Wireshark 4.7.3
The Wireshark network protocol analyzer
Loading...
Searching...
No Matches
wtap.h
Go to the documentation of this file.
1
8
9#ifndef __WTAP_H__
10#define __WTAP_H__
11
12#include <wireshark.h>
13#include <time.h>
14#include <wsutil/array.h>
15#include <wsutil/buffer.h>
16#include <wsutil/nstime.h>
17#include <wsutil/inet_addr.h>
18#include <wsutil/file_compressed.h>
19#include "wtap_opttypes.h"
20
21#ifdef __cplusplus
22extern "C" {
23#endif /* __cplusplus */
24
25/* Encapsulation types. Choose names that truly reflect
26 * what is contained in the packet trace file.
27 *
28 * WTAP_ENCAP_PER_PACKET is a value passed to "wtap_dump_open()" or
29 * "wtap_dump_fdopen()" to indicate that there is no single encapsulation
30 * type for all packets in the file; this may cause those routines to
31 * fail if the capture file format being written can't support that.
32 * It's also returned by "wtap_file_encap()" for capture files that
33 * don't have a single encapsulation type for all packets in the file.
34 *
35 * WTAP_ENCAP_UNKNOWN is returned by "wtap_pcap_encap_to_wtap_encap()"
36 * if it's handed an unknown encapsulation. It is also used by file
37 * types for encapsulations which are unsupported by libwiretap.
38 *
39 * WTAP_ENCAP_NONE is an initial value used by file types like pcapng
40 * that do not have a single file level encapsulation type. If and when
41 * something that indicate encapsulation is read, the encapsulation will
42 * change (possibly to WTAP_ENCAP_PER_PACKET) and appropriate IDBs will
43 * be generated. If a file type uses this value, it MUST provide IDBs
44 * (possibly fake) when the encapsulation changes; otherwise, it should
45 * return WTAP_ENCAP_UNKNOWN so that attempts to write an output file
46 * without reading the entire input file first fail gracefully.
47 *
48 * WTAP_ENCAP_FDDI_BITSWAPPED is for FDDI captures on systems where the
49 * MAC addresses you get from the hardware are bit-swapped. Ideally,
50 * the driver would tell us that, but I know of none that do, so, for
51 * now, we base it on the machine on which we're *reading* the
52 * capture, rather than on the machine on which the capture was taken
53 * (they're probably likely to be the same). We assume that they're
54 * bit-swapped on everything except for systems running Ultrix, Alpha
55 * systems, and BSD/OS systems (that's what "tcpdump" does; I guess
56 * Digital decided to bit-swap addresses in the hardware or in the
57 * driver, and I guess BSDI bit-swapped them in the driver, given that
58 * BSD/OS generally runs on Boring Old PC's). If we create a wiretap
59 * save file format, we'd use the WTAP_ENCAP values to flag the
60 * encapsulation of a packet, so there we'd at least be able to base
61 * it on the machine on which the capture was taken.
62 *
63 * WTAP_ENCAP_LINUX_ATM_CLIP is the encapsulation you get with the
64 * ATM on Linux code from <http://linux-atm.sourceforge.net/>;
65 * that code adds a DLT_ATM_CLIP DLT_ code of 19, and that
66 * encapsulation isn't the same as the DLT_ATM_RFC1483 encapsulation
67 * presumably used on some BSD systems, which we turn into
68 * WTAP_ENCAP_ATM_RFC1483.
69 *
70 * WTAP_ENCAP_NULL corresponds to DLT_NULL from "libpcap". This
71 * corresponds to
72 *
73 * 1) PPP-over-HDLC encapsulation, at least with some versions
74 * of ISDN4BSD (but not the current ones, it appears, unless
75 * I've missed something);
76 *
77 * 2) a 4-byte header containing the AF_ address family, in
78 * the byte order of the machine that saved the capture,
79 * for the packet, as used on many BSD systems for the
80 * loopback device and some other devices, or a 4-byte header
81 * containing the AF_ address family in network byte order,
82 * as used on recent OpenBSD systems for the loopback device;
83 *
84 * 3) a 4-byte header containing 2 octets of 0 and an Ethernet
85 * type in the byte order from an Ethernet header, that being
86 * what older versions of "libpcap" on Linux turn the Ethernet
87 * header for loopback interfaces into (0.6.0 and later versions
88 * leave the Ethernet header alone and make it DLT_EN10MB). */
89#define WTAP_ENCAP_NONE -2
90#define WTAP_ENCAP_PER_PACKET -1
91#define WTAP_ENCAP_UNKNOWN 0
92#define WTAP_ENCAP_ETHERNET 1
93#define WTAP_ENCAP_TOKEN_RING 2
94#define WTAP_ENCAP_SLIP 3
95#define WTAP_ENCAP_PPP 4
96#define WTAP_ENCAP_FDDI 5
97#define WTAP_ENCAP_FDDI_BITSWAPPED 6
98#define WTAP_ENCAP_RAW_IP 7
99#define WTAP_ENCAP_ARCNET 8
100#define WTAP_ENCAP_ARCNET_LINUX 9
101#define WTAP_ENCAP_ATM_RFC1483 10
102#define WTAP_ENCAP_LINUX_ATM_CLIP 11
103#define WTAP_ENCAP_LAPB 12
104#define WTAP_ENCAP_ATM_PDUS 13
105#define WTAP_ENCAP_ATM_PDUS_UNTRUNCATED 14
106#define WTAP_ENCAP_NULL 15
107#define WTAP_ENCAP_ASCEND 16
108#define WTAP_ENCAP_ISDN 17
109#define WTAP_ENCAP_IP_OVER_FC 18
110#define WTAP_ENCAP_PPP_WITH_PHDR 19
111#define WTAP_ENCAP_IEEE_802_11 20
112#define WTAP_ENCAP_IEEE_802_11_PRISM 21
113#define WTAP_ENCAP_IEEE_802_11_WITH_RADIO 22
114#define WTAP_ENCAP_IEEE_802_11_RADIOTAP 23
115#define WTAP_ENCAP_IEEE_802_11_AVS 24
116#define WTAP_ENCAP_SLL 25
117#define WTAP_ENCAP_FRELAY 26
118#define WTAP_ENCAP_FRELAY_WITH_PHDR 27
119#define WTAP_ENCAP_CHDLC 28
120#define WTAP_ENCAP_CISCO_IOS 29
121#define WTAP_ENCAP_LOCALTALK 30
122#define WTAP_ENCAP_OLD_PFLOG 31
123#define WTAP_ENCAP_HHDLC 32
124#define WTAP_ENCAP_DOCSIS 33
125#define WTAP_ENCAP_COSINE 34
126#define WTAP_ENCAP_WFLEET_HDLC 35
127#define WTAP_ENCAP_SDLC 36
128#define WTAP_ENCAP_TZSP 37
129#define WTAP_ENCAP_ENC 38
130#define WTAP_ENCAP_PFLOG 39
131#define WTAP_ENCAP_CHDLC_WITH_PHDR 40
132#define WTAP_ENCAP_BLUETOOTH_H4 41
133#define WTAP_ENCAP_MTP2 42
134#define WTAP_ENCAP_MTP3 43
135#define WTAP_ENCAP_IRDA 44
136#define WTAP_ENCAP_USER0 45
137#define WTAP_ENCAP_USER1 46
138#define WTAP_ENCAP_USER2 47
139#define WTAP_ENCAP_USER3 48
140#define WTAP_ENCAP_USER4 49
141#define WTAP_ENCAP_USER5 50
142#define WTAP_ENCAP_USER6 51
143#define WTAP_ENCAP_USER7 52
144#define WTAP_ENCAP_USER8 53
145#define WTAP_ENCAP_USER9 54
146#define WTAP_ENCAP_USER10 55
147#define WTAP_ENCAP_USER11 56
148#define WTAP_ENCAP_USER12 57
149#define WTAP_ENCAP_USER13 58
150#define WTAP_ENCAP_USER14 59
151#define WTAP_ENCAP_USER15 60
152#define WTAP_ENCAP_SYMANTEC 61
153#define WTAP_ENCAP_APPLE_IP_OVER_IEEE1394 62
154#define WTAP_ENCAP_BACNET_MS_TP 63
155#define WTAP_ENCAP_NETTL_RAW_ICMP 64
156#define WTAP_ENCAP_NETTL_RAW_ICMPV6 65
157#define WTAP_ENCAP_GPRS_LLC 66
158#define WTAP_ENCAP_JUNIPER_ATM1 67
159#define WTAP_ENCAP_JUNIPER_ATM2 68
160#define WTAP_ENCAP_REDBACK 69
161#define WTAP_ENCAP_NETTL_RAW_IP 70
162#define WTAP_ENCAP_NETTL_ETHERNET 71
163#define WTAP_ENCAP_NETTL_TOKEN_RING 72
164#define WTAP_ENCAP_NETTL_FDDI 73
165#define WTAP_ENCAP_NETTL_UNKNOWN 74
166#define WTAP_ENCAP_MTP2_WITH_PHDR 75
167#define WTAP_ENCAP_JUNIPER_PPPOE 76
168#define WTAP_ENCAP_GCOM_TIE1 77
169#define WTAP_ENCAP_GCOM_SERIAL 78
170#define WTAP_ENCAP_NETTL_X25 79
171#define WTAP_ENCAP_K12 80
172#define WTAP_ENCAP_JUNIPER_MLPPP 81
173#define WTAP_ENCAP_JUNIPER_MLFR 82
174#define WTAP_ENCAP_JUNIPER_ETHER 83
175#define WTAP_ENCAP_JUNIPER_PPP 84
176#define WTAP_ENCAP_JUNIPER_FRELAY 85
177#define WTAP_ENCAP_JUNIPER_CHDLC 86
178#define WTAP_ENCAP_JUNIPER_GGSN 87
179#define WTAP_ENCAP_LINUX_LAPD 88
180#define WTAP_ENCAP_CATAPULT_DCT2000 89
181#define WTAP_ENCAP_BER 90
182#define WTAP_ENCAP_JUNIPER_VP 91
183#define WTAP_ENCAP_USB_FREEBSD 92
184#define WTAP_ENCAP_IEEE802_16_MAC_CPS 93
185#define WTAP_ENCAP_NETTL_RAW_TELNET 94
186#define WTAP_ENCAP_USB_LINUX 95
187#define WTAP_ENCAP_MPEG 96
188#define WTAP_ENCAP_PPI 97
189#define WTAP_ENCAP_ERF 98
190#define WTAP_ENCAP_BLUETOOTH_H4_WITH_PHDR 99
191#define WTAP_ENCAP_SITA 100
192#define WTAP_ENCAP_SCCP 101
193#define WTAP_ENCAP_BLUETOOTH_HCI 102 /*raw packets without a transport layer header e.g. H4*/
194#define WTAP_ENCAP_IPMB_KONTRON 103
195#define WTAP_ENCAP_IEEE802_15_4 104
196#define WTAP_ENCAP_X2E_XORAYA 105
197#define WTAP_ENCAP_FLEXRAY 106
198#define WTAP_ENCAP_LIN 107
199#define WTAP_ENCAP_MOST 108
200#define WTAP_ENCAP_CAN20B 109
201#define WTAP_ENCAP_LAYER1_EVENT 110
202#define WTAP_ENCAP_X2E_SERIAL 111
203#define WTAP_ENCAP_I2C_LINUX 112
204#define WTAP_ENCAP_IEEE802_15_4_NONASK_PHY 113
205#define WTAP_ENCAP_TNEF 114
206#define WTAP_ENCAP_USB_LINUX_MMAPPED 115
207#define WTAP_ENCAP_GSM_UM 116
208#define WTAP_ENCAP_DPNSS 117
209#define WTAP_ENCAP_PACKETLOGGER 118
210#define WTAP_ENCAP_NSTRACE_1_0 119
211#define WTAP_ENCAP_NSTRACE_2_0 120
212#define WTAP_ENCAP_FIBRE_CHANNEL_FC2 121
213#define WTAP_ENCAP_FIBRE_CHANNEL_FC2_WITH_FRAME_DELIMS 122
214#define WTAP_ENCAP_JPEG_JFIF 123 /* obsoleted by WTAP_ENCAP_MIME*/
215#define WTAP_ENCAP_IPNET 124
216#define WTAP_ENCAP_SOCKETCAN 125
217#define WTAP_ENCAP_IEEE_802_11_NETMON 126
218#define WTAP_ENCAP_IEEE802_15_4_NOFCS 127
219#define WTAP_ENCAP_RAW_IPFIX 128
220#define WTAP_ENCAP_RAW_IP4 129
221#define WTAP_ENCAP_RAW_IP6 130
222#define WTAP_ENCAP_LAPD 131
223#define WTAP_ENCAP_DVBCI 132
224#define WTAP_ENCAP_MUX27010 133
225#define WTAP_ENCAP_MIME 134
226#define WTAP_ENCAP_NETANALYZER 135
227#define WTAP_ENCAP_NETANALYZER_TRANSPARENT 136
228#define WTAP_ENCAP_IP_OVER_IB_SNOOP 137
229#define WTAP_ENCAP_MPEG_2_TS 138
230#define WTAP_ENCAP_PPP_ETHER 139
231#define WTAP_ENCAP_NFC_LLCP 140
232#define WTAP_ENCAP_NFLOG 141
233#define WTAP_ENCAP_V5_EF 142
234#define WTAP_ENCAP_BACNET_MS_TP_WITH_PHDR 143
235#define WTAP_ENCAP_IXVERIWAVE 144
236#define WTAP_ENCAP_SDH 145
237#define WTAP_ENCAP_DBUS 146
238#define WTAP_ENCAP_AX25_KISS 147
239#define WTAP_ENCAP_AX25 148
240#define WTAP_ENCAP_SCTP 149
241#define WTAP_ENCAP_INFINIBAND 150
242#define WTAP_ENCAP_JUNIPER_SVCS 151
243#define WTAP_ENCAP_USBPCAP 152
244#define WTAP_ENCAP_RTAC_SERIAL 153
245#define WTAP_ENCAP_BLUETOOTH_LE_LL 154
246#define WTAP_ENCAP_WIRESHARK_UPPER_PDU 155
247#define WTAP_ENCAP_STANAG_4607 156
248#define WTAP_ENCAP_STANAG_5066_D_PDU 157
249#define WTAP_ENCAP_NETLINK 158
250#define WTAP_ENCAP_BLUETOOTH_LINUX_MONITOR 159
251#define WTAP_ENCAP_BLUETOOTH_BREDR_BB 160
252#define WTAP_ENCAP_BLUETOOTH_LE_LL_WITH_PHDR 161
253#define WTAP_ENCAP_NSTRACE_3_0 162
254#define WTAP_ENCAP_LOGCAT 163
255#define WTAP_ENCAP_LOGCAT_BRIEF 164
256#define WTAP_ENCAP_LOGCAT_PROCESS 165
257#define WTAP_ENCAP_LOGCAT_TAG 166
258#define WTAP_ENCAP_LOGCAT_THREAD 167
259#define WTAP_ENCAP_LOGCAT_TIME 168
260#define WTAP_ENCAP_LOGCAT_THREADTIME 169
261#define WTAP_ENCAP_LOGCAT_LONG 170
262#define WTAP_ENCAP_PKTAP 171
263#define WTAP_ENCAP_EPON 172
264#define WTAP_ENCAP_IPMI_TRACE 173
265#define WTAP_ENCAP_LOOP 174
266#define WTAP_ENCAP_JSON 175
267#define WTAP_ENCAP_NSTRACE_3_5 176
268#define WTAP_ENCAP_ISO14443 177
269#define WTAP_ENCAP_GFP_T 178
270#define WTAP_ENCAP_GFP_F 179
271#define WTAP_ENCAP_IP_OVER_IB_PCAP 180
272#define WTAP_ENCAP_JUNIPER_VN 181
273#define WTAP_ENCAP_USB_DARWIN 182
274#define WTAP_ENCAP_LORATAP 183
275#define WTAP_ENCAP_3MB_ETHERNET 184
276#define WTAP_ENCAP_VSOCK 185
277#define WTAP_ENCAP_NORDIC_BLE 186
278#define WTAP_ENCAP_NETMON_NET_NETEVENT 187
279#define WTAP_ENCAP_NETMON_HEADER 188
280#define WTAP_ENCAP_NETMON_NET_FILTER 189
281#define WTAP_ENCAP_NETMON_NETWORK_INFO_EX 190
282#define WTAP_ENCAP_MA_WFP_CAPTURE_V4 191
283#define WTAP_ENCAP_MA_WFP_CAPTURE_V6 192
284#define WTAP_ENCAP_MA_WFP_CAPTURE_2V4 193
285#define WTAP_ENCAP_MA_WFP_CAPTURE_2V6 194
286#define WTAP_ENCAP_MA_WFP_CAPTURE_AUTH_V4 195
287#define WTAP_ENCAP_MA_WFP_CAPTURE_AUTH_V6 196
288#define WTAP_ENCAP_JUNIPER_ST 197
289#define WTAP_ENCAP_ETHERNET_MPACKET 198
290#define WTAP_ENCAP_DOCSIS31_XRA31 199
291#define WTAP_ENCAP_DPAUXMON 200
292#define WTAP_ENCAP_RUBY_MARSHAL 201
293#define WTAP_ENCAP_RFC7468 202
294#define WTAP_ENCAP_SYSTEMD_JOURNAL 203 /* Event, not a packet */
295#define WTAP_ENCAP_EBHSCR 204
296#define WTAP_ENCAP_VPP 205
297#define WTAP_ENCAP_IEEE802_15_4_TAP 206
298#define WTAP_ENCAP_LOG_3GPP 207
299#define WTAP_ENCAP_USB_2_0 208
300#define WTAP_ENCAP_MP4 209
301#define WTAP_ENCAP_SLL2 210
302#define WTAP_ENCAP_ZWAVE_SERIAL 211
303#define WTAP_ENCAP_ETW 212
304#define WTAP_ENCAP_ERI_ENB_LOG 213
305#define WTAP_ENCAP_ZBNCP 214
306#define WTAP_ENCAP_USB_2_0_LOW_SPEED 215
307#define WTAP_ENCAP_USB_2_0_FULL_SPEED 216
308#define WTAP_ENCAP_USB_2_0_HIGH_SPEED 217
309#define WTAP_ENCAP_AUTOSAR_DLT 218
310#define WTAP_ENCAP_AUERSWALD_LOG 219
311#define WTAP_ENCAP_ATSC_ALP 220
312#define WTAP_ENCAP_FIRA_UCI 221
313#define WTAP_ENCAP_SILABS_DEBUG_CHANNEL 222
314#define WTAP_ENCAP_MDB 223
315#define WTAP_ENCAP_EMS 224
316#define WTAP_ENCAP_DECT_NR 225
317#define WTAP_ENCAP_MMODULE 226
318#define WTAP_ENCAP_PROCMON 227
319#define WTAP_ENCAP_ZWAVE_TAP 228
320#define WTAP_ENCAP_DECT_NR_TAP 229
321
322/* After adding new item here, please also add new item to encap_table_base array */
323
324#define WTAP_NUM_ENCAP_TYPES wtap_get_num_encap_types()
325
326/* Value to be used as a file type/subtype value if the type is unknown */
327#define WTAP_FILE_TYPE_SUBTYPE_UNKNOWN -1
328
329/* timestamp precision (currently only these values are supported) */
330#define WTAP_TSPREC_UNKNOWN -2
331#define WTAP_TSPREC_PER_PACKET -1
332
333/*
334 * These values are the number of digits of precision after the integral part.
335 * They're the same as WS_TSPREC values; we define them here so that
336 * tools/make-enums.py sees them.
337 */
338#define WTAP_TSPREC_SEC 0
339#define WTAP_TSPREC_100_MSEC 1
340#define WTAP_TSPREC_DSEC 1
341#define WTAP_TSPREC_10_MSEC 2
342#define WTAP_TSPREC_CSEC 2
343#define WTAP_TSPREC_MSEC 3
344#define WTAP_TSPREC_100_USEC 4
345#define WTAP_TSPREC_10_USEC 5
346#define WTAP_TSPREC_USEC 6
347#define WTAP_TSPREC_100_NSEC 7
348#define WTAP_TSPREC_10_NSEC 8
349#define WTAP_TSPREC_NSEC 9
350/* if you add to the above, update wtap_tsprec_string() */
351
352/*
353 * Maximum packet sizes.
354 *
355 * For most link-layer types, we use 262144, which is currently
356 * libpcap's MAXIMUM_SNAPLEN.
357 *
358 * For WTAP_ENCAP_DBUS, the maximum is 128MiB, as per
359 *
360 * https://dbus.freedesktop.org/doc/dbus-specification.html#message-protocol-messages
361 *
362 * For WTAP_ENCAP_EBHSCR, the maximum is 8MiB, as per
363 *
364 * https://www.elektrobit.com/ebhscr
365 *
366 * For WTAP_ENCAP_USBPCAP, the maximum is 128MiB, as per
367 *
368 * https://gitlab.com/wireshark/wireshark/-/issues/15985
369 *
370 * We don't want to write out files that specify a maximum packet size
371 * greater than 262144 if we don't have to, as software reading those
372 * files might allocate a buffer much larger than necessary, wasting memory.
373 */
374#define WTAP_MAX_PACKET_SIZE_STANDARD 262144U
375#define WTAP_MAX_PACKET_SIZE_USBPCAP (128U*1024U*1024U)
376#define WTAP_MAX_PACKET_SIZE_EBHSCR (32U*1024U*1024U)
377#define WTAP_MAX_PACKET_SIZE_DBUS (128U*1024U*1024U)
378
379/*
380 * "Pseudo-headers" are used to supply to the clients of wiretap
381 * per-packet information that's not part of the packet payload
382 * proper.
383 *
384 * NOTE: do not use pseudo-header structures to hold information
385 * used by the code to read a particular capture file type; to
386 * keep that sort of state information, define a private structure
387 * to hold that information in your code, and allocate one of those
388 * structures and set the "priv" member of the wth structure to
389 * point to the allocated structure in the "open" routine for that
390 * capture file type if the open succeeds. See various other capture
391 * file type handlers for examples of that.
392 */
393
394
398struct eth_phdr {
400};
401
402#define FROM_DCE 0x80
403
408 uint8_t flags;
409};
410
414struct isdn_phdr {
415 bool uton;
416 uint8_t channel;
417};
418
419/* Packet "pseudo-header" for ATM capture files.
420 Not all of this information is supplied by all capture types.
421 These originally came from the Network General (DOS-based)
422 ATM Sniffer file format, but we've added some additional
423 items. */
424
425/*
426 * Status bits.
427 */
428#define ATM_RAW_CELL 0x01 /* true if the packet is a single cell */
429#define ATM_NO_HEC 0x02 /* true if the cell has HEC stripped out */
430#define ATM_AAL2_NOPHDR 0x04 /* true if the AAL2 PDU has no pseudo-header */
431#define ATM_REASSEMBLY_ERROR 0x08 /* true if this is an incompletely-reassembled PDU */
432
433/*
434 * AAL types.
435 */
436#define AAL_UNKNOWN 0 /* AAL unknown */
437#define AAL_1 1 /* AAL1 */
438#define AAL_2 2 /* AAL2 */
439#define AAL_3_4 3 /* AAL3/4 */
440#define AAL_5 4 /* AAL5 */
441#define AAL_USER 5 /* User AAL */
442#define AAL_SIGNALLING 6 /* Signaling AAL */
443#define AAL_OAMCELL 7 /* OAM cell */
444
445/*
446 * Traffic types.
447 */
448#define TRAF_UNKNOWN 0 /* Unknown */
449#define TRAF_LLCMX 1 /* LLC multiplexed (RFC 1483) */
450#define TRAF_VCMX 2 /* VC multiplexed (RFC 1483) */
451#define TRAF_LANE 3 /* LAN Emulation */
452#define TRAF_ILMI 4 /* ILMI */
453#define TRAF_FR 5 /* Frame Relay */
454#define TRAF_SPANS 6 /* FORE SPANS */
455#define TRAF_IPSILON 7 /* Ipsilon */
456#define TRAF_UMTS_FP 8 /* UMTS Frame Protocol */
457#define TRAF_GPRS_NS 9 /* GPRS Network Services */
458#define TRAF_SSCOP 10 /* SSCOP */
459
460/*
461 * Traffic subtypes.
462 */
463#define TRAF_ST_UNKNOWN 0 /* Unknown */
464
465/*
466 * For TRAF_VCMX:
467 */
468#define TRAF_ST_VCMX_802_3_FCS 1 /* 802.3 with an FCS */
469#define TRAF_ST_VCMX_802_4_FCS 2 /* 802.4 with an FCS */
470#define TRAF_ST_VCMX_802_5_FCS 3 /* 802.5 with an FCS */
471#define TRAF_ST_VCMX_FDDI_FCS 4 /* FDDI with an FCS */
472#define TRAF_ST_VCMX_802_6_FCS 5 /* 802.6 with an FCS */
473#define TRAF_ST_VCMX_802_3 7 /* 802.3 without an FCS */
474#define TRAF_ST_VCMX_802_4 8 /* 802.4 without an FCS */
475#define TRAF_ST_VCMX_802_5 9 /* 802.5 without an FCS */
476#define TRAF_ST_VCMX_FDDI 10 /* FDDI without an FCS */
477#define TRAF_ST_VCMX_802_6 11 /* 802.6 without an FCS */
478#define TRAF_ST_VCMX_FRAGMENTS 12 /* Fragments */
479#define TRAF_ST_VCMX_BPDU 13 /* BPDU */
480
481/*
482 * For TRAF_LANE:
483 */
484#define TRAF_ST_LANE_LE_CTRL 1 /* LANE: LE Ctrl */
485#define TRAF_ST_LANE_802_3 2 /* LANE: 802.3 */
486#define TRAF_ST_LANE_802_5 3 /* LANE: 802.5 */
487#define TRAF_ST_LANE_802_3_MC 4 /* LANE: 802.3 multicast */
488#define TRAF_ST_LANE_802_5_MC 5 /* LANE: 802.5 multicast */
489
490/*
491 * For TRAF_IPSILON:
492 */
493#define TRAF_ST_IPSILON_FT0 1 /* Ipsilon: Flow Type 0 */
494#define TRAF_ST_IPSILON_FT1 2 /* Ipsilon: Flow Type 1 */
495#define TRAF_ST_IPSILON_FT2 3 /* Ipsilon: Flow Type 2 */
496
500struct atm_phdr {
501 uint32_t flags;
502 uint8_t aal;
503 uint8_t type;
504 uint8_t subtype;
505 uint16_t vpi;
506 uint16_t vci;
507 uint8_t aal2_cid;
508 uint16_t channel;
509 uint16_t cells;
510 uint16_t aal5t_u2u;
511 uint16_t aal5t_len;
512 uint32_t aal5t_chksum;
513};
514
515/* Packet "pseudo-header" for the output from "wandsession", "wannext",
516 "wandisplay", and similar commands on Lucent/Ascend access equipment. */
517
518#define ASCEND_MAX_STR_LEN 64
519
520#define ASCEND_PFX_WDS_X 1
521#define ASCEND_PFX_WDS_R 2
522#define ASCEND_PFX_WDD 3
523#define ASCEND_PFX_ISDN_X 4
524#define ASCEND_PFX_ISDN_R 5
525#define ASCEND_PFX_ETHER 6
526
531 uint16_t type;
532 char user[ASCEND_MAX_STR_LEN];
533 uint32_t sess;
534 char call_num[ASCEND_MAX_STR_LEN];
535 uint32_t chunk;
536 uint32_t task;
537};
538
542struct p2p_phdr {
543 bool sent;
544};
545
546/*
547 * Packet "pseudo-header" information for 802.11.
548 * Radio information is only present in this form for
549 * WTAP_ENCAP_IEEE_802_11_WITH_RADIO. This is used for file formats in
550 * which the radio information isn't provided as a pseudo-header in the
551 * packet data. It is also used by the dissectors for the pseudo-headers
552 * in the packet data to supply radio information, in a form independent
553 * of the file format and pseudo-header format, to the "802.11 radio"
554 * dissector.
555 *
556 * Signal strength, etc. information:
557 *
558 * Raw signal strength can be measured in milliwatts.
559 * It can also be represented as dBm, which is 10 times the log base 10
560 * of the signal strength in mW.
561 *
562 * The Receive Signal Strength Indicator is an integer in the range 0 to 255.
563 * The actual RSSI value for a given signal strength is dependent on the
564 * vendor (and perhaps on the adapter). The maximum possible RSSI value
565 * is also dependent on the vendor and perhaps the adapter.
566 *
567 * The signal strength can be represented as a percentage, which is 100
568 * times the ratio of the RSSI and the maximum RSSI.
569 */
570
571/*
572 * PHY types.
573 */
574#define PHDR_802_11_PHY_UNKNOWN 0 /* PHY not known */
575#define PHDR_802_11_PHY_11_FHSS 1 /* 802.11 FHSS */
576#define PHDR_802_11_PHY_11_IR 2 /* 802.11 IR */
577#define PHDR_802_11_PHY_11_DSSS 3 /* 802.11 DSSS */
578#define PHDR_802_11_PHY_11B 4 /* 802.11b */
579#define PHDR_802_11_PHY_11A 5 /* 802.11a */
580#define PHDR_802_11_PHY_11G 6 /* 802.11g */
581#define PHDR_802_11_PHY_11N 7 /* 802.11n */
582#define PHDR_802_11_PHY_11AC 8 /* 802.11ac */
583#define PHDR_802_11_PHY_11AD 9 /* 802.11ad */
584#define PHDR_802_11_PHY_11AH 10 /* 802.11ah */
585#define PHDR_802_11_PHY_11AX 11 /* 802.11ax */
586#define PHDR_802_11_PHY_11BE 12 /* 802.11be - EHT */
587
588/*
589 * PHY-specific information.
590 */
591
596 unsigned has_hop_set : 1;
597 unsigned has_hop_pattern : 1;
598 unsigned has_hop_index : 1;
599
600 uint8_t hop_set;
601 uint8_t hop_pattern;
602 uint8_t hop_index;
603};
604
605
610 unsigned has_short_preamble : 1;
611
613};
614
615
620 unsigned has_channel_type : 1;
621 unsigned has_turbo_type : 1;
622
623 unsigned channel_type : 2;
624 unsigned turbo_type : 2;
625};
626
627/*
628 * Channel type values.
629 */
630#define PHDR_802_11A_CHANNEL_TYPE_NORMAL 0
631#define PHDR_802_11A_CHANNEL_TYPE_HALF_CLOCKED 1
632#define PHDR_802_11A_CHANNEL_TYPE_QUARTER_CLOCKED 2
633
634/*
635 * "Turbo" is an Atheros proprietary extension with 40 MHz-wide channels.
636 * It can be dynamic or static.
637 *
638 * See
639 *
640 * http://wifi-insider.com/atheros/turbo.htm
641 */
642#define PHDR_802_11A_TURBO_TYPE_NORMAL 0
643#define PHDR_802_11A_TURBO_TYPE_TURBO 1 /* If we don't know whether it's static or dynamic */
644#define PHDR_802_11A_TURBO_TYPE_DYNAMIC_TURBO 2
645#define PHDR_802_11A_TURBO_TYPE_STATIC_TURBO 3
646
655 unsigned has_mode : 1;
656
657 uint32_t mode;
658};
659
660/*
661 * Mode values.
662 */
663#define PHDR_802_11G_MODE_NORMAL 0
664#define PHDR_802_11G_MODE_SUPER_G 1 /* Atheros Super G */
665
670 unsigned has_mcs_index : 1;
671 unsigned has_bandwidth : 1;
672 unsigned has_short_gi : 1;
673 unsigned has_greenfield : 1;
674 unsigned has_fec : 1;
675 unsigned has_stbc_streams : 1;
676 unsigned has_ness : 1;
677
678 uint16_t mcs_index;
679 unsigned bandwidth;
680 unsigned short_gi : 1;
681 unsigned greenfield : 1;
682 unsigned fec : 1;
683 unsigned stbc_streams : 2;
684 unsigned ness;
685};
686
687/*
688 * Bandwidth values; used for both 11n and 11ac.
689 */
690#define PHDR_802_11_BANDWIDTH_20_MHZ 0 /* 20 MHz */
691#define PHDR_802_11_BANDWIDTH_40_MHZ 1 /* 40 MHz */
692#define PHDR_802_11_BANDWIDTH_20_20L 2 /* 20 + 20L, 40 MHz */
693#define PHDR_802_11_BANDWIDTH_20_20U 3 /* 20 + 20U, 40 MHz */
694#define PHDR_802_11_BANDWIDTH_80_MHZ 4 /* 80 MHz */
695#define PHDR_802_11_BANDWIDTH_40_40L 5 /* 40 + 40L MHz, 80 MHz */
696#define PHDR_802_11_BANDWIDTH_40_40U 6 /* 40 + 40U MHz, 80 MHz */
697#define PHDR_802_11_BANDWIDTH_20LL 7 /* ???, 80 MHz */
698#define PHDR_802_11_BANDWIDTH_20LU 8 /* ???, 80 MHz */
699#define PHDR_802_11_BANDWIDTH_20UL 9 /* ???, 80 MHz */
700#define PHDR_802_11_BANDWIDTH_20UU 10 /* ???, 80 MHz */
701#define PHDR_802_11_BANDWIDTH_160_MHZ 11 /* 160 MHz */
702#define PHDR_802_11_BANDWIDTH_80_80L 12 /* 80 + 80L, 160 MHz */
703#define PHDR_802_11_BANDWIDTH_80_80U 13 /* 80 + 80U, 160 MHz */
704#define PHDR_802_11_BANDWIDTH_40LL 14 /* ???, 160 MHz */
705#define PHDR_802_11_BANDWIDTH_40LU 15 /* ???, 160 MHz */
706#define PHDR_802_11_BANDWIDTH_40UL 16 /* ???, 160 MHz */
707#define PHDR_802_11_BANDWIDTH_40UU 17 /* ???, 160 MHz */
708#define PHDR_802_11_BANDWIDTH_20LLL 18 /* ???, 160 MHz */
709#define PHDR_802_11_BANDWIDTH_20LLU 19 /* ???, 160 MHz */
710#define PHDR_802_11_BANDWIDTH_20LUL 20 /* ???, 160 MHz */
711#define PHDR_802_11_BANDWIDTH_20LUU 21 /* ???, 160 MHz */
712#define PHDR_802_11_BANDWIDTH_20ULL 22 /* ???, 160 MHz */
713#define PHDR_802_11_BANDWIDTH_20ULU 23 /* ???, 160 MHz */
714#define PHDR_802_11_BANDWIDTH_20UUL 24 /* ???, 160 MHz */
715#define PHDR_802_11_BANDWIDTH_20UUU 25 /* ???, 160 MHz */
716
721 unsigned has_stbc : 1;
723 unsigned has_short_gi : 1;
726 unsigned has_beamformed : 1;
727 unsigned has_bandwidth : 1;
728 unsigned has_fec : 1;
729 unsigned has_group_id : 1;
730 unsigned has_partial_aid : 1;
731
732 unsigned stbc : 1;
733 unsigned txop_ps_not_allowed : 1;
734 unsigned short_gi : 1;
737 unsigned beamformed : 1;
738 uint8_t bandwidth;
739 uint8_t mcs[4];
740 uint8_t nss[4];
741 uint8_t fec;
742 uint8_t group_id;
743 uint16_t partial_aid;
744};
745
746/*
747 * 802.11ad.
748 */
749
750/*
751 * Min and Max frequencies for 802.11ad and a macro for checking for 802.11ad.
752 */
753
754#define PHDR_802_11AD_MIN_FREQUENCY 57000
755#define PHDR_802_11AD_MAX_FREQUENCY 71000
756
757#define IS_80211AD(frequency) (((frequency) >= PHDR_802_11AD_MIN_FREQUENCY) &&\
758 ((frequency) <= PHDR_802_11AD_MAX_FREQUENCY))
759
764 unsigned has_mcs_index : 1;
765
766 uint8_t mcs;
767};
768
769
774 unsigned has_mcs_index : 1;
775 unsigned has_bwru : 1;
776 unsigned has_gi : 1;
777
778 uint8_t nsts : 4;
779 uint8_t mcs : 4;
780 uint8_t bwru : 4;
781 uint8_t gi : 2;
782};
783
784
789 unsigned sta_id_known : 1;
790 unsigned mcs_known : 1;
791 unsigned coding_known : 1;
792 unsigned rsv_known : 1;
793 unsigned nsts_known : 1;
794 unsigned bf_known : 1;
795 unsigned spatial_config_known : 1;
796 unsigned data_for_this_user : 1;
797 unsigned sta_id : 11;
798 unsigned ldpc_coding : 1;
799 unsigned mcs : 4;
800 unsigned nsts : 4;
801 unsigned rsv : 1;
802 unsigned beamform : 1;
803 unsigned rsv2 : 2;
804};
805
806#define PHDR_802_11BE_MAX_USERS 4
807
812 unsigned has_ru_mru_size : 1;
813 unsigned has_gi : 1;
814 unsigned has_bandwidth : 1;
815
816 uint8_t bandwidth;
817 uint8_t ru_mru_size : 4;
818 uint8_t gi : 2;
819 uint8_t num_users;
821};
822
823
845
851 unsigned decrypted : 1;
852 unsigned datapad : 1;
853 unsigned no_a_msdus : 1;
854 unsigned phy;
856
857 unsigned has_channel : 1;
858 unsigned has_frequency : 1;
859 unsigned has_data_rate : 1;
860 unsigned has_signal_percent : 1;
861 unsigned has_noise_percent : 1;
862 unsigned has_signal_dbm : 1;
863 unsigned has_noise_dbm : 1;
864 unsigned has_signal_db : 1;
865 unsigned has_noise_db : 1;
866 unsigned has_tsf_timestamp : 1;
867 unsigned has_aggregate_info : 1;
869
870 uint16_t channel;
871 uint32_t frequency;
872 uint16_t data_rate;
875 int8_t signal_dbm;
876 int8_t noise_dbm;
877 uint8_t signal_db;
878 uint8_t noise_db;
879 uint64_t tsf_timestamp;
881 uint32_t aggregate_id;
883};
884
885/*
886 * A-MPDU flags.
887 */
888#define PHDR_802_11_LAST_PART_OF_A_MPDU 0x00000001 /* this is the last part of an A-MPDU */
889#define PHDR_802_11_A_MPDU_DELIM_CRC_ERROR 0x00000002 /* delimiter CRC error after this part */
890
891/*
892 * Zero-length PSDU types.
893 */
894#define PHDR_802_11_SOUNDING_PSDU 0 /* sounding PPDU */
895#define PHDR_802_11_DATA_NOT_CAPTURED 1 /* data not captured, (e.g. multi-user PPDU) */
896#define PHDR_802_11_0_LENGTH_PSDU_VENDOR_SPECIFIC 0xff
897
898/* Packet "pseudo-header" for the output from CoSine L2 debug output. */
899
900#define COSINE_MAX_IF_NAME_LEN 128
901
902#define COSINE_ENCAP_TEST 1
903#define COSINE_ENCAP_PPoATM 2
904#define COSINE_ENCAP_PPoFR 3
905#define COSINE_ENCAP_ATM 4
906#define COSINE_ENCAP_FR 5
907#define COSINE_ENCAP_HDLC 6
908#define COSINE_ENCAP_PPP 7
909#define COSINE_ENCAP_ETH 8
910#define COSINE_ENCAP_UNKNOWN 99
911
912#define COSINE_DIR_TX 1
913#define COSINE_DIR_RX 2
914
919 uint8_t encap;
920 uint8_t direction;
921 char if_name[COSINE_MAX_IF_NAME_LEN];
922 uint16_t pro;
923 uint16_t off;
924 uint16_t pri;
925 uint16_t rm;
926 uint16_t err;
927};
928
929/* Packet "pseudo-header" for IrDA capture files. */
930
931/*
932 * Direction of the packet
933 */
934#define IRDA_INCOMING 0x0000
935#define IRDA_OUTGOING 0x0004
936
937/*
938 * "Inline" log messages produced by IrCOMM2k on Windows
939 */
940#define IRDA_LOG_MESSAGE 0x0100 /* log message */
941#define IRDA_MISSED_MSG 0x0101 /* missed log entry or frame */
942
943/*
944 * Differentiate between frames and log messages
945 */
946#define IRDA_CLASS_FRAME 0x0000
947#define IRDA_CLASS_LOG 0x0100
948#define IRDA_CLASS_MASK 0xFF00
949
953struct irda_phdr {
954 uint16_t pkttype;
955};
956
961 uint16_t subsys;
962 uint32_t devid;
963 uint32_t kind;
964 int32_t pid;
965 uint32_t uid;
966};
967
968/* Packet "pseudo-header" for MTP2 files. */
969
970#define MTP2_ANNEX_A_NOT_USED 0
971#define MTP2_ANNEX_A_USED 1
972#define MTP2_ANNEX_A_USED_UNKNOWN 2
973
977struct mtp2_phdr {
978 uint8_t sent;
979 uint8_t annex_a_used;
980 uint16_t link_number;
981};
982
990typedef union {
996 struct {
997 uint16_t vp;
998 uint16_t vc;
999 uint16_t cid;
1000 } atm;
1001
1008 uint32_t ds0mask;
1010
1014struct k12_phdr {
1015 uint32_t input;
1016 const char *input_name;
1017 const char *stack_file;
1018 uint32_t input_type;
1020 uint8_t *extra_info;
1021 uint32_t extra_length;
1022 void *stuff;
1023};
1024
1025#define K12_PORT_DS0S 0x00010008
1026#define K12_PORT_DS1 0x00100008
1027#define K12_PORT_ATMPVC 0x01020000
1028
1037 uint16_t pkttype;
1038 uint8_t we_network;
1039};
1040
1049 union {
1051 struct atm_phdr atm;
1052 struct p2p_phdr p2p;
1053 } inner_pseudo_header;
1054
1055 int64_t seek_off;
1056 struct wtap *wth;
1057};
1058
1062struct erf_phdr {
1063 uint64_t ts;
1064 uint8_t type;
1065 uint8_t flags;
1066 uint16_t rlen;
1067 uint16_t lctr;
1068 uint16_t wlen;
1069};
1070
1074struct erf_ehdr {
1075 uint64_t ehdr;
1076};
1077
1078#define MAX_ERF_EHDR 16
1079
1084 uint8_t offset;
1085 uint8_t pad;
1086};
1087
1098
1100
1106 union {
1108 uint32_t mc_hdr;
1109 uint32_t aal2_hdr;
1111};
1112
1113#define SITA_FRAME_DIR_TXED (0x00) /* values of sita_phdr.flags */
1114#define SITA_FRAME_DIR_RXED (0x01)
1115#define SITA_FRAME_DIR (0x01) /* mask */
1116#define SITA_ERROR_NO_BUFFER (0x80)
1117
1118#define SITA_SIG_DSR (0x01) /* values of sita_phdr.signals */
1119#define SITA_SIG_DTR (0x02)
1120#define SITA_SIG_CTS (0x04)
1121#define SITA_SIG_RTS (0x08)
1122#define SITA_SIG_DCD (0x10)
1123#define SITA_SIG_UNDEF1 (0x20)
1124#define SITA_SIG_UNDEF2 (0x40)
1125#define SITA_SIG_UNDEF3 (0x80)
1126
1127#define SITA_ERROR_TX_UNDERRUN (0x01) /* values of sita_phdr.errors2 (if SITA_FRAME_DIR_TXED) */
1128#define SITA_ERROR_TX_CTS_LOST (0x02)
1129#define SITA_ERROR_TX_UART_ERROR (0x04)
1130#define SITA_ERROR_TX_RETX_LIMIT (0x08)
1131#define SITA_ERROR_TX_UNDEF1 (0x10)
1132#define SITA_ERROR_TX_UNDEF2 (0x20)
1133#define SITA_ERROR_TX_UNDEF3 (0x40)
1134#define SITA_ERROR_TX_UNDEF4 (0x80)
1135
1136#define SITA_ERROR_RX_FRAMING (0x01) /* values of sita_phdr.errors1 (if SITA_FRAME_DIR_RXED) */
1137#define SITA_ERROR_RX_PARITY (0x02)
1138#define SITA_ERROR_RX_COLLISION (0x04)
1139#define SITA_ERROR_RX_FRAME_LONG (0x08)
1140#define SITA_ERROR_RX_FRAME_SHORT (0x10)
1141#define SITA_ERROR_RX_UNDEF1 (0x20)
1142#define SITA_ERROR_RX_UNDEF2 (0x40)
1143#define SITA_ERROR_RX_UNDEF3 (0x80)
1144
1145#define SITA_ERROR_RX_NONOCTET_ALIGNED (0x01) /* values of sita_phdr.errors2 (if SITA_FRAME_DIR_RXED) */
1146#define SITA_ERROR_RX_ABORT (0x02)
1147#define SITA_ERROR_RX_CD_LOST (0x04)
1148#define SITA_ERROR_RX_DPLL (0x08)
1149#define SITA_ERROR_RX_OVERRUN (0x10)
1150#define SITA_ERROR_RX_FRAME_LEN_VIOL (0x20)
1151#define SITA_ERROR_RX_CRC (0x40)
1152#define SITA_ERROR_RX_BREAK (0x80)
1153
1154#define SITA_PROTO_UNUSED (0x00) /* values of sita_phdr.proto */
1155#define SITA_PROTO_BOP_LAPB (0x01)
1156#define SITA_PROTO_ETHERNET (0x02)
1157#define SITA_PROTO_ASYNC_INTIO (0x03)
1158#define SITA_PROTO_ASYNC_BLKIO (0x04)
1159#define SITA_PROTO_ALC (0x05)
1160#define SITA_PROTO_UTS (0x06)
1161#define SITA_PROTO_PPP_HDLC (0x07)
1162#define SITA_PROTO_SDLC (0x08)
1163#define SITA_PROTO_TOKENRING (0x09)
1164#define SITA_PROTO_I2C (0x10)
1165#define SITA_PROTO_DPM_LINK (0x11)
1166#define SITA_PROTO_BOP_FRL (0x12)
1167
1172 uint8_t sita_flags;
1176 uint8_t sita_proto;
1177};
1178
1183 bool sent;
1184 uint32_t channel;
1185};
1186
1187#define BTHCI_CHANNEL_COMMAND 1
1188#define BTHCI_CHANNEL_ACL 2
1189#define BTHCI_CHANNEL_SCO 3
1190#define BTHCI_CHANNEL_EVENT 4
1191#define BTHCI_CHANNEL_ISO 5
1192
1197 uint16_t adapter_id;
1198 uint16_t opcode;
1199};
1200
1205 bool uton;
1206};
1207
1211struct i2c_phdr {
1212 uint8_t is_event;
1213 uint8_t bus;
1214 uint32_t flags;
1215};
1216
1221 bool uplink;
1222 uint8_t channel;
1223 /* The following are only populated for downlink */
1224 uint8_t bsic;
1225 uint16_t arfcn;
1226 uint32_t tdma_frame;
1227 uint8_t error;
1228 uint16_t timeshift;
1229};
1230
1231#define GSM_UM_CHANNEL_UNKNOWN 0
1232#define GSM_UM_CHANNEL_BCCH 1
1233#define GSM_UM_CHANNEL_SDCCH 2
1234#define GSM_UM_CHANNEL_SACCH 3
1235#define GSM_UM_CHANNEL_FACCH 4
1236#define GSM_UM_CHANNEL_CCCH 5
1237#define GSM_UM_CHANNEL_RACH 6
1238#define GSM_UM_CHANNEL_AGCH 7
1239#define GSM_UM_CHANNEL_PCH 8
1240
1265
1270 struct eth_phdr eth;
1271 uint8_t stuff[4];
1272};
1273
1274#define LLCP_PHDR_FLAG_SENT 0
1275
1280 uint8_t adapter;
1281 uint8_t flags;
1282};
1283
1289};
1290
1299 uint8_t* title;
1300 uint32_t descLength;
1301 uint8_t* description;
1302
1303 unsigned sub_encap;
1304
1315};
1316
1317/* Record "pseudo-header" information for header data from MS ProcMon files. */
1318
1319struct procmon_process_t;
1320
1331
1332
1336struct ber_phdr {
1337 const char *pathname;
1338};
1339
1340
1345 uint8_t chunktype;
1346};
1347
1385
1386/*
1387 * Record type values.
1388 *
1389 * This list will expand over time, so don't assume everything will
1390 * forever be one of the types listed below.
1391 *
1392 * For file-type-specific records, the "ftsrec" field of the pseudo-header
1393 * contains a file-type-specific subtype value, such as a block type for
1394 * a pcapng file.
1395 *
1396 * An "event" is an indication that something happened during the capture
1397 * process, such as a status transition of some sort on the network.
1398 * These should, ideally, have a time stamp and, if they're relevant to
1399 * a particular interface on a multi-interface capture, should also have
1400 * an interface ID. The data for the event is file-type-specific and
1401 * subtype-specific. These should be dissected and displayed just as
1402 * packets are.
1403 *
1404 * A "report" supplies information not corresponding to an event;
1405 * for example, a pcapng Interface Statistics Block would be a report,
1406 * as it doesn't correspond to something happening on the network.
1407 * They may have a time stamp, and should be dissected and displayed
1408 * just as packets are.
1409 *
1410 * We distinguish between "events" and "reports" so that, for example,
1411 * the packet display can show the delta between a packet and an event
1412 * but not show the delta between a packet and a report, as the time
1413 * stamp of a report may not correspond to anything interesting on
1414 * the network but the time stamp of an event would.
1415 *
1416 * XXX - are there any file-type-specific records that *shouldn't* be
1417 * dissected and displayed? If so, they should be parsed and the
1418 * information in them stored somewhere, and used somewhere, whether
1419 * it's just used when saving the file in its native format or also
1420 * used to parse *other* file-type-specific records.
1421 *
1422 * These would be similar to, for example, pcapng Interface Description
1423 * Blocks, for which the position within the file is significant only
1424 * in that an IDB for an interface must appear before any packets from
1425 * the interface; the fact that an IDB appears at some point doesn't
1426 * necessarily mean something happened in the capture at that point.
1427 * Name Resolution Blocks are another example of such a record.
1428 *
1429 * (XXX - if you want to have a record that says "this interface first
1430 * showed up at this time", that needs to be a separate record type
1431 * from the IDB. We *could* add a "New Interface Description Block",
1432 * with a time stamp, for that purpose, but we'd *still* have to
1433 * provide IDBs for those interfaces, for compatibility with programs
1434 * that don't know about the NIDB. An ISB with only an isb_starttime
1435 * option would suffice for this purpose, so nothing needs to be
1436 * added to pcapng for this.)
1437 */
1438#define REC_TYPE_PACKET 0
1439#define REC_TYPE_FT_SPECIFIC_EVENT 1
1440#define REC_TYPE_FT_SPECIFIC_REPORT 2
1441#define REC_TYPE_SYSCALL 3
1442#define REC_TYPE_SYSTEMD_JOURNAL_EXPORT 4
1443#define REC_TYPE_CUSTOM_BLOCK 5
1444
1448typedef struct {
1449 uint32_t caplen;
1450 uint32_t len;
1452 uint32_t interface_id;
1453
1456
1457/*
1458 * The pcapng specification says "The word is encoded as an unsigned
1459 * 32-bit integer, using the endianness of the Section Header Block
1460 * scope it is in. In the following table, the bits are numbered with
1461 * 0 being the most-significant bit and 31 being the least-significant
1462 * bit of the 32-bit unsigned integer."
1463 *
1464 * From that, the direction, in bits 0 and 1, is at the *top* of the word.
1465 *
1466 * However, several implementations, such as:
1467 *
1468 * the Wireshark pcapng file reading code;
1469 *
1470 * macOS libpcap and tcpdump;
1471 *
1472 * text2pcap;
1473 *
1474 * and probably the software that generated the capture in bug 11665;
1475 *
1476 * treat 0 as the *least*-significant bit and bit 31 being the *most*-
1477 * significant bit of the flags word, and put the direction at the
1478 * *bottom* of the word.
1479 *
1480 * For now, we go with the known implementations.
1481 */
1482
1483/* Direction field of the packet flags */
1484#define PACK_FLAGS_DIRECTION_MASK 0x00000003 /* unshifted */
1485#define PACK_FLAGS_DIRECTION_SHIFT 0
1486#define PACK_FLAGS_DIRECTION(pack_flags) (((pack_flags) & PACK_FLAGS_DIRECTION_MASK) >> PACK_FLAGS_DIRECTION_SHIFT)
1487#define PACK_FLAGS_DIRECTION_UNKNOWN 0
1488#define PACK_FLAGS_DIRECTION_INBOUND 1
1489#define PACK_FLAGS_DIRECTION_OUTBOUND 2
1490
1491/* Reception type field of the packet flags */
1492#define PACK_FLAGS_RECEPTION_TYPE_MASK 0x0000001C /* unshifted */
1493#define PACK_FLAGS_RECEPTION_TYPE_SHIFT 2
1494#define PACK_FLAGS_RECEPTION_TYPE(pack_flags) (((pack_flags) & PACK_FLAGS_RECEPTION_TYPE_MASK) >> PACK_FLAGS_RECEPTION_TYPE_SHIFT)
1495#define PACK_FLAGS_RECEPTION_TYPE_UNSPECIFIED 0
1496#define PACK_FLAGS_RECEPTION_TYPE_UNICAST 1
1497#define PACK_FLAGS_RECEPTION_TYPE_MULTICAST 2
1498#define PACK_FLAGS_RECEPTION_TYPE_BROADCAST 3
1499#define PACK_FLAGS_RECEPTION_TYPE_PROMISCUOUS 4
1500
1501/* FCS length field of the packet flags */
1502#define PACK_FLAGS_FCS_LENGTH_MASK 0x000001E0 /* unshifted */
1503#define PACK_FLAGS_FCS_LENGTH_SHIFT 5
1504#define PACK_FLAGS_FCS_LENGTH(pack_flags) (((pack_flags) & PACK_FLAGS_FCS_LENGTH_MASK) >> PACK_FLAGS_FCS_LENGTH_SHIFT)
1505
1506/* Reserved bits of the packet flags */
1507#define PACK_FLAGS_RESERVED_MASK 0x0000FE00
1508
1509/* Link-layer-dependent errors of the packet flags */
1510
1511/* For Ethernet and possibly some other network types */
1512#define PACK_FLAGS_CRC_ERROR 0x01000000
1513#define PACK_FLAGS_PACKET_TOO_LONG 0x02000000
1514#define PACK_FLAGS_PACKET_TOO_SHORT 0x04000000
1515#define PACK_FLAGS_WRONG_INTER_FRAME_GAP 0x08000000
1516#define PACK_FLAGS_UNALIGNED_FRAME 0x10000000
1517#define PACK_FLAGS_START_FRAME_DELIMITER_ERROR 0x20000000
1518#define PACK_FLAGS_PREAMBLE_ERROR 0x40000000
1519#define PACK_FLAGS_SYMBOL_ERROR 0x80000000
1520
1521/* Construct a pack_flags value from its subfield values */
1522#define PACK_FLAGS_VALUE(direction, reception_type, fcs_length, ll_dependent_errors) \
1523 (((direction) << 30) | \
1524 ((reception_type) << 27) | \
1525 ((fcs_length) << 23) | \
1526 (ll_dependent_errors))
1527
1538
1542typedef struct {
1543 const char *pathname;
1544 unsigned record_type;
1546 uint64_t timestamp;
1547 uint64_t thread_id;
1548 uint32_t event_len;
1550 uint32_t nparams;
1551 uint32_t flags;
1552 uint16_t event_type;
1553 uint16_t cpu_id;
1555
1559typedef struct {
1560 uint32_t record_len;
1562
1566typedef struct {
1567 uint32_t pen;
1568 uint32_t length;
1571
1572/*
1573 * The largest nstime.secs value that can be put into an unsigned
1574 * 32-bit quantity.
1575 *
1576 * We assume that time_t is signed; it is signed on Windows/MSVC and
1577 * on many UN*Xes.
1578 *
1579 * So, if time_t is 32-bit, we define this as INT32_MAX, as that's
1580 * the largest value a time_t can have, and it fits in an unsigned
1581 * 32-bit quantity. If it's 64-bit or larger, we define this as
1582 * UINT32_MAX, as, even if it's signed, it can be as large as
1583 * UINT32_MAX, and that's the largest value that can fit in
1584 * a 32-bit unsigned quantity.
1585 *
1586 * Comparing against this, rather than against G_MAXINT2, when checking
1587 * whether a time stamp will fit in a 32-bit unsigned integer seconds
1588 * field in a capture file being written avoids signed vs. unsigned
1589 * warnings if time_t is a signed 32-bit type.
1590 *
1591 * XXX - what if time_t is unsigned? Are there any platforms where
1592 * it is?
1593 */
1594#define WTAP_NSTIME_32BIT_SECS_MAX ((time_t)(sizeof(time_t) > sizeof(int32_t) ? UINT32_MAX : INT32_MAX))
1595
1638
1639/*
1640 * Bits in presence_flags, indicating which of the fields we have.
1641 *
1642 * For the time stamp, we may need some more flags to indicate
1643 * whether the time stamp is an absolute date-and-time stamp, an
1644 * absolute time-only stamp (which can make relative time
1645 * calculations tricky, as you could in theory have two time
1646 * stamps separated by an unknown number of days), or a time stamp
1647 * relative to some unspecified time in the past (see mpeg.c).
1648 *
1649 * There is no presence flag for len - there has to be *some* length
1650 * value for the packet. (The "captured length" can be missing if
1651 * the file format doesn't report a captured length distinct from
1652 * the on-the-network length because the application(s) producing those
1653 * files don't support slicing packets.)
1654 *
1655 * There could be a presence flag for the packet encapsulation - if it's
1656 * absent, use the file encapsulation - but it's not clear that's useful;
1657 * we currently do that in the module for the file format.
1658 *
1659 * Only WTAP_HAS_TS and WTAP_HAS_SECTION_NUMBER apply to all record types.
1660 */
1661#define WTAP_HAS_TS 0x00000001
1662#define WTAP_HAS_CAP_LEN 0x00000002
1663#define WTAP_HAS_INTERFACE_ID 0x00000004
1664#define WTAP_HAS_SECTION_NUMBER 0x00000008
1665
1666/*
1667 * The old max name length define, both for backwards compatibility and because
1668 * other name types (in epan) use it. While Name Resolution Blocks (NRBs) only
1669 * support IPv4 and IPv6 currently, they could later support other name types.
1670 */
1671#ifndef MAXNAMELEN
1672#define MAXNAMELEN 64 /* max name length (most names: DNS labels, services, eth) */
1673#endif
1674
1675#ifndef MAXDNSNAMELEN
1676#define MAXDNSNAMELEN 256 /* max total length of a domain name in DNS */
1677#endif
1678
1682typedef struct hashipv4 {
1683 unsigned addr;
1684 uint8_t flags;
1685 char ip[WS_INET_ADDRSTRLEN];
1686 char name[MAXDNSNAMELEN];
1689
1690
1694typedef struct hashipv6 {
1695 uint8_t addr[16];
1696 uint8_t flags;
1697 char ip6[WS_INET6_ADDRSTRLEN];
1698 char name[MAXDNSNAMELEN];
1699 char cidr_addr[WS_INET6_CIDRADDRSTRLEN];
1701
1702
1710
1751
1752/* Zero-initializer for wtap_dump_params. */
1753#define WTAP_DUMP_PARAMS_INIT {.snaplen=0}
1754
1755struct wtap_dumper;
1756
1757typedef struct wtap wtap;
1758typedef struct wtap_dumper wtap_dumper;
1759
1760typedef struct wtap_reader *FILE_T;
1761
1780
1820 const char *name;
1822 const char *extensions;
1823};
1824
1856
1857typedef wtap_open_return_val (*wtap_open_routine_t)(struct wtap*, int *,
1858 char **);
1859
1884
1891WS_DLL_PUBLIC void init_open_routines(void);
1892
1899void cleanup_open_routines(void);
1900
1928 const char *name;
1930 wtap_open_routine_t open_routine;
1931 const char *extensions;
1934};
1935
1942WS_DLL_PUBLIC struct open_info *open_routines;
1943
1944/*
1945 * Types of comments.
1946 */
1952#define WTAP_COMMENT_PER_SECTION 0x00000001 /* per-file/per-file-section */
1953
1959#define WTAP_COMMENT_PER_INTERFACE 0x00000002 /* per-interface */
1960
1966#define WTAP_COMMENT_PER_PACKET 0x00000004 /* per-packet */
1967
1983
1994
2000#define OPTION_TYPES_SUPPORTED(option_type_array) \
2001 array_length(option_type_array), option_type_array
2002
2008#define NO_OPTIONS_SUPPORTED \
2009 0, NULL
2010
2019
2029
2030#define BLOCKS_SUPPORTED(block_type_array) \
2031 array_length(block_type_array), block_type_array
2032
2040 const char *description;
2041
2046 const char *name;
2047
2053
2061
2066
2071
2076
2085 int (*can_write_encap)(int);
2086
2091 bool (*dump_open)(wtap_dumper *, int *, char **);
2092
2098};
2099
2100#define WTAP_TYPE_AUTO 0
2101
2110WS_DLL_PUBLIC
2111void wtap_init(bool load_wiretap_plugins, const char* app_env_var_prefix, const struct file_extension_info* file_extensions, unsigned num_extensions);
2112
2130WS_DLL_PUBLIC
2131struct wtap* wtap_open_offline(const char *filename, unsigned int type, int *err,
2132 char **err_info, bool do_random, const char* app_env_var_prefix);
2133
2142WS_DLL_PUBLIC
2143void wtap_cleareof(wtap *wth);
2144
2155typedef void (*wtap_new_ipv4_callback_t) (const unsigned addr, const char *name, const bool static_entry);
2156
2166WS_DLL_PUBLIC
2168
2179typedef void (*wtap_new_ipv6_callback_t) (const ws_in6_addr *addrp, const char *name, const bool static_entry);
2180
2190WS_DLL_PUBLIC
2192
2203typedef void (*wtap_new_secrets_callback_t)(uint32_t secrets_type, const void *secrets, unsigned size);
2204
2214WS_DLL_PUBLIC
2216
2232WS_DLL_PUBLIC
2233bool wtap_read(wtap *wth, wtap_rec *rec, int *err, char **err_info,
2234 int64_t *offset);
2235
2252WS_DLL_PUBLIC
2253bool wtap_seek_read(wtap *wth, int64_t seek_off, wtap_rec *rec,
2254 int *err, char **err_info);
2255
2264WS_DLL_PUBLIC
2265void wtap_rec_init(wtap_rec *rec, size_t space);
2266
2275WS_DLL_PUBLIC
2276void wtap_rec_apply_snapshot(wtap_rec *rec, uint32_t snaplen);
2277
2285WS_DLL_PUBLIC
2286void wtap_rec_reset(wtap_rec *rec);
2287
2295WS_DLL_PUBLIC
2296void wtap_rec_cleanup(wtap_rec *rec);
2297
2307WS_DLL_PUBLIC
2309
2318WS_DLL_PUBLIC
2319void wtap_setup_packet_rec(wtap_rec *rec, int encap);
2320
2330WS_DLL_PUBLIC
2332 unsigned record_type);
2333
2343WS_DLL_PUBLIC
2345 unsigned record_type);
2346
2354WS_DLL_PUBLIC
2356
2364WS_DLL_PUBLIC
2366
2378WS_DLL_PUBLIC
2379void wtap_setup_custom_block_rec(wtap_rec *rec, uint32_t pen,
2380 uint32_t payload_length, bool copy_allowed);
2381
2390WS_DLL_PUBLIC
2391ws_compression_type wtap_get_compression_type(wtap *wth);
2392
2393/*** get various information snippets about the current file ***/
2394
2404WS_DLL_PUBLIC
2405int64_t wtap_read_so_far(wtap *wth);
2406
2416WS_DLL_PUBLIC
2417int64_t wtap_file_size(wtap *wth, int *err);
2418
2427WS_DLL_PUBLIC
2428unsigned wtap_snapshot_length(wtap *wth);
2429
2438WS_DLL_PUBLIC
2440
2449WS_DLL_PUBLIC
2450int wtap_file_encap(wtap *wth);
2451
2460WS_DLL_PUBLIC
2461int wtap_file_tsprec(wtap *wth);
2462
2471WS_DLL_PUBLIC
2472const nstime_t* wtap_file_start_ts(wtap *wth);
2473
2482WS_DLL_PUBLIC
2483const nstime_t* wtap_file_end_ts(wtap *wth);
2484
2492WS_DLL_PUBLIC
2493unsigned wtap_file_get_num_shbs(wtap *wth);
2494
2507WS_DLL_PUBLIC
2508wtap_block_t wtap_file_get_shb(wtap *wth, unsigned shb_num);
2509
2520WS_DLL_PUBLIC
2521void wtap_write_shb_comment(wtap *wth, char *comment);
2522
2534WS_DLL_PUBLIC
2535unsigned wtap_file_get_shb_global_interface_id(wtap *wth, unsigned shb_num, uint32_t interface_id);
2536
2547WS_DLL_PUBLIC
2549
2550
2557WS_DLL_PUBLIC
2559
2569WS_DLL_PUBLIC
2570wtap_block_t wtap_get_next_interface_description(wtap *wth);
2571
2584WS_DLL_PUBLIC
2586
2598WS_DLL_PUBLIC
2599char *wtap_get_debug_if_descr(const wtap_block_t if_descr,
2600 const int indent,
2601 const char* line_end);
2602
2615WS_DLL_PUBLIC
2616wtap_block_t wtap_file_get_nrb(wtap *wth);
2617
2625WS_DLL_PUBLIC
2626unsigned wtap_file_get_num_dsbs(wtap *wth);
2627
2638WS_DLL_PUBLIC
2639wtap_block_t wtap_file_get_dsb(wtap *wth, unsigned dsb_num);
2640
2649WS_DLL_PUBLIC
2650void wtap_file_add_decryption_secrets(wtap *wth, const wtap_block_t dsb);
2651
2660WS_DLL_PUBLIC
2662
2670WS_DLL_PUBLIC
2671void wtap_fdclose(wtap *wth);
2672
2683WS_DLL_PUBLIC
2684bool wtap_fdreopen(wtap *wth, const char *filename, int *err);
2685
2693WS_DLL_PUBLIC
2694void wtap_sequential_close(wtap *wth);
2695
2703WS_DLL_PUBLIC
2704void wtap_close(wtap *wth);
2705
2714WS_DLL_PUBLIC
2715bool wtap_dump_can_open(int filetype);
2716
2727WS_DLL_PUBLIC
2728int wtap_dump_required_file_encap_type(const GArray *file_encaps);
2729
2740WS_DLL_PUBLIC
2741bool wtap_dump_can_write_encap(int file_type_subtype, int encap);
2742
2751WS_DLL_PUBLIC
2753
2764WS_DLL_PUBLIC
2765void wtap_dump_params_init(wtap_dump_params *params, wtap *wth);
2766
2783WS_DLL_PUBLIC
2785
2793WS_DLL_PUBLIC
2795
2803WS_DLL_PUBLIC
2805
2812WS_DLL_PUBLIC
2814
2827WS_DLL_PUBLIC
2828wtap_dumper* wtap_dump_open(const char *filename, int file_type_subtype,
2829 ws_compression_type compression_type, const wtap_dump_params *params,
2830 int *err, char **err_info);
2831
2847WS_DLL_PUBLIC
2848wtap_dumper* wtap_dump_open_tempfile(const char *tmpdir, char **filenamep,
2849 const char *pfx,
2850 int file_type_subtype, ws_compression_type compression_type,
2851 const wtap_dump_params *params, int *err, char **err_info);
2852
2865WS_DLL_PUBLIC
2867 ws_compression_type compression_type, const wtap_dump_params *params,
2868 int *err, char **err_info);
2869
2881WS_DLL_PUBLIC
2883 ws_compression_type compression_type, const wtap_dump_params *params,
2884 int *err, char **err_info);
2885
2897WS_DLL_PUBLIC
2898bool wtap_dump_add_idb(wtap_dumper *wdh, wtap_block_t idb, int *err,
2899 char **err_info);
2900
2911WS_DLL_PUBLIC
2912bool wtap_dump(wtap_dumper *wdh, const wtap_rec *rec, int *err, char **err_info);
2913
2921WS_DLL_PUBLIC
2922bool wtap_dump_flush(wtap_dumper *wdh, int *err);
2923
2930WS_DLL_PUBLIC
2932
2939WS_DLL_PUBLIC
2940uint64_t wtap_get_bytes_dumped(const wtap_dumper *wdh);
2941
2948WS_DLL_PUBLIC
2949void wtap_set_bytes_dumped(wtap_dumper *wdh, uint64_t bytes_dumped);
2950
2951struct addrinfo;
2952
2959WS_DLL_PUBLIC
2961
2969WS_DLL_PUBLIC
2971
2977WS_DLL_PUBLIC
2979
2985WS_DLL_PUBLIC
2987
3004WS_DLL_PUBLIC
3005bool wtap_dump_close(wtap_dumper *wdh, bool *needs_reload,
3006 int *err, char **err_info);
3007
3024WS_DLL_PUBLIC
3025bool wtap_dump_can_write(const GArray *file_encaps, uint32_t required_comment_types);
3026
3040WS_DLL_PUBLIC
3041void wtap_buffer_append_epdu_tag(Buffer *buf, uint16_t epdu_tag, const uint8_t *data, uint16_t data_len);
3042
3051WS_DLL_PUBLIC
3052void wtap_buffer_append_epdu_uint(Buffer *buf, uint16_t epdu_tag, uint32_t val);
3053
3062WS_DLL_PUBLIC
3063void wtap_buffer_append_epdu_string(Buffer *buf, uint16_t epdu_tag, const char *val);
3064
3073WS_DLL_PUBLIC
3075
3083
3100WS_DLL_PUBLIC
3101GArray *wtap_get_savable_file_types_subtypes_for_file(int file_type_subtype,
3102 const GArray *file_encaps, uint32_t required_comment_types,
3103 ft_sort_order sort_order);
3104
3116WS_DLL_PUBLIC
3118
3119/*** various file type/subtype functions ***/
3129WS_DLL_PUBLIC
3130const char *wtap_file_type_subtype_description(int file_type_subtype);
3131
3140WS_DLL_PUBLIC
3141const char *wtap_file_type_subtype_name(int file_type_subtype);
3142
3152WS_DLL_PUBLIC
3153int wtap_name_to_file_type_subtype(const char *name);
3154
3160WS_DLL_PUBLIC
3162
3168WS_DLL_PUBLIC
3170
3176WS_DLL_PUBLIC
3178
3189WS_DLL_PUBLIC
3191 wtap_block_type_t type);
3192
3207WS_DLL_PUBLIC
3209 wtap_block_type_t type, unsigned opttype);
3210
3234WS_DLL_PUBLIC
3236
3252WS_DLL_PUBLIC
3254
3269WS_DLL_PUBLIC
3270void wtap_free_extensions_list(GSList *extensions);
3271
3283WS_DLL_PUBLIC
3284const char *wtap_default_file_extension(int file_type_subtype);
3285
3301WS_DLL_PUBLIC
3302GSList *wtap_get_file_extensions_list(int file_type_subtype, bool include_compressed);
3303
3312WS_DLL_PUBLIC
3313const char *wtap_encap_name(int encap);
3314
3323WS_DLL_PUBLIC
3324const char *wtap_encap_description(int encap);
3325
3335WS_DLL_PUBLIC
3336int wtap_name_to_encap(const char *short_name);
3337
3346WS_DLL_PUBLIC
3347const char* wtap_tsprec_string(int tsprec);
3348
3357WS_DLL_PUBLIC
3358const char *wtap_strerror(int err);
3359
3360
3361/*** get available number of file types and encapsulations ***/
3370WS_DLL_PUBLIC
3372
3380WS_DLL_PUBLIC
3381int wtap_get_num_encap_types(void);
3382
3383/*** get information for file type extension ***/
3384
3396WS_DLL_PUBLIC
3397const char *wtap_get_file_extension_type_name(int extension_type);
3398
3410WS_DLL_PUBLIC
3411GSList *wtap_get_file_extension_type_extensions(unsigned extension_type);
3412
3413/*** dynamically register new file types and encapsulations ***/
3414
3426WS_DLL_PUBLIC
3428
3439typedef struct {
3440 void (*register_wtap_module)(void);
3441} wtap_plugin;
3442
3454WS_DLL_PUBLIC
3456
3457
3471WS_DLL_PUBLIC
3472int wtap_plugins_supported(void);
3473
3474/* Registration and open-info */
3475
3481WS_DLL_PUBLIC
3482void wtap_register_open_info(struct open_info *oi, const bool first_routine);
3483
3489WS_DLL_PUBLIC
3490bool wtap_has_open_info(const char *name);
3491
3497WS_DLL_PUBLIC
3498bool wtap_uses_lua_filehandler(const wtap* wth);
3499
3504WS_DLL_PUBLIC
3505void wtap_deregister_open_info(const char *name);
3506
3507/* Type mapping and registration */
3508
3514WS_DLL_PUBLIC
3515unsigned int open_info_name_to_type(const char *name);
3516
3522WS_DLL_PUBLIC
3524
3529WS_DLL_PUBLIC
3530void wtap_deregister_file_type_subtype(const int file_type_subtype);
3531
3532/* Encapsulation and cleanup */
3539WS_DLL_PUBLIC
3540int wtap_register_encap_type(const char *description, const char *name);
3541
3545WS_DLL_PUBLIC
3546void wtap_cleanup(void);
3547
3551#define WTAP_ERR_NOT_REGULAR_FILE -1
3553
3554#define WTAP_ERR_RANDOM_OPEN_PIPE -2
3556
3557#define WTAP_ERR_FILE_UNKNOWN_FORMAT -3
3559
3560#define WTAP_ERR_UNSUPPORTED -4
3563
3564#define WTAP_ERR_CANT_WRITE_TO_PIPE -5
3566
3567#define WTAP_ERR_CANT_OPEN -6
3569
3570#define WTAP_ERR_UNWRITABLE_FILE_TYPE -7
3572
3573#define WTAP_ERR_UNWRITABLE_ENCAP -8
3576
3577#define WTAP_ERR_ENCAP_PER_PACKET_UNSUPPORTED -9
3579
3580#define WTAP_ERR_CANT_WRITE -10
3582
3583#define WTAP_ERR_CANT_CLOSE -11
3585
3586#define WTAP_ERR_SHORT_READ -12
3588
3589#define WTAP_ERR_BAD_FILE -13
3591
3592#define WTAP_ERR_SHORT_WRITE -14
3594
3595#define WTAP_ERR_UNC_OVERFLOW -15
3597
3598#define WTAP_ERR_RANDOM_OPEN_STDIN -16
3600
3601#define WTAP_ERR_COMPRESSION_NOT_SUPPORTED -17
3603
3604#define WTAP_ERR_CANT_SEEK -18
3606
3607#define WTAP_ERR_CANT_SEEK_COMPRESSED -19
3609
3610#define WTAP_ERR_DECOMPRESS -20
3612
3613#define WTAP_ERR_INTERNAL -21
3615
3616#define WTAP_ERR_PACKET_TOO_LARGE -22
3619
3620#define WTAP_ERR_CHECK_WSLUA -23
3623
3624#define WTAP_ERR_UNWRITABLE_REC_TYPE -24
3626
3627#define WTAP_ERR_UNWRITABLE_REC_DATA -25
3629
3630#define WTAP_ERR_DECOMPRESSION_NOT_SUPPORTED -26
3632
3633#define WTAP_ERR_TIME_STAMP_NOT_SUPPORTED -27
3636
3637#define WTAP_ERR_REC_MALFORMED -28
3640
3641#ifdef __cplusplus
3642}
3643#endif /* __cplusplus */
3644
3645#endif /* __WTAP_H__ */
3646
3647/*
3648 * Editor modelines - https://www.wireshark.org/tools/modelines.html
3649 *
3650 * Local variables:
3651 * c-basic-offset: 4
3652 * tab-width: 8
3653 * indent-tabs-mode: nil
3654 * End:
3655 *
3656 * vi: set shiftwidth=4 tabstop=8 expandtab:
3657 * :indentSize=4:tabSize=8:noTabs=true:
3658 */
struct e_in6_addr ws_in6_addr
Represents a 128-bit IPv6 address.
#define WS_INET_CIDRADDRSTRLEN
Convert an IPv6 address to a string representation.
Definition inet_addr.h:155
A dynamic byte buffer with adjustable start and end positions.
Definition buffer.h:30
Aggregates lists of resolved IPv4 and IPv6 addresses for writing into a pcapng Name Resolution Block ...
Definition wtap.h:1706
GList * ipv6_addr_list
Definition wtap.h:1708
GList * ipv4_addr_list
Definition wtap.h:1707
Pseudo-header for Ascend WAN capture files carrying session, call, and task metadata.
Definition wtap.h:530
uint32_t chunk
Definition wtap.h:535
uint16_t type
Definition wtap.h:531
char call_num[64]
Definition wtap.h:534
uint32_t sess
Definition wtap.h:533
uint32_t task
Definition wtap.h:536
char user[64]
Definition wtap.h:532
Pseudo-header for ATM capture files carrying cell, circuit, and AAL-layer metadata.
Definition wtap.h:500
uint16_t vpi
Definition wtap.h:505
uint16_t aal5t_len
Definition wtap.h:511
uint16_t aal5t_u2u
Definition wtap.h:510
uint16_t channel
Definition wtap.h:508
uint8_t aal2_cid
Definition wtap.h:507
uint16_t cells
Definition wtap.h:509
uint8_t subtype
Definition wtap.h:504
uint32_t aal5t_chksum
Definition wtap.h:512
uint8_t aal
Definition wtap.h:502
uint16_t vci
Definition wtap.h:506
uint32_t flags
Definition wtap.h:501
uint8_t type
Definition wtap.h:503
Pseudo-header for BER (Basic Encoding Rules) data files.
Definition wtap.h:1336
const char * pathname
Definition wtap.h:1337
Pseudo-header for Bluetooth HCI capture files carrying direction and channel metadata.
Definition wtap.h:1182
bool sent
Definition wtap.h:1183
uint32_t channel
Definition wtap.h:1184
Pseudo-header for Linux Bluetooth Monitor (WTAP_ENCAP_BLUETOOTH_LINUX_MONITOR) capture files.
Definition wtap.h:1196
uint16_t opcode
Definition wtap.h:1198
uint16_t adapter_id
Definition wtap.h:1197
Pseudo-header for Catapult DCT2000 captures.
Definition wtap.h:1048
int64_t seek_off
Definition wtap.h:1055
struct wtap * wth
Definition wtap.h:1056
struct isdn_phdr isdn
Definition wtap.h:1050
struct p2p_phdr p2p
Definition wtap.h:1052
struct atm_phdr atm
Definition wtap.h:1051
Pseudo-header for CoSine Systems capture files carrying encapsulation, direction, and QoS metadata.
Definition wtap.h:918
uint16_t err
Definition wtap.h:926
uint16_t rm
Definition wtap.h:925
uint8_t direction
Definition wtap.h:920
uint16_t pro
Definition wtap.h:922
char if_name[128]
Definition wtap.h:921
uint16_t off
Definition wtap.h:923
uint16_t pri
Definition wtap.h:924
uint8_t encap
Definition wtap.h:919
Pseudo-header for DTE/DCE capture files (LAPB, V.120, Frame Relay) carrying direction metadata.
Definition wtap.h:407
uint8_t flags
Definition wtap.h:408
Holds a single ERF extension header word appended after the main ERF header.
Definition wtap.h:1074
uint64_t ehdr
Definition wtap.h:1075
Extended pseudo-header for ERF multi-channel (MC) packet records.
Definition wtap.h:1096
union erf_mc_phdr::@031203371227322325321065306065226045005243346162 subhdr
Protocol-specific subheader union.
struct wtap_erf_eth_hdr eth_hdr
Definition wtap.h:1107
struct erf_ehdr ehdr_list[16]
Definition wtap.h:1099
struct erf_phdr phdr
Definition wtap.h:1097
uint32_t aal2_hdr
Definition wtap.h:1109
uint32_t mc_hdr
Definition wtap.h:1108
Pseudo-header for Endace ERF (Extensible Record Format) capture files carrying timestamp and record m...
Definition wtap.h:1062
uint16_t lctr
Definition wtap.h:1067
uint16_t rlen
Definition wtap.h:1066
uint8_t type
Definition wtap.h:1064
uint8_t flags
Definition wtap.h:1065
uint64_t ts
Definition wtap.h:1063
uint16_t wlen
Definition wtap.h:1068
Pseudo-header for Ethernet capture files carrying FCS length metadata.
Definition wtap.h:398
int fcs_len
Definition wtap.h:399
For registering extensions used for file formats.
Definition wtap.h:1819
const char * extensions
Definition wtap.h:1822
const char * name
Definition wtap.h:1820
bool is_capture_file
Definition wtap.h:1821
Describes a single capture file type/subtype, including its metadata, capability flags,...
Definition wtap.h:2036
wtap_wslua_file_info_t * wslua_info
Definition wtap.h:2097
const char * name
Definition wtap.h:2046
const char * additional_file_extensions
Definition wtap.h:2060
int(* can_write_encap)(int)
Definition wtap.h:2085
const struct supported_block_type * supported_blocks
Definition wtap.h:2075
bool writing_must_seek
Definition wtap.h:2065
const char * description
Definition wtap.h:2040
bool(* dump_open)(wtap_dumper *, int *, char **)
Definition wtap.h:2091
size_t num_supported_blocks
Definition wtap.h:2070
const char * default_file_extension
Definition wtap.h:2052
Pseudo-header for GSM Um air interface (WTAP_ENCAP_GSM_UM) capture files.
Definition wtap.h:1220
bool uplink
Definition wtap.h:1221
uint8_t bsic
Definition wtap.h:1224
uint32_t tdma_frame
Definition wtap.h:1226
uint16_t arfcn
Definition wtap.h:1225
uint8_t channel
Definition wtap.h:1222
uint8_t error
Definition wtap.h:1227
uint16_t timeshift
Definition wtap.h:1228
Hash table entry for a resolved or unresolved IPv4 address.
Definition wtap.h:1682
char ip[WS_INET_ADDRSTRLEN]
Definition wtap.h:1685
char cidr_addr[WS_INET_CIDRADDRSTRLEN]
Definition wtap.h:1687
char name[256]
Definition wtap.h:1686
unsigned addr
Definition wtap.h:1683
uint8_t flags
Definition wtap.h:1684
Hash table entry for a resolved or unresolved IPv6 address.
Definition wtap.h:1694
char name[256]
Definition wtap.h:1698
char ip6[WS_INET6_ADDRSTRLEN]
Definition wtap.h:1697
uint8_t flags
Definition wtap.h:1696
uint8_t addr[16]
Definition wtap.h:1695
char cidr_addr[WS_INET6_CIDRADDRSTRLEN]
Definition wtap.h:1699
Pseudo-header for I2C bus capture files carrying bus number, event type, and flag metadata.
Definition wtap.h:1211
uint32_t flags
Definition wtap.h:1214
uint8_t bus
Definition wtap.h:1213
uint8_t is_event
Definition wtap.h:1212
Definition pcapio.c:117
PHY metadata for 802.11 legacy FHSS (Frequency Hopping Spread Spectrum) captures.
Definition wtap.h:595
unsigned has_hop_pattern
Definition wtap.h:597
uint8_t hop_set
Definition wtap.h:600
uint8_t hop_index
Definition wtap.h:602
uint8_t hop_pattern
Definition wtap.h:601
unsigned has_hop_set
Definition wtap.h:596
unsigned has_hop_index
Definition wtap.h:598
Pseudo-header for 802.11 wireless capture files carrying full PHY, signal, and frame metadata.
Definition wtap.h:849
unsigned has_noise_percent
Definition wtap.h:861
unsigned has_frequency
Definition wtap.h:858
uint32_t frequency
Definition wtap.h:871
unsigned has_signal_dbm
Definition wtap.h:862
unsigned has_signal_db
Definition wtap.h:864
int8_t noise_dbm
Definition wtap.h:876
unsigned phy
Definition wtap.h:854
unsigned has_aggregate_info
Definition wtap.h:867
unsigned has_signal_percent
Definition wtap.h:860
unsigned has_channel
Definition wtap.h:857
union ieee_802_11_phy_info phy_info
Definition wtap.h:855
unsigned has_zero_length_psdu_type
Definition wtap.h:868
unsigned datapad
Definition wtap.h:852
unsigned decrypted
Definition wtap.h:851
int fcs_len
Definition wtap.h:850
uint16_t channel
Definition wtap.h:870
uint8_t signal_db
Definition wtap.h:877
unsigned has_tsf_timestamp
Definition wtap.h:866
uint32_t aggregate_id
Definition wtap.h:881
uint16_t data_rate
Definition wtap.h:872
uint8_t signal_percent
Definition wtap.h:873
unsigned has_data_rate
Definition wtap.h:859
uint8_t zero_length_psdu_type
Definition wtap.h:882
uint8_t noise_percent
Definition wtap.h:874
uint64_t tsf_timestamp
Definition wtap.h:879
unsigned has_noise_db
Definition wtap.h:865
unsigned has_noise_dbm
Definition wtap.h:863
unsigned no_a_msdus
Definition wtap.h:853
uint8_t noise_db
Definition wtap.h:878
int8_t signal_dbm
Definition wtap.h:875
uint32_t aggregate_flags
Definition wtap.h:880
PHY metadata for 802.11a captures.
Definition wtap.h:619
unsigned channel_type
Definition wtap.h:623
unsigned has_channel_type
Definition wtap.h:620
unsigned has_turbo_type
Definition wtap.h:621
unsigned turbo_type
Definition wtap.h:624
PHY metadata for 802.11ac (VHT) captures.
Definition wtap.h:720
uint8_t fec
Definition wtap.h:741
unsigned has_short_gi
Definition wtap.h:723
unsigned short_gi_nsym_disambig
Definition wtap.h:735
unsigned txop_ps_not_allowed
Definition wtap.h:733
unsigned stbc
Definition wtap.h:732
uint8_t nss[4]
Definition wtap.h:740
uint16_t partial_aid
Definition wtap.h:743
unsigned has_beamformed
Definition wtap.h:726
unsigned has_ldpc_extra_ofdm_symbol
Definition wtap.h:725
uint8_t mcs[4]
Definition wtap.h:739
unsigned has_bandwidth
Definition wtap.h:727
unsigned has_stbc
Definition wtap.h:721
unsigned has_partial_aid
Definition wtap.h:730
unsigned has_fec
Definition wtap.h:728
unsigned beamformed
Definition wtap.h:737
unsigned short_gi
Definition wtap.h:734
unsigned has_short_gi_nsym_disambig
Definition wtap.h:724
uint8_t bandwidth
Definition wtap.h:738
unsigned has_group_id
Definition wtap.h:729
uint8_t group_id
Definition wtap.h:742
unsigned has_txop_ps_not_allowed
Definition wtap.h:722
unsigned ldpc_extra_ofdm_symbol
Definition wtap.h:736
PHY metadata for 802.11ad (WiGig/DMG) captures.
Definition wtap.h:763
uint8_t mcs
Definition wtap.h:766
unsigned has_mcs_index
Definition wtap.h:764
PHY metadata for 802.11ax (HE — High Efficiency) captures.
Definition wtap.h:773
uint8_t bwru
Definition wtap.h:780
uint8_t gi
Definition wtap.h:781
unsigned has_gi
Definition wtap.h:776
uint8_t mcs
Definition wtap.h:779
uint8_t nsts
Definition wtap.h:778
unsigned has_bwru
Definition wtap.h:775
unsigned has_mcs_index
Definition wtap.h:774
PHY metadata for 802.11b captures.
Definition wtap.h:609
unsigned has_short_preamble
Definition wtap.h:610
bool short_preamble
Definition wtap.h:612
Per-user PHY metadata for a single user within an 802.11be (EHT) MU transmission.
Definition wtap.h:788
unsigned data_for_this_user
Definition wtap.h:796
unsigned coding_known
Definition wtap.h:791
unsigned mcs_known
Definition wtap.h:790
unsigned sta_id
Definition wtap.h:797
unsigned spatial_config_known
Definition wtap.h:795
unsigned ldpc_coding
Definition wtap.h:798
unsigned bf_known
Definition wtap.h:794
unsigned nsts_known
Definition wtap.h:793
unsigned sta_id_known
Definition wtap.h:789
unsigned mcs
Definition wtap.h:799
unsigned rsv
Definition wtap.h:801
unsigned nsts
Definition wtap.h:800
unsigned beamform
Definition wtap.h:802
unsigned rsv_known
Definition wtap.h:792
unsigned rsv2
Definition wtap.h:803
PHY metadata for 802.11be (EHT — Extremely High Throughput) captures.
Definition wtap.h:811
uint8_t bandwidth
Definition wtap.h:816
unsigned has_bandwidth
Definition wtap.h:814
unsigned has_ru_mru_size
Definition wtap.h:812
uint8_t ru_mru_size
Definition wtap.h:817
unsigned has_gi
Definition wtap.h:813
uint8_t gi
Definition wtap.h:818
uint8_t num_users
Definition wtap.h:819
struct ieee_802_11be_user_info user[4]
Definition wtap.h:820
PHY metadata for 802.11g OFDM captures.
Definition wtap.h:654
uint32_t mode
Definition wtap.h:657
unsigned has_mode
Definition wtap.h:655
PHY metadata for 802.11n (HT) captures.
Definition wtap.h:669
unsigned fec
Definition wtap.h:682
unsigned short_gi
Definition wtap.h:680
unsigned has_fec
Definition wtap.h:674
unsigned has_greenfield
Definition wtap.h:673
uint16_t mcs_index
Definition wtap.h:678
unsigned has_stbc_streams
Definition wtap.h:675
unsigned ness
Definition wtap.h:684
unsigned greenfield
Definition wtap.h:681
unsigned has_ness
Definition wtap.h:676
unsigned stbc_streams
Definition wtap.h:683
unsigned has_mcs_index
Definition wtap.h:670
unsigned has_bandwidth
Definition wtap.h:671
unsigned bandwidth
Definition wtap.h:679
unsigned has_short_gi
Definition wtap.h:672
Pseudo-header carrying IrDA packet type metadata for captured IrDA frames.
Definition wtap.h:953
uint16_t pkttype
Definition wtap.h:954
Pseudo-header for ISDN capture files carrying direction and channel metadata.
Definition wtap.h:414
bool uton
Definition wtap.h:415
uint8_t channel
Definition wtap.h:416
Pseudo-header for Tektronix K12 capture files carrying input port, stack, and protocol metadata.
Definition wtap.h:1014
const char * input_name
Definition wtap.h:1016
uint32_t input
Definition wtap.h:1015
void * stuff
Definition wtap.h:1022
uint8_t * extra_info
Definition wtap.h:1020
k12_input_info_t input_info
Definition wtap.h:1019
uint32_t extra_length
Definition wtap.h:1021
uint32_t input_type
Definition wtap.h:1018
const char * stack_file
Definition wtap.h:1017
Pseudo-header for layer 1 event (WTAP_ENCAP_LAYER1_EVENT) capture files carrying signal direction met...
Definition wtap.h:1204
bool uton
Definition wtap.h:1205
LAPD pseudo-header for packet metadata.
Definition wtap.h:1036
uint8_t we_network
Definition wtap.h:1038
uint16_t pkttype
Definition wtap.h:1037
Pseudo-header for NFC Logical Link Control Protocol (LLCP) capture files.
Definition wtap.h:1279
uint8_t adapter
Definition wtap.h:1280
uint8_t flags
Definition wtap.h:1281
Pseudo-header for Android Logcat (WTAP_ENCAP_LOGCAT) capture files.
Definition wtap.h:1287
int version
Definition wtap.h:1288
Pseudo-header for M-Module binary files.
Definition wtap.h:1344
uint8_t chunktype
Definition wtap.h:1345
Pseudo-header carrying MTP2 link metadata for captured SS7 MTP2 frames.
Definition wtap.h:977
uint8_t annex_a_used
Definition wtap.h:979
uint16_t link_number
Definition wtap.h:980
uint8_t sent
Definition wtap.h:978
Pseudo-header metadata for packets captured in NetMon (Network Monitor) files.
Definition wtap.h:1298
unsigned sub_encap
Definition wtap.h:1303
uint8_t * description
Definition wtap.h:1301
uint8_t * title
Definition wtap.h:1299
uint32_t descLength
Definition wtap.h:1300
Pseudo-header for HP-UX nettl capture files carrying subsystem, device, and process metadata.
Definition wtap.h:960
int32_t pid
Definition wtap.h:964
uint16_t subsys
Definition wtap.h:961
uint32_t devid
Definition wtap.h:962
uint32_t kind
Definition wtap.h:963
uint32_t uid
Definition wtap.h:965
Pseudo-header for Nokia firewall capture files, extending the Ethernet pseudo-header with device-spec...
Definition wtap.h:1269
struct eth_phdr eth
Definition wtap.h:1270
uint8_t stuff[4]
Definition wtap.h:1271
Definition nstime.h:26
Pseudo-header for Citrix NetScaler nstrace capture files carrying field offset and record layout meta...
Definition wtap.h:1244
uint8_t dir_len
Definition wtap.h:1250
uint8_t src_vmname_len_offset
Definition wtap.h:1260
uint8_t clflags_offset
Definition wtap.h:1259
uint8_t srcnodeid_offset
Definition wtap.h:1257
uint8_t ns_activity_offset
Definition wtap.h:1262
uint8_t pcb_offset
Definition wtap.h:1252
uint8_t dst_vmname_len_offset
Definition wtap.h:1261
uint8_t coreid_offset
Definition wtap.h:1256
uint8_t data_offset
Definition wtap.h:1263
uint8_t rec_type
Definition wtap.h:1254
uint8_t destnodeid_offset
Definition wtap.h:1258
uint8_t nicno_offset
Definition wtap.h:1247
int64_t rec_offset
Definition wtap.h:1245
uint8_t nicno_len
Definition wtap.h:1248
uint8_t l_pcb_offset
Definition wtap.h:1253
uint8_t vlantag_offset
Definition wtap.h:1255
int32_t rec_len
Definition wtap.h:1246
uint8_t dir_offset
Definition wtap.h:1249
uint16_t eth_offset
Definition wtap.h:1251
Information about a given file type that applies to all subtypes of the file type.
Definition wtap.h:1927
const char * name
Definition wtap.h:1928
wtap_open_routine_t open_routine
Definition wtap.h:1930
void * wslua_data
Definition wtap.h:1933
const char * extensions
Definition wtap.h:1931
wtap_open_type type
Definition wtap.h:1929
char ** extensions_set
Definition wtap.h:1932
Pseudo-header for point-to-point link capture files carrying packet direction metadata.
Definition wtap.h:542
bool sent
Definition wtap.h:543
Pseudo-header for Microsoft ProcMon (Process Monitor) captures.
Definition wtap.h:1324
struct procmon_process_t * process_array
Definition wtap.h:1327
uint32_t * process_index_map
Definition wtap.h:1325
size_t process_array_size
Definition wtap.h:1328
size_t process_index_map_size
Definition wtap.h:1326
bool system_bitness
Definition wtap.h:1329
Describes a single process observed by Process Monitor, including its identity, security context,...
Definition procmon.h:30
Definition ngsniffer.c:82
Pseudo-header for SITA WAN capture files carrying signal, error, and protocol metadata.
Definition wtap.h:1171
uint8_t sita_signals
Definition wtap.h:1173
uint8_t sita_flags
Definition wtap.h:1172
uint8_t sita_errors2
Definition wtap.h:1175
uint8_t sita_proto
Definition wtap.h:1176
uint8_t sita_errors1
Definition wtap.h:1174
Describes a single block type supported by a file format, including its option support.
Definition wtap.h:2023
const struct supported_option_type * supported_options
Definition wtap.h:2027
block_support_t support
Definition wtap.h:2025
wtap_block_type_t type
Definition wtap.h:2024
size_t num_supported_options
Definition wtap.h:2026
Entry describing support level for a specific option type.
Definition wtap.h:1990
unsigned opt
Definition wtap.h:1991
option_support_t support
Definition wtap.h:1992
Header metadata for a pcapng Custom Block record.
Definition wtap.h:1566
uint32_t pen
Definition wtap.h:1567
uint32_t length
Definition wtap.h:1568
bool copy_allowed
Definition wtap.h:1569
Definition wtap.h:1727
const GArray * nrbs_growing
Definition wtap.h:1736
const GArray * dsbs_growing
Definition wtap.h:1740
int tsprec
Definition wtap.h:1730
GArray * shb_hdrs
Definition wtap.h:1731
int encap
Definition wtap.h:1728
bool dont_copy_idbs
Definition wtap.h:1749
GArray * dsbs_initial
Definition wtap.h:1739
wtapng_iface_descriptions_t * idb_inf
Definition wtap.h:1735
const GArray * mevs_growing
Definition wtap.h:1743
const GArray * shb_iface_to_global
Definition wtap.h:1732
const GArray * dpibs_growing
Definition wtap.h:1746
int snaplen
Definition wtap.h:1729
Wiretap dumper handle and associated state.
Definition wtap_module.h:163
ERF Ethernet subheader providing the frame offset for Ethernet ERF records.
Definition wtap.h:1083
uint8_t pad
Definition wtap.h:1085
uint8_t offset
Definition wtap.h:1084
Header metadata for a file-type-specific event or report record.
Definition wtap.h:1531
union wtap_pseudo_header pseudo_header
Definition wtap.h:1536
uint32_t record_len
Definition wtap.h:1534
int file_type_subtype
Definition wtap.h:1532
unsigned record_type
Definition wtap.h:1533
Header metadata for a captured network packet.
Definition wtap.h:1448
uint32_t caplen
Definition wtap.h:1449
uint32_t interface_id
Definition wtap.h:1452
int pkt_encap
Definition wtap.h:1451
union wtap_pseudo_header pseudo_header
Definition wtap.h:1454
uint32_t len
Definition wtap.h:1450
Plugin registration callback table.
Definition wtap.h:3439
Definition file_wrappers.c:96
Represents a single capture record read from or written to a capture file, regardless of record type.
Definition wtap.h:1599
wtap_syscall_header syscall_header
Definition wtap.h:1613
bool block_was_modified
Definition wtap.h:1627
unsigned rec_type
Definition wtap.h:1600
unsigned section_number
Definition wtap.h:1602
const char * rec_type_name
Definition wtap.h:1605
wtap_packet_header packet_header
Definition wtap.h:1611
wtap_block_t block
Block-level metadata associated with this record.
Definition wtap.h:1625
wtap_ft_specific_header ft_specific_header
Definition wtap.h:1612
wtap_custom_block_header custom_block_header
Definition wtap.h:1615
wtap_systemd_journal_export_header systemd_journal_export_header
Definition wtap.h:1614
int tsprec
Definition wtap.h:1604
Buffer options_buf
Reusable buffer holding serialized file-type-specific option data for this record.
Definition wtap.h:1634
uint32_t presence_flags
Definition wtap.h:1601
nstime_t ts
Definition wtap.h:1603
Buffer data
Definition wtap.h:1636
Header metadata for a system call record (e.g. from Sysdig/Falco captures).
Definition wtap.h:1542
uint16_t cpu_id
Definition wtap.h:1553
uint32_t event_data_len
Definition wtap.h:1549
const char * pathname
Definition wtap.h:1543
uint64_t thread_id
Definition wtap.h:1547
uint64_t timestamp
Definition wtap.h:1546
uint32_t nparams
Definition wtap.h:1550
uint32_t flags
Definition wtap.h:1551
unsigned record_type
Definition wtap.h:1544
uint16_t event_type
Definition wtap.h:1552
uint32_t event_len
Definition wtap.h:1548
int byte_order
Definition wtap.h:1545
Header metadata for a systemd journal export record.
Definition wtap.h:1559
uint32_t record_len
Definition wtap.h:1560
Companion metadata block for Lua-based file writers registered via wslua, carrying the write-open cal...
Definition wtap.h:1776
void * wslua_data
Definition wtap.h:1778
int(* wslua_can_write_encap)(int, void *)
Definition wtap.h:1777
Definition wtap_module.h:58
wtap_new_secrets_callback_t add_new_secrets
Definition wtap_module.h:113
const char * app_env_var_prefix
Definition wtap_module.h:74
int file_type_subtype
Definition wtap_module.h:62
wtap_new_ipv4_callback_t add_new_ipv4
Definition wtap_module.h:111
wtap_new_ipv6_callback_t add_new_ipv6
Definition wtap_module.h:112
Union representing physical layer information for IEEE 802.11 variants.
Definition wtap.h:834
struct ieee_802_11_fhss info_11_fhss
Definition wtap.h:835
struct ieee_802_11ac info_11ac
Definition wtap.h:840
struct ieee_802_11n info_11n
Definition wtap.h:839
struct ieee_802_11g info_11g
Definition wtap.h:838
struct ieee_802_11ax info_11ax
Definition wtap.h:842
struct ieee_802_11b info_11b
Definition wtap.h:836
struct ieee_802_11be info_11be
Definition wtap.h:843
struct ieee_802_11ad info_11ad
Definition wtap.h:841
struct ieee_802_11a info_11a
Definition wtap.h:837
Pseudo-header metadata for packets in K12 capture files.
Definition wtap.h:990
uint16_t vp
Definition wtap.h:997
uint16_t cid
Definition wtap.h:999
uint16_t vc
Definition wtap.h:998
uint32_t ds0mask
DS0 channel bitmask.
Definition wtap.h:1008
Protocol-specific subheader union.
Definition wtap.h:1310
struct eth_phdr eth
Definition wtap.h:1311
struct atm_phdr atm
Definition wtap.h:1312
struct ieee_802_11_phdr ieee_802_11
Definition wtap.h:1313
Top-level union of all Wiretap pseudo-headers.
Definition wtap.h:1354
struct l1event_phdr l1event
Definition wtap.h:1373
struct lapd_phdr lapd
Definition wtap.h:1367
struct i2c_phdr i2c
Definition wtap.h:1374
struct p2p_phdr p2p
Definition wtap.h:1360
struct ieee_802_11_phdr ieee_802_11
Definition wtap.h:1361
struct k12_phdr k12
Definition wtap.h:1366
struct btmon_phdr btmon
Definition wtap.h:1372
struct nokia_phdr nokia
Definition wtap.h:1377
struct ber_phdr ber
Definition wtap.h:1382
struct sita_phdr sita
Definition wtap.h:1370
struct bthci_phdr bthci
Definition wtap.h:1371
struct llcp_phdr llcp
Definition wtap.h:1378
struct mtp2_phdr mtp2
Definition wtap.h:1365
struct logcat_phdr logcat
Definition wtap.h:1379
struct atm_phdr atm
Definition wtap.h:1358
struct dte_dce_phdr dte_dce
Definition wtap.h:1356
struct isdn_phdr isdn
Definition wtap.h:1357
struct catapult_dct2000_phdr dct2000
Definition wtap.h:1368
struct irda_phdr irda
Definition wtap.h:1363
struct netmon_phdr netmon
Definition wtap.h:1380
struct gsm_um_phdr gsm_um
Definition wtap.h:1375
struct nettl_phdr nettl
Definition wtap.h:1364
struct cosine_phdr cosine
Definition wtap.h:1362
struct erf_mc_phdr erf
Definition wtap.h:1369
struct ascend_phdr ascend
Definition wtap.h:1359
struct nstr_phdr nstr
Definition wtap.h:1376
struct mmodule_phdr mmodule
Definition wtap.h:1383
struct procmon_phdr procmon
Definition wtap.h:1381
struct eth_phdr eth
Definition wtap.h:1355
WS_DLL_PUBLIC bool wtap_dump_can_open(int filetype)
Check if a file type can be opened for dumping.
Definition file_access.c:2070
WS_DLL_PUBLIC void wtap_buffer_append_epdu_tag(Buffer *buf, uint16_t epdu_tag, const uint8_t *data, uint16_t data_len)
Generates arbitrary packet data in "exported PDU" format and appends it to buf.
Definition wtap.c:2290
WS_DLL_PUBLIC GSList * wtap_get_all_file_extensions_list(void)
Return a list of all extensions that are used by all file types that we can read, including compresse...
Definition file_access.c:2014
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open(const char *filename, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Opens a new capture file for writing.
Definition file_access.c:2243
void(* wtap_new_secrets_callback_t)(uint32_t secrets_type, const void *secrets, unsigned size)
Callback type for receiving new decryption secrets.
Definition wtap.h:2203
WS_DLL_PUBLIC int wtap_register_file_type_subtype(const struct file_type_subtype_info *fi)
Register a file type/subtype.
Definition file_access.c:1174
WS_DLL_PUBLIC bool wtap_dump_flush(wtap_dumper *wdh, int *err)
Flushes the dump file.
Definition file_access.c:2565
WS_DLL_PUBLIC int64_t wtap_file_size(wtap *wth, int *err)
Get the size of the capture file.
Definition wtap.c:81
WS_DLL_PUBLIC GSList * wtap_get_all_capture_file_extensions_list(void)
Return a list of all extensions that are used by all capture file types, including compressed extensi...
Definition file_access.c:1965
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open_tempfile(const char *tmpdir, char **filenamep, const char *pfx, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for a temporary file.
Definition file_access.c:2285
option_support_t
Indicates how a file format supports a given option type.
Definition wtap.h:1978
@ MULTIPLE_OPTIONS_SUPPORTED
Definition wtap.h:1981
@ OPTION_NOT_SUPPORTED
Definition wtap.h:1979
@ ONE_OPTION_SUPPORTED
Definition wtap.h:1980
WS_DLL_PUBLIC GSList * wtap_get_file_extensions_list(int file_type_subtype, bool include_compressed)
Return a list of file extensions that are used by the specified file type and subtype.
Definition file_access.c:1908
struct hashipv6 hashipv6_t
Hash table entry for a resolved or unresolved IPv6 address.
WS_DLL_PUBLIC GArray * wtap_get_savable_file_types_subtypes_for_file(int file_type_subtype, const GArray *file_encaps, uint32_t required_comment_types, ft_sort_order sort_order)
Get savable file type/subtype candidates for saving a capture file.
Definition file_access.c:1457
WS_DLL_PUBLIC char * wtap_unwritable_rec_type_err_string(const wtap_rec *rec)
Return an error string for WTAP_ERR_UNWRITABLE_REC_TYPE.
Definition wtap.c:1790
WS_DLL_PUBLIC int wtap_plugins_supported(void)
Query whether libwiretap plugin loading is available.
Definition wtap.c:57
WS_DLL_PUBLIC const char * wtap_encap_description(int encap)
Get a human-readable description for an encapsulation type.
Definition wtap.c:1412
WS_DLL_PUBLIC wtap_block_t wtap_file_get_shb(wtap *wth, unsigned shb_num)
Gets existing section header block, not for new file.
Definition wtap.c:146
WS_DLL_PUBLIC const char * wtap_file_type_subtype_description(int file_type_subtype)
Get a human-readable description for a file type/subtype.
Definition file_access.c:1633
WS_DLL_PUBLIC void wtap_dump_params_cleanup(wtap_dump_params *params)
Free memory associated with the wtap_dump_params when it is no longer in use by wtap_dumper.
Definition wtap.c:644
void(* wtap_new_ipv6_callback_t)(const ws_in6_addr *addrp, const char *name, const bool static_entry)
Callback type for registering new IPv6 hostnames.
Definition wtap.h:2179
WS_DLL_PUBLIC wtapng_iface_descriptions_t * wtap_file_get_idb_info(wtap *wth)
Gets existing interface descriptions.
Definition wtap.c:198
WS_DLL_PUBLIC void wtap_setup_packet_rec(wtap_rec *rec, int encap)
Set up a wtap_rec for a packet (REC_TYPE_PACKET).
Definition wtap.c:1800
WS_DLL_PUBLIC GSList * wtap_get_file_extension_type_extensions(unsigned extension_type)
Get the list of extensions for a file extension type.
Definition file_access.c:208
WS_DLL_PUBLIC void wtap_deregister_open_info(const char *name)
Deregister an open_info handler by name.
Definition file_access.c:500
struct hashipv4 hashipv4_t
Hash table entry for a resolved or unresolved IPv4 address.
WS_DLL_PUBLIC bool wtap_dump_close(wtap_dumper *wdh, bool *needs_reload, int *err, char **err_info)
Definition file_access.c:2594
WS_DLL_PUBLIC void wtap_set_bytes_dumped(wtap_dumper *wdh, uint64_t bytes_dumped)
Set the number of bytes dumped by a capture file.
Definition file_access.c:2638
WS_DLL_PUBLIC wtap_block_t wtap_get_next_interface_description(wtap *wth)
Gets next interface description.
Definition wtap.c:221
ft_sort_order
Controls the sort key used when enumerating or presenting file type lists.
Definition wtap.h:3079
@ FT_SORT_BY_NAME
Definition wtap.h:3080
@ FT_SORT_BY_DESCRIPTION
Definition wtap.h:3081
WS_DLL_PUBLIC bool wtap_read(wtap *wth, wtap_rec *rec, int *err, char **err_info, int64_t *offset)
Read the next record in the file, filling in *phdr and *buf.
Definition wtap.c:1861
WS_DLL_PUBLIC void wtap_buffer_append_epdu_string(Buffer *buf, uint16_t epdu_tag, const char *val)
Generates packet data for a string in "exported PDU" format. For filetype readers to transform non-pa...
Definition wtap.c:2337
WS_DLL_PUBLIC void wtap_free_idb_info(wtapng_iface_descriptions_t *idb_info)
Free's a interface description block and all of its members.
Definition wtap.c:396
WS_DLL_PUBLIC struct wtap * wtap_open_offline(const char *filename, unsigned int type, int *err, char **err_info, bool do_random, const char *app_env_var_prefix)
Open a capture file for offline analysis.
Definition file_access.c:848
WS_DLL_PUBLIC int wtap_dump_file_type_subtype(const wtap_dumper *wdh)
Get the file type subtype of a dump file.
Definition file_access.c:2626
WS_DLL_PUBLIC int wtap_file_type_subtype(wtap *wth)
Get the file type subtype.
Definition wtap.c:104
WS_DLL_PUBLIC void wtap_register_file_type_extension(const struct file_extension_info *ei)
Register file extension information for a file type.
Definition file_access.c:152
WS_DLL_PUBLIC const char * wtap_get_file_extension_type_name(int extension_type)
Get the short name for a file extension type.
Definition file_access.c:166
WS_DLL_PUBLIC bool wtap_dump_add_idb(wtap_dumper *wdh, wtap_block_t idb, int *err, char **err_info)
Add an IDB to the list of IDBs for a file we're writing. Makes a copy of the IDB, so it can be freed ...
Definition file_access.c:2527
wtap_open_type
Strategy used to identify a file format.
Definition wtap.h:1880
@ OPEN_INFO_MAGIC
Definition wtap.h:1881
@ OPEN_INFO_HEURISTIC
Definition wtap.h:1882
WS_DLL_PUBLIC void wtap_dump_params_discard_decryption_secrets(wtap_dump_params *params)
Remove any decryption secret information from the per-file information; used if we're stripping decry...
Definition wtap.c:631
WS_DLL_PUBLIC void wtap_fdclose(wtap *wth)
Close all file descriptors for the current wiretap file.
Definition wtap.c:1608
wtap_open_return_val
For registering file types that we can open.
Definition wtap.h:1851
@ WTAP_OPEN_MINE
Definition wtap.h:1853
@ WTAP_OPEN_NOT_MINE
Definition wtap.h:1852
@ WTAP_OPEN_ERROR
Definition wtap.h:1854
WS_DLL_PUBLIC uint64_t wtap_get_bytes_dumped(const wtap_dumper *wdh)
Get the number of bytes dumped by a packet capture.
Definition file_access.c:2632
#define MAX_ERF_EHDR
Definition wtap.h:1078
WS_DLL_PUBLIC void wtap_rec_reset(wtap_rec *rec)
Re-initialize a wtap_rec structure.
Definition wtap.c:2127
WS_DLL_PUBLIC bool wtap_has_open_info(const char *name)
Check if an open_info handler with the given name is registered.
Definition file_access.c:524
WS_DLL_PUBLIC int wtap_dump_required_file_encap_type(const GArray *file_encaps)
Determine the required per-file encapsulation type.
Definition file_access.c:1291
WS_DLL_PUBLIC void wtap_dump_discard_name_resolution(wtap_dumper *wdh)
Discard name resolution information for a dump file.
Definition file_access.c:2663
WS_DLL_PUBLIC int wtap_file_encap(wtap *wth)
Get the encapsulation type for the capture file.
Definition wtap.c:116
WS_DLL_PUBLIC void wtap_dump_params_discard_name_resolution(wtap_dump_params *params)
Remove any name resolution information from the per-file information; used if we're stripping name re...
Definition wtap.c:625
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open_stdout(int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for the standard output.
Definition file_access.c:2388
WS_DLL_PUBLIC void wtap_dump_params_init_no_idbs(wtap_dump_params *params, wtap *wth)
Initialize the per-file information based on an existing file, but don't copy over the interface info...
Definition wtap.c:602
WS_DLL_PUBLIC wtap_dumper * wtap_dump_fdopen(int fd, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for an existing file descriptor.
Definition file_access.c:2350
WS_DLL_PUBLIC void wtap_buffer_append_epdu_uint(Buffer *buf, uint16_t epdu_tag, uint32_t val)
Generates packet data for an unsigned integer in "exported PDU" format. For filetype readers to trans...
Definition wtap.c:2321
WS_DLL_PUBLIC void wtap_dump_discard_decryption_secrets(wtap_dumper *wdh)
Discard decryption secrets for a dump file.
Definition file_access.c:2675
WS_DLL_PUBLIC const nstime_t * wtap_file_start_ts(wtap *wth)
Get the start timestamp of the capture file.
Definition wtap.c:128
WS_DLL_PUBLIC int wtap_get_num_file_type_extensions(void)
Return the number of registered file type extension groups.
Definition file_access.c:160
WS_DLL_PUBLIC void wtap_setup_custom_block_rec(wtap_rec *rec, uint32_t pen, uint32_t payload_length, bool copy_allowed)
Set up a wtap_rec for a custom block.
Definition wtap.c:1850
WS_DLL_PUBLIC const char * wtap_strerror(int err)
Return a human-readable error string for a WTAP error code.
Definition wtap.c:1557
WS_DLL_PUBLIC unsigned wtap_file_get_shb_global_interface_id(wtap *wth, unsigned shb_num, uint32_t interface_id)
Gets the unique interface id for a SHB's interface.
Definition wtap.c:155
WS_DLL_PUBLIC unsigned wtap_file_get_num_shbs(wtap *wth)
Gets number of section header blocks.
Definition wtap.c:140
WS_DLL_PUBLIC void wtap_register_plugin(const wtap_plugin *plug)
Register a wiretap plugin.
WS_DLL_PUBLIC void wtap_deregister_file_type_subtype(const int file_type_subtype)
Deregister a previously registered file type/subtype.
Definition file_access.c:1251
WS_DLL_PUBLIC void wtap_dump_params_init(wtap_dump_params *params, wtap *wth)
Initialize the per-file information based on an existing file.
Definition wtap.c:575
WS_DLL_PUBLIC bool wtap_dump(wtap_dumper *wdh, const wtap_rec *rec, int *err, char **err_info)
Write a record to the dump file.
Definition file_access.c:2557
WS_DLL_PUBLIC void wtap_free_extensions_list(GSList *extensions)
Free a list of file extension strings returned by extension helpers.
Definition file_access.c:2041
WS_DLL_PUBLIC bool wtap_uses_lua_filehandler(const wtap *wth)
Check whether a wtap handle uses a Lua-based file handler.
Definition file_access.c:544
WS_DLL_PUBLIC void wtap_write_shb_comment(wtap *wth, char *comment)
Sets or replaces the section header comment.
Definition wtap.c:190
block_support_t
Indicates how many instances of a given block type a file format supports.
Definition wtap.h:2014
@ MULTIPLE_BLOCKS_SUPPORTED
Definition wtap.h:2017
@ ONE_BLOCK_SUPPORTED
Definition wtap.h:2016
@ BLOCK_NOT_SUPPORTED
Definition wtap.h:2015
struct wtap_wslua_file_info wtap_wslua_file_info_t
Companion metadata block for Lua-based file writers registered via wslua, carrying the write-open cal...
WS_DLL_PUBLIC void init_open_routines(void)
Initialize registered file open routines.
Definition file_access.c:419
WS_DLL_PUBLIC int64_t wtap_read_so_far(wtap *wth)
Return an approximation of the amount of data read sequentially.
Definition wtap.c:2081
WS_DLL_PUBLIC void wtap_file_add_decryption_secrets(wtap *wth, const wtap_block_t dsb)
Adds a Decryption Secrets Block to the open wiretap session.
Definition wtap.c:262
WS_DLL_PUBLIC void wtap_set_cb_new_secrets(wtap *wth, wtap_new_secrets_callback_t add_new_secrets)
Set the callback for receiving new decryption secrets.
Definition wtap.c:1729
WS_DLL_PUBLIC void wtap_setup_systemd_journal_export_rec(wtap_rec *rec)
Set up a wtap_rec for a systemd journal export entry.
Definition wtap.c:1840
WS_DLL_PUBLIC void wtap_cleanup(void)
Clean up libwiretap internal registrations and plugin state.
Definition wtap.c:2390
WS_DLL_PUBLIC int wtap_pcapng_file_type_subtype(void)
Get the file type/subtype identifier for pcapng.
Definition file_access.c:1730
void cleanup_open_routines(void)
Clean up registered file open routines.
Definition file_access.c:2860
WS_DLL_PUBLIC void wtap_cleareof(wtap *wth)
Clear EOF status for a wiretap file.
Definition wtap.c:1648
struct addrinfo_lists addrinfo_lists_t
Aggregates lists of resolved IPv4 and IPv6 addresses for writing into a pcapng Name Resolution Block ...
WS_DLL_PUBLIC const nstime_t * wtap_file_end_ts(wtap *wth)
Get the end timestamp of the capture file.
Definition wtap.c:134
WS_DLL_PUBLIC unsigned wtap_file_get_num_dsbs(wtap *wth)
Gets number of decryption secrets blocks.
Definition wtap.c:244
WS_DLL_PUBLIC ws_compression_type wtap_get_compression_type(wtap *wth)
Get the compression type used for the capture file.
Definition file_wrappers.c:46
WS_DLL_PUBLIC int wtap_pcap_nsec_file_type_subtype(void)
Get the file type/subtype identifier for pcap with nanosecond timestamps.
Definition file_access.c:1716
WS_DLL_PUBLIC void wtap_close(wtap *wth)
Fully close the wiretap file and release all resources.
Definition wtap.c:1617
WS_DLL_PUBLIC void wtap_setup_syscall_rec(wtap_rec *rec)
Set up a wtap_rec for a system call.
Definition pcapng-sysdig.c:40
WS_DLL_PUBLIC bool wtap_dump_set_addrinfo_list(wtap_dumper *wdh, addrinfo_lists_t *addrinfo_lists)
Set the address information list for a dump file.
Definition file_access.c:2652
WS_DLL_PUBLIC void wtap_rec_apply_snapshot(wtap_rec *rec, uint32_t snaplen)
Apply a snapshot length to a wtap_rec.
Definition wtap.c:2101
WS_DLL_PUBLIC int wtap_file_tsprec(wtap *wth)
Get the timestamp precision for the capture file.
Definition wtap.c:122
WS_DLL_PUBLIC void wtap_init(bool load_wiretap_plugins, const char *app_env_var_prefix, const struct file_extension_info *file_extensions, unsigned num_extensions)
Initialize the Wiretap library.
Definition wtap.c:2371
WS_DLL_PUBLIC bool wtap_dump_can_write_encap(int file_type_subtype, int encap)
Check if a file type/subtype supports writing a given encapsulation.
Definition file_access.c:1304
WS_DLL_PUBLIC bool wtap_dump_can_write(const GArray *file_encaps, uint32_t required_comment_types)
Determine whether a capture file can be written with the specified options.
Definition file_access.c:1406
WS_DLL_PUBLIC const char * wtap_file_type_subtype_name(int file_type_subtype)
Get a short name for a file type/subtype.
Definition file_access.c:1646
WS_DLL_PUBLIC void wtap_setup_ft_specific_report_rec(wtap_rec *rec, int file_type_subtype, unsigned record_type)
Set up a wtap_rec for a file-type specific report.
Definition wtap.c:1826
WS_DLL_PUBLIC int wtap_get_num_encap_types(void)
Return the number of known encapsulation types.
Definition wtap.c:1378
WS_DLL_PUBLIC void wtap_rec_cleanup(wtap_rec *rec)
Clean up a wtap_rec structure.
Definition wtap.c:2136
WS_DLL_PUBLIC const char * wtap_tsprec_string(int tsprec)
Convert a timestamp precision constant to a string.
Definition wtap.c:1455
WS_DLL_PUBLIC unsigned int open_info_name_to_type(const char *name)
Convert an open_info short name to its numeric type.
Definition file_access.c:582
WS_DLL_PUBLIC wtap_block_t wtap_file_get_dsb(wtap *wth, unsigned dsb_num)
Gets existing decryption secrets block, not for new file.
Definition wtap.c:253
WS_DLL_PUBLIC bool wtap_dump_can_compress(int file_type_subtype)
Check if a file type/subtype supports compression.
Definition file_access.c:2102
WS_DLL_PUBLIC unsigned wtap_snapshot_length(wtap *wth)
Get the snapshot length for the capture file.
Definition wtap.c:110
WS_DLL_PUBLIC bool wtap_fdreopen(wtap *wth, const char *filename, int *err)
Reopen the random-access file descriptor for the current file.
Definition file_access.c:1033
WS_DLL_PUBLIC void wtap_rec_init(wtap_rec *rec, size_t space)
Initialize a wtap_rec structure.
Definition wtap.c:2088
WS_DLL_PUBLIC bool wtap_file_discard_decryption_secrets(wtap *wth)
Remove any decryption secret information from the per-file information; used if we're stripping decry...
Definition wtap.c:271
WS_DLL_PUBLIC void wtap_setup_ft_specific_event_rec(wtap_rec *rec, int file_type_subtype, unsigned record_type)
Set up a wtap_rec for a file-type specific event.
Definition wtap.c:1812
WS_DLL_PUBLIC void wtap_set_cb_new_ipv6(wtap *wth, wtap_new_ipv6_callback_t add_new_ipv6)
Set the callback for adding new IPv6 hostnames.
Definition wtap.c:1702
WS_DLL_PUBLIC const char * wtap_default_file_extension(int file_type_subtype)
Get the default file extension for a file type/subtype.
Definition file_access.c:2057
WS_DLL_PUBLIC int wtap_pcap_file_type_subtype(void)
Get the file type/subtype identifier for classic pcap (microsecond timestamps).
Definition file_access.c:1702
WS_DLL_PUBLIC void wtap_register_open_info(struct open_info *oi, const bool first_routine)
Register an open_info probe/open handler.
Definition file_access.c:464
WS_DLL_PUBLIC int wtap_buffer_append_epdu_end(Buffer *buf)
Close off a set of "exported PDUs" added to the buffer. For filetype readers to transform non-packeti...
Definition wtap.c:2354
WS_DLL_PUBLIC bool wtap_addrinfo_list_empty(const addrinfo_lists_t *addrinfo_lists)
Checks if the address information list is empty.
Definition file_access.c:2644
WS_DLL_PUBLIC wtapng_dpib_lookup_info_t * wtap_file_get_dpib_lookup_info(wtap *wth)
Gets the DPIB lookup information for the current file.
Definition wtap.c:210
WS_DLL_PUBLIC block_support_t wtap_file_type_subtype_supports_block(int file_type_subtype, wtap_block_type_t type)
Determine whether a capture file format supports a given block type.
Definition file_access.c:1744
WS_DLL_PUBLIC GArray * wtap_get_writable_file_types_subtypes(ft_sort_order sort_order)
Get a list of all writable file type/subtype values.
Definition file_access.c:1569
WS_DLL_PUBLIC const char * wtap_encap_name(int encap)
Get a short name for an encapsulation type.
Definition wtap.c:1398
WS_DLL_PUBLIC int wtap_register_encap_type(const char *description, const char *name)
Register a new packet encapsulation type.
Definition wtap.c:1384
WS_DLL_PUBLIC char * wtap_get_debug_if_descr(const wtap_block_t if_descr, const int indent, const char *line_end)
Gets a debug string of an interface description.
Definition wtap.c:406
#define PHDR_802_11BE_MAX_USERS
Definition wtap.h:806
WS_DLL_PUBLIC wtap_block_t wtap_file_get_nrb(wtap *wth)
Gets existing name resolution block, not for new file.
Definition wtap.c:545
WS_DLL_PUBLIC void wtap_set_cb_new_ipv4(wtap *wth, wtap_new_ipv4_callback_t add_new_ipv4)
Set the callback for adding new IPv4 hostnames.
Definition wtap.c:1682
WS_DLL_PUBLIC int wtap_name_to_file_type_subtype(const char *name)
Convert a file type/subtype name to its identifier.
Definition file_access.c:1670
WS_DLL_PUBLIC void wtap_sequential_close(wtap *wth)
Close the sequential-access side of the file.
Definition wtap.c:1584
void(* wtap_new_ipv4_callback_t)(const unsigned addr, const char *name, const bool static_entry)
Callback type for registering new IPv4 hostnames.
Definition wtap.h:2155
WS_DLL_PUBLIC option_support_t wtap_file_type_subtype_supports_option(int file_type_subtype, wtap_block_type_t type, unsigned opttype)
Determine whether a capture file format supports a specific option for a block.
Definition file_access.c:1779
WS_DLL_PUBLIC int wtap_name_to_encap(const char *short_name)
Convert a short encapsulation name to its WTAP_ENCAP_ value.
Definition wtap.c:1426
WS_DLL_PUBLIC bool wtap_seek_read(wtap *wth, int64_t seek_off, wtap_rec *rec, int *err, char **err_info)
Read the record at a specified offset in a capture file, filling in *phdr and *buf.
Definition wtap.c:2158
wtap_block_type_t
Currently supported blocks; these are not the pcapng block type values for them, they're identifiers ...
Definition wtap_opttypes.h:234
struct wtapng_dpib_lookup_info_s wtapng_dpib_lookup_info_t
struct wtapng_iface_descriptions_s wtapng_iface_descriptions_t