
77
92 const nstime_t *(*get_frame_ts)(struct packet_provider_data *prov, uint32_t frame_num);
93
100 const nstime_t *(*get_start_ts)(struct packet_provider_data *prov);
101
108 const nstime_t *(*get_end_ts)(struct packet_provider_data *prov);
109
118 const char *(*get_interface_name)(struct packet_provider_data *prov, uint32_t interface_id, unsigned section_number);
119
128 const char *(*get_interface_description)(struct packet_provider_data *prov, uint32_t interface_id, unsigned section_number);
129
137 wtap_block_t (*get_modified_block)(struct packet_provider_data *prov, const frame_data *fd);
138
147 int32_t (*get_process_id)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number);
148
157 const char *(*get_process_name)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number);
158
168 const uint8_t *(*get_process_uuid)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number, size_t *uuid_size);
169};
170
178/*
179Ref 1
180Epan
181Enhanced Packet ANalyzer, aka the packet analyzing engine. Source code can be found in the epan directory.
182
183Protocol-Tree - Keep data of the capture file protocol information.
184
185Dissectors - The various protocol dissectors in epan/dissectors.
186
187Plugins - Some of the protocol dissectors are implemented as plugins. Source code can be found at plugins.
188
189Display-Filters - the display filter engine at epan/dfilter
190
191*/
192
196typedef struct {
197 const char* env_var_prefix;
198 const char** col_fmt;
200 register_entity_func register_func;
201 register_entity_func handoff_func;
204
216WS_DLL_PUBLIC
217bool epan_init(register_cb cb, void *client_data, bool load_plugins, epan_app_data_t* app_data);
218
224WS_DLL_PUBLIC
226
233WS_DLL_PUBLIC
234void epan_cleanup(void);
235
236
244typedef struct {
248 void (*init)(void);
249
253 void (*post_init)(void);
254
258 void (*dissect_init)(epan_dissect_t *);
259
263 void (*dissect_cleanup)(epan_dissect_t *);
264
268 void (*cleanup)(void);
269
276 void (*register_all_protocols)(register_cb cb, void *user_data);
277
284 void (*register_all_handoffs)(register_cb cb, void *user_data);
285
289 void (*register_all_tap_listeners)(void);
291
304WS_DLL_PUBLIC void epan_register_plugin(const epan_plugin *plugin);
305
314WS_DLL_PUBLIC int epan_plugins_supported(void);
315
323void epan_conversation_init(void);
324
325
326typedef struct epan_session epan_t;
337typedef struct epan_session epan_t;
338
352WS_DLL_PUBLIC epan_t *epan_new(struct packet_provider_data *prov,
353 const struct packet_provider_funcs *funcs);
354
367WS_DLL_PUBLIC wtap_block_t epan_get_modified_block(const epan_t *session, const frame_data *fd);
368
384WS_DLL_PUBLIC const char *epan_get_interface_name(const epan_t *session, uint32_t interface_id, unsigned section_number);
385
400WS_DLL_PUBLIC const char *epan_get_interface_description(const epan_t *session, uint32_t interface_id, unsigned section_number);
401
418WS_DLL_PUBLIC int32_t epan_get_process_id(const epan_t *session, uint32_t process_info_id, unsigned section_number);
419
436WS_DLL_PUBLIC const char *epan_get_process_name(const epan_t *session, uint32_t process_info_id, unsigned section_number);
437
455WS_DLL_PUBLIC const uint8_t *epan_get_process_uuid(const epan_t *session, uint32_t process_info_id, unsigned section_number, size_t *uuid_size);
456
469const nstime_t *epan_get_frame_ts(const epan_t *session, uint32_t frame_num);
470
481const nstime_t *epan_get_start_ts(const epan_t *session);
482
492WS_DLL_PUBLIC void epan_free(epan_t *session);
493
504WS_DLL_PUBLIC const char* epan_get_version(void);
505
519WS_DLL_PUBLIC void epan_get_version_number(int *major, int *minor, int *micro);
520
529WS_DLL_PUBLIC const char* epan_get_environment_prefix(void);
530
545WS_DLL_PUBLIC
546void epan_set_always_visible(bool force);
547
556WS_DLL_PUBLIC
557void
558epan_dissect_init(epan_dissect_t *edt, epan_t *session, const bool create_proto_tree, const bool proto_tree_visible);
559
572WS_DLL_PUBLIC
574epan_dissect_new(epan_t *session, const bool create_proto_tree, const bool proto_tree_visible);
575
585WS_DLL_PUBLIC
586void
588
595WS_DLL_PUBLIC
596void
597epan_dissect_fake_protocols(epan_dissect_t *edt, const bool fake_protocols);
598
612WS_DLL_PUBLIC
613void
614epan_dissect_run(epan_dissect_t *edt, int file_type_subtype,
615 wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo);
616
633WS_DLL_PUBLIC
634void
635epan_dissect_run_with_taps(epan_dissect_t *edt, int file_type_subtype,
636 wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo);
637
653WS_DLL_PUBLIC
654void
656 frame_data *fd, struct epan_column_info *cinfo);
657
674WS_DLL_PUBLIC
675void
677 frame_data *fd, struct epan_column_info *cinfo);
678
695WS_DLL_PUBLIC
696void
698
712WS_DLL_PUBLIC
713void
715
729WS_DLL_PUBLIC
730void
732
746WS_DLL_PUBLIC
747void
749
762WS_DLL_PUBLIC
763void
764epan_dissect_fill_in_columns(epan_dissect_t *edt, const bool fill_col_exprs, const bool fill_fd_colums);
765
781WS_DLL_PUBLIC
782bool
784 const char *field_name);
785
799WS_DLL_PUBLIC
800void
802
813WS_DLL_PUBLIC
814void
816
834const char *
835epan_custom_set(epan_dissect_t *edt, GSList *ids, int occurrence, bool display_details,
836 char *result, char *expr, const int size);
837
843WS_DLL_PUBLIC
844void
846
852WS_DLL_PUBLIC
853void
855
856#ifdef __cplusplus
857}
858#endif /* __cplusplus */
859
860#endif /* __EPAN_H__ */
WS_DLL_PUBLIC void epan_dissect_init(epan_dissect_t *edt, epan_t *session, const bool create_proto_tree, const bool proto_tree_visible)
Initialize an existing single packet dissection.
Definition epan.c:649
WS_DLL_PUBLIC void epan_dissect_fake_protocols(epan_dissect_t *edt, const bool fake_protocols)
Indicate whether protocols should be faked during dissection.
Definition epan.c:720
WS_DLL_PUBLIC int32_t epan_get_process_id(const epan_t *session, uint32_t process_info_id, unsigned section_number)
Retrieve the process ID associated with a given process info record.
Definition epan.c:581
WS_DLL_PUBLIC bool epan_init(register_cb cb, void *client_data, bool load_plugins, epan_app_data_t *app_data)
Initialize the entire epan module.
Definition epan.c:266
void epan_conversation_init(void)
Initialize the table of conversations.
Definition epan.c:628
WS_DLL_PUBLIC void epan_dissect_file_run(epan_dissect_t *edt, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a dissection of file-based packet data.
Definition epan.c:757
bool wireshark_abort_on_dissector_bug
Controls whether Wireshark should abort on a dissector bug.
Definition epan.c:122
WS_DLL_PUBLIC void epan_gather_compile_info(feature_list l)
Get compile-time information for libraries used by libwireshark.
Definition epan.c:890
WS_DLL_PUBLIC void epan_dissect_cleanup(epan_dissect_t *edt)
Release resources associated with a packet dissection context.
Definition epan.c:784
WS_DLL_PUBLIC const char * epan_get_process_name(const epan_t *session, uint32_t process_info_id, unsigned section_number)
Retrieve the name of a process associated with a given process info record.
Definition epan.c:599
WS_DLL_PUBLIC epan_t * epan_new(struct packet_provider_data *prov, const struct packet_provider_funcs *funcs)
Create a new epan dissection session.
Definition epan.c:508
WS_DLL_PUBLIC const char * epan_get_interface_description(const epan_t *session, uint32_t interface_id, unsigned section_number)
Retrieve the description of a network interface.
Definition epan.c:541
WS_DLL_PUBLIC e_prefs * epan_load_settings(void)
Load all settings from the current profile that affect epan.
Definition epan.c:407
WS_DLL_PUBLIC void epan_free(epan_t *session)
Free an epan dissection session.
Definition epan.c:617
WS_DLL_PUBLIC void epan_dissect_prime_with_hfid(epan_dissect_t *edt, int hfid)
Prime a dissection context's protocol tree with a specific field or protocol.
Definition epan.c:833
WS_DLL_PUBLIC void epan_dissect_reset(epan_dissect_t *edt)
Reset a dissection context for reuse.
Definition epan.c:678
WS_DLL_PUBLIC int epan_plugins_supported(void)
Check plugin support status for libwireshark components.
Definition epan.c:249
WS_DLL_PUBLIC void epan_cleanup(void)
Clean up the entire epan module.
Definition epan.c:426
WS_DLL_PUBLIC void epan_dissect_free(epan_dissect_t *edt)
Free a single packet dissection context.
Definition epan.c:814
WS_DLL_PUBLIC void epan_dissect_fill_in_columns(epan_dissect_t *edt, const bool fill_col_exprs, const bool fill_fd_colums)
Populate packet list columns with dissection output.
Definition epan.c:861
WS_DLL_PUBLIC void epan_get_version_number(int *major, int *minor, int *micro)
Retrieve the version number of the epan library.
Definition epan.c:152
WS_DLL_PUBLIC wtap_block_t epan_get_modified_block(const epan_t *session, const frame_data *fd)
Retrieve a modified capture block associated with a specific frame.
Definition epan.c:523
WS_DLL_PUBLIC const char * epan_get_environment_prefix(void)
Retrieve the environment prefix string used by epan.
Definition epan.c:163
WS_DLL_PUBLIC bool epan_dissect_packet_contains_field(epan_dissect_t *edt, const char *field_name)
Check whether a dissected packet contains a specific named field.
Definition epan.c:868
const nstime_t * epan_get_frame_ts(const epan_t *session, uint32_t frame_num)
Retrieve the timestamp of a specific frame.
Definition epan.c:550
WS_DLL_PUBLIC void epan_dissect_prime_with_dfilter(epan_dissect_t *edt, const struct epan_dfilter *dfcode)
Prime a dissection context's protocol tree using a display filter.
WS_DLL_PUBLIC const uint8_t * epan_get_process_uuid(const epan_t *session, uint32_t process_info_id, unsigned section_number, size_t *uuid_size)
Retrieve the UUID of a process associated with a given process info record.
Definition epan.c:608
const nstime_t * epan_get_start_ts(const epan_t *session)
Retrieve the start timestamp of the capture session.
Definition epan.c:565
WS_DLL_PUBLIC void epan_dissect_run(epan_dissect_t *edt, int file_type_subtype, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a single packet dissection.
Definition epan.c:727
WS_DLL_PUBLIC void epan_gather_runtime_info(feature_list l)
Get runtime information for libraries used by libwireshark.
Definition epan.c:999
WS_DLL_PUBLIC void epan_dissect_prime_with_hfid_array(epan_dissect_t *edt, GArray *hfids)
Prime a dissection context's protocol tree with a set of fields or protocols.
Definition epan.c:839
WS_DLL_PUBLIC void ws_dissector_bug(const char *format,...)
Report a dissector bug (and optionally abort).
Definition epan.c:126
WS_DLL_PUBLIC const char * epan_get_version(void)
Retrieve the epan library's version as a string.
Definition epan.c:147
WS_DLL_PUBLIC epan_dissect_t * epan_dissect_new(epan_t *session, const bool create_proto_tree, const bool proto_tree_visible)
Create a new single packet dissection.
Definition epan.c:709
WS_DLL_PUBLIC void epan_dissect_prime_with_dfilter_print(epan_dissect_t *edt, const struct epan_dfilter *dfcode)
Prime a dissection context's protocol tree using a display filter, marking fields for print output.
bool wireshark_abort_on_too_many_items
Controls whether Wireshark should abort when too many items are added to a tree.
Definition epan.c:123
WS_DLL_PUBLIC void epan_dissect_file_run_with_taps(epan_dissect_t *edt, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a dissection of file-based packet data and invoke tap listeners.
Definition epan.c:771
WS_DLL_PUBLIC void epan_set_always_visible(bool force)
Set or unset the tree to always be visible when epan_dissect_init() is called.
Definition epan.c:640
WS_DLL_PUBLIC void epan_dissect_run_with_taps(epan_dissect_t *edt, int file_type_subtype, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a single packet dissection and invoke tap listeners.
Definition epan.c:744
const char * epan_custom_set(epan_dissect_t *edt, GSList *ids, int occurrence, bool display_details, char *result, char *expr, const int size)
Set the value of a custom column based on specified fields and expression.
Definition epan.c:851
WS_DLL_PUBLIC void epan_register_plugin(const epan_plugin *plugin)
Register an epan plugin with the dissection engine.
WS_DLL_PUBLIC const char * epan_get_interface_name(const epan_t *session, uint32_t interface_id, unsigned section_number)
Retrieve the name of a network interface.
Definition epan.c:532
GList ** feature_list
Semi-opaque handle to a list of features or dependencies.
Definition feature_list.h:33
Definition prefs.h:174
Definition plugins.c:33
Definition tap.h:82
Definition packet-bt-dht.c:99
Information about the application that wants to use epan.
Definition epan.h:196
register_entity_func register_func
Definition epan.h:200
int num_cols
Definition epan.h:199
const char * env_var_prefix
Definition epan.h:197
struct _tap_reg const * tap_reg_listeners
Definition epan.h:202
const char ** col_fmt
Definition epan.h:198
register_entity_func handoff_func
Definition epan.h:201
Definition column-info.h:62
Definition dfilter-int.h:35
Definition epan_dissect.h:28
Plugin interface for EPAN modules.
Definition epan.h:244
Definition epan.c:502
Definition nstime.h:26
Definition cfile.h:58
Structure containing pointers to functions supplied by the user of libwireshark.
Definition epan.h:84
wtap_block_t(* get_modified_block)(struct packet_provider_data *prov, const frame_data *fd)
Get a modified WTAP block for a given frame.
Definition epan.h:137
int32_t(* get_process_id)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number)
Get the process ID associated with a packet.
Definition epan.h:147
Definition wtap_opttypes.h:272
Definition wtap.h:1512