Wireshark 4.7.2
The Wireshark network protocol analyzer
Loading...
Searching...
No Matches
wtap.h
Go to the documentation of this file.
1
8
9#ifndef __WTAP_H__
10#define __WTAP_H__
11
12#include <wireshark.h>
13#include <time.h>
14#include <wsutil/array.h>
15#include <wsutil/buffer.h>
16#include <wsutil/nstime.h>
17#include <wsutil/inet_addr.h>
18#include <wsutil/file_compressed.h>
19#include "wtap_opttypes.h"
20
21#ifdef __cplusplus
22extern "C" {
23#endif /* __cplusplus */
24
25/* Encapsulation types. Choose names that truly reflect
26 * what is contained in the packet trace file.
27 *
28 * WTAP_ENCAP_PER_PACKET is a value passed to "wtap_dump_open()" or
29 * "wtap_dump_fdopen()" to indicate that there is no single encapsulation
30 * type for all packets in the file; this may cause those routines to
31 * fail if the capture file format being written can't support that.
32 * It's also returned by "wtap_file_encap()" for capture files that
33 * don't have a single encapsulation type for all packets in the file.
34 *
35 * WTAP_ENCAP_UNKNOWN is returned by "wtap_pcap_encap_to_wtap_encap()"
36 * if it's handed an unknown encapsulation. It is also used by file
37 * types for encapsulations which are unsupported by libwiretap.
38 *
39 * WTAP_ENCAP_NONE is an initial value used by file types like pcapng
40 * that do not have a single file level encapsulation type. If and when
41 * something that indicate encapsulation is read, the encapsulation will
42 * change (possibly to WTAP_ENCAP_PER_PACKET) and appropriate IDBs will
43 * be generated. If a file type uses this value, it MUST provide IDBs
44 * (possibly fake) when the encapsulation changes; otherwise, it should
45 * return WTAP_ENCAP_UNKNOWN so that attempts to write an output file
46 * without reading the entire input file first fail gracefully.
47 *
48 * WTAP_ENCAP_FDDI_BITSWAPPED is for FDDI captures on systems where the
49 * MAC addresses you get from the hardware are bit-swapped. Ideally,
50 * the driver would tell us that, but I know of none that do, so, for
51 * now, we base it on the machine on which we're *reading* the
52 * capture, rather than on the machine on which the capture was taken
53 * (they're probably likely to be the same). We assume that they're
54 * bit-swapped on everything except for systems running Ultrix, Alpha
55 * systems, and BSD/OS systems (that's what "tcpdump" does; I guess
56 * Digital decided to bit-swap addresses in the hardware or in the
57 * driver, and I guess BSDI bit-swapped them in the driver, given that
58 * BSD/OS generally runs on Boring Old PC's). If we create a wiretap
59 * save file format, we'd use the WTAP_ENCAP values to flag the
60 * encapsulation of a packet, so there we'd at least be able to base
61 * it on the machine on which the capture was taken.
62 *
63 * WTAP_ENCAP_LINUX_ATM_CLIP is the encapsulation you get with the
64 * ATM on Linux code from <http://linux-atm.sourceforge.net/>;
65 * that code adds a DLT_ATM_CLIP DLT_ code of 19, and that
66 * encapsulation isn't the same as the DLT_ATM_RFC1483 encapsulation
67 * presumably used on some BSD systems, which we turn into
68 * WTAP_ENCAP_ATM_RFC1483.
69 *
70 * WTAP_ENCAP_NULL corresponds to DLT_NULL from "libpcap". This
71 * corresponds to
72 *
73 * 1) PPP-over-HDLC encapsulation, at least with some versions
74 * of ISDN4BSD (but not the current ones, it appears, unless
75 * I've missed something);
76 *
77 * 2) a 4-byte header containing the AF_ address family, in
78 * the byte order of the machine that saved the capture,
79 * for the packet, as used on many BSD systems for the
80 * loopback device and some other devices, or a 4-byte header
81 * containing the AF_ address family in network byte order,
82 * as used on recent OpenBSD systems for the loopback device;
83 *
84 * 3) a 4-byte header containing 2 octets of 0 and an Ethernet
85 * type in the byte order from an Ethernet header, that being
86 * what older versions of "libpcap" on Linux turn the Ethernet
87 * header for loopback interfaces into (0.6.0 and later versions
88 * leave the Ethernet header alone and make it DLT_EN10MB). */
89#define WTAP_ENCAP_NONE -2
90#define WTAP_ENCAP_PER_PACKET -1
91#define WTAP_ENCAP_UNKNOWN 0
92#define WTAP_ENCAP_ETHERNET 1
93#define WTAP_ENCAP_TOKEN_RING 2
94#define WTAP_ENCAP_SLIP 3
95#define WTAP_ENCAP_PPP 4
96#define WTAP_ENCAP_FDDI 5
97#define WTAP_ENCAP_FDDI_BITSWAPPED 6
98#define WTAP_ENCAP_RAW_IP 7
99#define WTAP_ENCAP_ARCNET 8
100#define WTAP_ENCAP_ARCNET_LINUX 9
101#define WTAP_ENCAP_ATM_RFC1483 10
102#define WTAP_ENCAP_LINUX_ATM_CLIP 11
103#define WTAP_ENCAP_LAPB 12
104#define WTAP_ENCAP_ATM_PDUS 13
105#define WTAP_ENCAP_ATM_PDUS_UNTRUNCATED 14
106#define WTAP_ENCAP_NULL 15
107#define WTAP_ENCAP_ASCEND 16
108#define WTAP_ENCAP_ISDN 17
109#define WTAP_ENCAP_IP_OVER_FC 18
110#define WTAP_ENCAP_PPP_WITH_PHDR 19
111#define WTAP_ENCAP_IEEE_802_11 20
112#define WTAP_ENCAP_IEEE_802_11_PRISM 21
113#define WTAP_ENCAP_IEEE_802_11_WITH_RADIO 22
114#define WTAP_ENCAP_IEEE_802_11_RADIOTAP 23
115#define WTAP_ENCAP_IEEE_802_11_AVS 24
116#define WTAP_ENCAP_SLL 25
117#define WTAP_ENCAP_FRELAY 26
118#define WTAP_ENCAP_FRELAY_WITH_PHDR 27
119#define WTAP_ENCAP_CHDLC 28
120#define WTAP_ENCAP_CISCO_IOS 29
121#define WTAP_ENCAP_LOCALTALK 30
122#define WTAP_ENCAP_OLD_PFLOG 31
123#define WTAP_ENCAP_HHDLC 32
124#define WTAP_ENCAP_DOCSIS 33
125#define WTAP_ENCAP_COSINE 34
126#define WTAP_ENCAP_WFLEET_HDLC 35
127#define WTAP_ENCAP_SDLC 36
128#define WTAP_ENCAP_TZSP 37
129#define WTAP_ENCAP_ENC 38
130#define WTAP_ENCAP_PFLOG 39
131#define WTAP_ENCAP_CHDLC_WITH_PHDR 40
132#define WTAP_ENCAP_BLUETOOTH_H4 41
133#define WTAP_ENCAP_MTP2 42
134#define WTAP_ENCAP_MTP3 43
135#define WTAP_ENCAP_IRDA 44
136#define WTAP_ENCAP_USER0 45
137#define WTAP_ENCAP_USER1 46
138#define WTAP_ENCAP_USER2 47
139#define WTAP_ENCAP_USER3 48
140#define WTAP_ENCAP_USER4 49
141#define WTAP_ENCAP_USER5 50
142#define WTAP_ENCAP_USER6 51
143#define WTAP_ENCAP_USER7 52
144#define WTAP_ENCAP_USER8 53
145#define WTAP_ENCAP_USER9 54
146#define WTAP_ENCAP_USER10 55
147#define WTAP_ENCAP_USER11 56
148#define WTAP_ENCAP_USER12 57
149#define WTAP_ENCAP_USER13 58
150#define WTAP_ENCAP_USER14 59
151#define WTAP_ENCAP_USER15 60
152#define WTAP_ENCAP_SYMANTEC 61
153#define WTAP_ENCAP_APPLE_IP_OVER_IEEE1394 62
154#define WTAP_ENCAP_BACNET_MS_TP 63
155#define WTAP_ENCAP_NETTL_RAW_ICMP 64
156#define WTAP_ENCAP_NETTL_RAW_ICMPV6 65
157#define WTAP_ENCAP_GPRS_LLC 66
158#define WTAP_ENCAP_JUNIPER_ATM1 67
159#define WTAP_ENCAP_JUNIPER_ATM2 68
160#define WTAP_ENCAP_REDBACK 69
161#define WTAP_ENCAP_NETTL_RAW_IP 70
162#define WTAP_ENCAP_NETTL_ETHERNET 71
163#define WTAP_ENCAP_NETTL_TOKEN_RING 72
164#define WTAP_ENCAP_NETTL_FDDI 73
165#define WTAP_ENCAP_NETTL_UNKNOWN 74
166#define WTAP_ENCAP_MTP2_WITH_PHDR 75
167#define WTAP_ENCAP_JUNIPER_PPPOE 76
168#define WTAP_ENCAP_GCOM_TIE1 77
169#define WTAP_ENCAP_GCOM_SERIAL 78
170#define WTAP_ENCAP_NETTL_X25 79
171#define WTAP_ENCAP_K12 80
172#define WTAP_ENCAP_JUNIPER_MLPPP 81
173#define WTAP_ENCAP_JUNIPER_MLFR 82
174#define WTAP_ENCAP_JUNIPER_ETHER 83
175#define WTAP_ENCAP_JUNIPER_PPP 84
176#define WTAP_ENCAP_JUNIPER_FRELAY 85
177#define WTAP_ENCAP_JUNIPER_CHDLC 86
178#define WTAP_ENCAP_JUNIPER_GGSN 87
179#define WTAP_ENCAP_LINUX_LAPD 88
180#define WTAP_ENCAP_CATAPULT_DCT2000 89
181#define WTAP_ENCAP_BER 90
182#define WTAP_ENCAP_JUNIPER_VP 91
183#define WTAP_ENCAP_USB_FREEBSD 92
184#define WTAP_ENCAP_IEEE802_16_MAC_CPS 93
185#define WTAP_ENCAP_NETTL_RAW_TELNET 94
186#define WTAP_ENCAP_USB_LINUX 95
187#define WTAP_ENCAP_MPEG 96
188#define WTAP_ENCAP_PPI 97
189#define WTAP_ENCAP_ERF 98
190#define WTAP_ENCAP_BLUETOOTH_H4_WITH_PHDR 99
191#define WTAP_ENCAP_SITA 100
192#define WTAP_ENCAP_SCCP 101
193#define WTAP_ENCAP_BLUETOOTH_HCI 102 /*raw packets without a transport layer header e.g. H4*/
194#define WTAP_ENCAP_IPMB_KONTRON 103
195#define WTAP_ENCAP_IEEE802_15_4 104
196#define WTAP_ENCAP_X2E_XORAYA 105
197#define WTAP_ENCAP_FLEXRAY 106
198#define WTAP_ENCAP_LIN 107
199#define WTAP_ENCAP_MOST 108
200#define WTAP_ENCAP_CAN20B 109
201#define WTAP_ENCAP_LAYER1_EVENT 110
202#define WTAP_ENCAP_X2E_SERIAL 111
203#define WTAP_ENCAP_I2C_LINUX 112
204#define WTAP_ENCAP_IEEE802_15_4_NONASK_PHY 113
205#define WTAP_ENCAP_TNEF 114
206#define WTAP_ENCAP_USB_LINUX_MMAPPED 115
207#define WTAP_ENCAP_GSM_UM 116
208#define WTAP_ENCAP_DPNSS 117
209#define WTAP_ENCAP_PACKETLOGGER 118
210#define WTAP_ENCAP_NSTRACE_1_0 119
211#define WTAP_ENCAP_NSTRACE_2_0 120
212#define WTAP_ENCAP_FIBRE_CHANNEL_FC2 121
213#define WTAP_ENCAP_FIBRE_CHANNEL_FC2_WITH_FRAME_DELIMS 122
214#define WTAP_ENCAP_JPEG_JFIF 123 /* obsoleted by WTAP_ENCAP_MIME*/
215#define WTAP_ENCAP_IPNET 124
216#define WTAP_ENCAP_SOCKETCAN 125
217#define WTAP_ENCAP_IEEE_802_11_NETMON 126
218#define WTAP_ENCAP_IEEE802_15_4_NOFCS 127
219#define WTAP_ENCAP_RAW_IPFIX 128
220#define WTAP_ENCAP_RAW_IP4 129
221#define WTAP_ENCAP_RAW_IP6 130
222#define WTAP_ENCAP_LAPD 131
223#define WTAP_ENCAP_DVBCI 132
224#define WTAP_ENCAP_MUX27010 133
225#define WTAP_ENCAP_MIME 134
226#define WTAP_ENCAP_NETANALYZER 135
227#define WTAP_ENCAP_NETANALYZER_TRANSPARENT 136
228#define WTAP_ENCAP_IP_OVER_IB_SNOOP 137
229#define WTAP_ENCAP_MPEG_2_TS 138
230#define WTAP_ENCAP_PPP_ETHER 139
231#define WTAP_ENCAP_NFC_LLCP 140
232#define WTAP_ENCAP_NFLOG 141
233#define WTAP_ENCAP_V5_EF 142
234#define WTAP_ENCAP_BACNET_MS_TP_WITH_PHDR 143
235#define WTAP_ENCAP_IXVERIWAVE 144
236#define WTAP_ENCAP_SDH 145
237#define WTAP_ENCAP_DBUS 146
238#define WTAP_ENCAP_AX25_KISS 147
239#define WTAP_ENCAP_AX25 148
240#define WTAP_ENCAP_SCTP 149
241#define WTAP_ENCAP_INFINIBAND 150
242#define WTAP_ENCAP_JUNIPER_SVCS 151
243#define WTAP_ENCAP_USBPCAP 152
244#define WTAP_ENCAP_RTAC_SERIAL 153
245#define WTAP_ENCAP_BLUETOOTH_LE_LL 154
246#define WTAP_ENCAP_WIRESHARK_UPPER_PDU 155
247#define WTAP_ENCAP_STANAG_4607 156
248#define WTAP_ENCAP_STANAG_5066_D_PDU 157
249#define WTAP_ENCAP_NETLINK 158
250#define WTAP_ENCAP_BLUETOOTH_LINUX_MONITOR 159
251#define WTAP_ENCAP_BLUETOOTH_BREDR_BB 160
252#define WTAP_ENCAP_BLUETOOTH_LE_LL_WITH_PHDR 161
253#define WTAP_ENCAP_NSTRACE_3_0 162
254#define WTAP_ENCAP_LOGCAT 163
255#define WTAP_ENCAP_LOGCAT_BRIEF 164
256#define WTAP_ENCAP_LOGCAT_PROCESS 165
257#define WTAP_ENCAP_LOGCAT_TAG 166
258#define WTAP_ENCAP_LOGCAT_THREAD 167
259#define WTAP_ENCAP_LOGCAT_TIME 168
260#define WTAP_ENCAP_LOGCAT_THREADTIME 169
261#define WTAP_ENCAP_LOGCAT_LONG 170
262#define WTAP_ENCAP_PKTAP 171
263#define WTAP_ENCAP_EPON 172
264#define WTAP_ENCAP_IPMI_TRACE 173
265#define WTAP_ENCAP_LOOP 174
266#define WTAP_ENCAP_JSON 175
267#define WTAP_ENCAP_NSTRACE_3_5 176
268#define WTAP_ENCAP_ISO14443 177
269#define WTAP_ENCAP_GFP_T 178
270#define WTAP_ENCAP_GFP_F 179
271#define WTAP_ENCAP_IP_OVER_IB_PCAP 180
272#define WTAP_ENCAP_JUNIPER_VN 181
273#define WTAP_ENCAP_USB_DARWIN 182
274#define WTAP_ENCAP_LORATAP 183
275#define WTAP_ENCAP_3MB_ETHERNET 184
276#define WTAP_ENCAP_VSOCK 185
277#define WTAP_ENCAP_NORDIC_BLE 186
278#define WTAP_ENCAP_NETMON_NET_NETEVENT 187
279#define WTAP_ENCAP_NETMON_HEADER 188
280#define WTAP_ENCAP_NETMON_NET_FILTER 189
281#define WTAP_ENCAP_NETMON_NETWORK_INFO_EX 190
282#define WTAP_ENCAP_MA_WFP_CAPTURE_V4 191
283#define WTAP_ENCAP_MA_WFP_CAPTURE_V6 192
284#define WTAP_ENCAP_MA_WFP_CAPTURE_2V4 193
285#define WTAP_ENCAP_MA_WFP_CAPTURE_2V6 194
286#define WTAP_ENCAP_MA_WFP_CAPTURE_AUTH_V4 195
287#define WTAP_ENCAP_MA_WFP_CAPTURE_AUTH_V6 196
288#define WTAP_ENCAP_JUNIPER_ST 197
289#define WTAP_ENCAP_ETHERNET_MPACKET 198
290#define WTAP_ENCAP_DOCSIS31_XRA31 199
291#define WTAP_ENCAP_DPAUXMON 200
292#define WTAP_ENCAP_RUBY_MARSHAL 201
293#define WTAP_ENCAP_RFC7468 202
294#define WTAP_ENCAP_SYSTEMD_JOURNAL 203 /* Event, not a packet */
295#define WTAP_ENCAP_EBHSCR 204
296#define WTAP_ENCAP_VPP 205
297#define WTAP_ENCAP_IEEE802_15_4_TAP 206
298#define WTAP_ENCAP_LOG_3GPP 207
299#define WTAP_ENCAP_USB_2_0 208
300#define WTAP_ENCAP_MP4 209
301#define WTAP_ENCAP_SLL2 210
302#define WTAP_ENCAP_ZWAVE_SERIAL 211
303#define WTAP_ENCAP_ETW 212
304#define WTAP_ENCAP_ERI_ENB_LOG 213
305#define WTAP_ENCAP_ZBNCP 214
306#define WTAP_ENCAP_USB_2_0_LOW_SPEED 215
307#define WTAP_ENCAP_USB_2_0_FULL_SPEED 216
308#define WTAP_ENCAP_USB_2_0_HIGH_SPEED 217
309#define WTAP_ENCAP_AUTOSAR_DLT 218
310#define WTAP_ENCAP_AUERSWALD_LOG 219
311#define WTAP_ENCAP_ATSC_ALP 220
312#define WTAP_ENCAP_FIRA_UCI 221
313#define WTAP_ENCAP_SILABS_DEBUG_CHANNEL 222
314#define WTAP_ENCAP_MDB 223
315#define WTAP_ENCAP_EMS 224
316#define WTAP_ENCAP_DECT_NR 225
317#define WTAP_ENCAP_MMODULE 226
318#define WTAP_ENCAP_PROCMON 227
319
320/* After adding new item here, please also add new item to encap_table_base array */
321
322#define WTAP_NUM_ENCAP_TYPES wtap_get_num_encap_types()
323
324/* Value to be used as a file type/subtype value if the type is unknown */
325#define WTAP_FILE_TYPE_SUBTYPE_UNKNOWN -1
326
327/* timestamp precision (currently only these values are supported) */
328#define WTAP_TSPREC_UNKNOWN -2
329#define WTAP_TSPREC_PER_PACKET -1
330
331/*
332 * These values are the number of digits of precision after the integral part.
333 * They're the same as WS_TSPREC values; we define them here so that
334 * tools/make-enums.py sees them.
335 */
336#define WTAP_TSPREC_SEC 0
337#define WTAP_TSPREC_100_MSEC 1
338#define WTAP_TSPREC_DSEC 1
339#define WTAP_TSPREC_10_MSEC 2
340#define WTAP_TSPREC_CSEC 2
341#define WTAP_TSPREC_MSEC 3
342#define WTAP_TSPREC_100_USEC 4
343#define WTAP_TSPREC_10_USEC 5
344#define WTAP_TSPREC_USEC 6
345#define WTAP_TSPREC_100_NSEC 7
346#define WTAP_TSPREC_10_NSEC 8
347#define WTAP_TSPREC_NSEC 9
348/* if you add to the above, update wtap_tsprec_string() */
349
350/*
351 * Maximum packet sizes.
352 *
353 * For most link-layer types, we use 262144, which is currently
354 * libpcap's MAXIMUM_SNAPLEN.
355 *
356 * For WTAP_ENCAP_DBUS, the maximum is 128MiB, as per
357 *
358 * https://dbus.freedesktop.org/doc/dbus-specification.html#message-protocol-messages
359 *
360 * For WTAP_ENCAP_EBHSCR, the maximum is 8MiB, as per
361 *
362 * https://www.elektrobit.com/ebhscr
363 *
364 * For WTAP_ENCAP_USBPCAP, the maximum is 128MiB, as per
365 *
366 * https://gitlab.com/wireshark/wireshark/-/issues/15985
367 *
368 * We don't want to write out files that specify a maximum packet size
369 * greater than 262144 if we don't have to, as software reading those
370 * files might allocate a buffer much larger than necessary, wasting memory.
371 */
372#define WTAP_MAX_PACKET_SIZE_STANDARD 262144U
373#define WTAP_MAX_PACKET_SIZE_USBPCAP (128U*1024U*1024U)
374#define WTAP_MAX_PACKET_SIZE_EBHSCR (32U*1024U*1024U)
375#define WTAP_MAX_PACKET_SIZE_DBUS (128U*1024U*1024U)
376
377/*
378 * "Pseudo-headers" are used to supply to the clients of wiretap
379 * per-packet information that's not part of the packet payload
380 * proper.
381 *
382 * NOTE: do not use pseudo-header structures to hold information
383 * used by the code to read a particular capture file type; to
384 * keep that sort of state information, define a private structure
385 * to hold that information in your code, and allocate one of those
386 * structures and set the "priv" member of the wth structure to
387 * point to the allocated structure in the "open" routine for that
388 * capture file type if the open succeeds. See various other capture
389 * file type handlers for examples of that.
390 */
391
392
396struct eth_phdr {
398};
399
400#define FROM_DCE 0x80
401
406 uint8_t flags;
407};
408
412struct isdn_phdr {
413 bool uton;
414 uint8_t channel;
415};
416
417/* Packet "pseudo-header" for ATM capture files.
418 Not all of this information is supplied by all capture types.
419 These originally came from the Network General (DOS-based)
420 ATM Sniffer file format, but we've added some additional
421 items. */
422
423/*
424 * Status bits.
425 */
426#define ATM_RAW_CELL 0x01 /* true if the packet is a single cell */
427#define ATM_NO_HEC 0x02 /* true if the cell has HEC stripped out */
428#define ATM_AAL2_NOPHDR 0x04 /* true if the AAL2 PDU has no pseudo-header */
429#define ATM_REASSEMBLY_ERROR 0x08 /* true if this is an incompletely-reassembled PDU */
430
431/*
432 * AAL types.
433 */
434#define AAL_UNKNOWN 0 /* AAL unknown */
435#define AAL_1 1 /* AAL1 */
436#define AAL_2 2 /* AAL2 */
437#define AAL_3_4 3 /* AAL3/4 */
438#define AAL_5 4 /* AAL5 */
439#define AAL_USER 5 /* User AAL */
440#define AAL_SIGNALLING 6 /* Signaling AAL */
441#define AAL_OAMCELL 7 /* OAM cell */
442
443/*
444 * Traffic types.
445 */
446#define TRAF_UNKNOWN 0 /* Unknown */
447#define TRAF_LLCMX 1 /* LLC multiplexed (RFC 1483) */
448#define TRAF_VCMX 2 /* VC multiplexed (RFC 1483) */
449#define TRAF_LANE 3 /* LAN Emulation */
450#define TRAF_ILMI 4 /* ILMI */
451#define TRAF_FR 5 /* Frame Relay */
452#define TRAF_SPANS 6 /* FORE SPANS */
453#define TRAF_IPSILON 7 /* Ipsilon */
454#define TRAF_UMTS_FP 8 /* UMTS Frame Protocol */
455#define TRAF_GPRS_NS 9 /* GPRS Network Services */
456#define TRAF_SSCOP 10 /* SSCOP */
457
458/*
459 * Traffic subtypes.
460 */
461#define TRAF_ST_UNKNOWN 0 /* Unknown */
462
463/*
464 * For TRAF_VCMX:
465 */
466#define TRAF_ST_VCMX_802_3_FCS 1 /* 802.3 with an FCS */
467#define TRAF_ST_VCMX_802_4_FCS 2 /* 802.4 with an FCS */
468#define TRAF_ST_VCMX_802_5_FCS 3 /* 802.5 with an FCS */
469#define TRAF_ST_VCMX_FDDI_FCS 4 /* FDDI with an FCS */
470#define TRAF_ST_VCMX_802_6_FCS 5 /* 802.6 with an FCS */
471#define TRAF_ST_VCMX_802_3 7 /* 802.3 without an FCS */
472#define TRAF_ST_VCMX_802_4 8 /* 802.4 without an FCS */
473#define TRAF_ST_VCMX_802_5 9 /* 802.5 without an FCS */
474#define TRAF_ST_VCMX_FDDI 10 /* FDDI without an FCS */
475#define TRAF_ST_VCMX_802_6 11 /* 802.6 without an FCS */
476#define TRAF_ST_VCMX_FRAGMENTS 12 /* Fragments */
477#define TRAF_ST_VCMX_BPDU 13 /* BPDU */
478
479/*
480 * For TRAF_LANE:
481 */
482#define TRAF_ST_LANE_LE_CTRL 1 /* LANE: LE Ctrl */
483#define TRAF_ST_LANE_802_3 2 /* LANE: 802.3 */
484#define TRAF_ST_LANE_802_5 3 /* LANE: 802.5 */
485#define TRAF_ST_LANE_802_3_MC 4 /* LANE: 802.3 multicast */
486#define TRAF_ST_LANE_802_5_MC 5 /* LANE: 802.5 multicast */
487
488/*
489 * For TRAF_IPSILON:
490 */
491#define TRAF_ST_IPSILON_FT0 1 /* Ipsilon: Flow Type 0 */
492#define TRAF_ST_IPSILON_FT1 2 /* Ipsilon: Flow Type 1 */
493#define TRAF_ST_IPSILON_FT2 3 /* Ipsilon: Flow Type 2 */
494
498struct atm_phdr {
499 uint32_t flags;
500 uint8_t aal;
501 uint8_t type;
502 uint8_t subtype;
503 uint16_t vpi;
504 uint16_t vci;
505 uint8_t aal2_cid;
506 uint16_t channel;
507 uint16_t cells;
508 uint16_t aal5t_u2u;
509 uint16_t aal5t_len;
510 uint32_t aal5t_chksum;
511};
512
513/* Packet "pseudo-header" for the output from "wandsession", "wannext",
514 "wandisplay", and similar commands on Lucent/Ascend access equipment. */
515
516#define ASCEND_MAX_STR_LEN 64
517
518#define ASCEND_PFX_WDS_X 1
519#define ASCEND_PFX_WDS_R 2
520#define ASCEND_PFX_WDD 3
521#define ASCEND_PFX_ISDN_X 4
522#define ASCEND_PFX_ISDN_R 5
523#define ASCEND_PFX_ETHER 6
524
529 uint16_t type;
530 char user[ASCEND_MAX_STR_LEN];
531 uint32_t sess;
532 char call_num[ASCEND_MAX_STR_LEN];
533 uint32_t chunk;
534 uint32_t task;
535};
536
540struct p2p_phdr {
541 bool sent;
542};
543
544/*
545 * Packet "pseudo-header" information for 802.11.
546 * Radio information is only present in this form for
547 * WTAP_ENCAP_IEEE_802_11_WITH_RADIO. This is used for file formats in
548 * which the radio information isn't provided as a pseudo-header in the
549 * packet data. It is also used by the dissectors for the pseudo-headers
550 * in the packet data to supply radio information, in a form independent
551 * of the file format and pseudo-header format, to the "802.11 radio"
552 * dissector.
553 *
554 * Signal strength, etc. information:
555 *
556 * Raw signal strength can be measured in milliwatts.
557 * It can also be represented as dBm, which is 10 times the log base 10
558 * of the signal strength in mW.
559 *
560 * The Receive Signal Strength Indicator is an integer in the range 0 to 255.
561 * The actual RSSI value for a given signal strength is dependent on the
562 * vendor (and perhaps on the adapter). The maximum possible RSSI value
563 * is also dependent on the vendor and perhaps the adapter.
564 *
565 * The signal strength can be represented as a percentage, which is 100
566 * times the ratio of the RSSI and the maximum RSSI.
567 */
568
569/*
570 * PHY types.
571 */
572#define PHDR_802_11_PHY_UNKNOWN 0 /* PHY not known */
573#define PHDR_802_11_PHY_11_FHSS 1 /* 802.11 FHSS */
574#define PHDR_802_11_PHY_11_IR 2 /* 802.11 IR */
575#define PHDR_802_11_PHY_11_DSSS 3 /* 802.11 DSSS */
576#define PHDR_802_11_PHY_11B 4 /* 802.11b */
577#define PHDR_802_11_PHY_11A 5 /* 802.11a */
578#define PHDR_802_11_PHY_11G 6 /* 802.11g */
579#define PHDR_802_11_PHY_11N 7 /* 802.11n */
580#define PHDR_802_11_PHY_11AC 8 /* 802.11ac */
581#define PHDR_802_11_PHY_11AD 9 /* 802.11ad */
582#define PHDR_802_11_PHY_11AH 10 /* 802.11ah */
583#define PHDR_802_11_PHY_11AX 11 /* 802.11ax */
584#define PHDR_802_11_PHY_11BE 12 /* 802.11be - EHT */
585
586/*
587 * PHY-specific information.
588 */
589
594 unsigned has_hop_set : 1;
595 unsigned has_hop_pattern : 1;
596 unsigned has_hop_index : 1;
597
598 uint8_t hop_set;
599 uint8_t hop_pattern;
600 uint8_t hop_index;
601};
602
603
608 unsigned has_short_preamble : 1;
609
611};
612
613
618 unsigned has_channel_type : 1;
619 unsigned has_turbo_type : 1;
620
621 unsigned channel_type : 2;
622 unsigned turbo_type : 2;
623};
624
625/*
626 * Channel type values.
627 */
628#define PHDR_802_11A_CHANNEL_TYPE_NORMAL 0
629#define PHDR_802_11A_CHANNEL_TYPE_HALF_CLOCKED 1
630#define PHDR_802_11A_CHANNEL_TYPE_QUARTER_CLOCKED 2
631
632/*
633 * "Turbo" is an Atheros proprietary extension with 40 MHz-wide channels.
634 * It can be dynamic or static.
635 *
636 * See
637 *
638 * http://wifi-insider.com/atheros/turbo.htm
639 */
640#define PHDR_802_11A_TURBO_TYPE_NORMAL 0
641#define PHDR_802_11A_TURBO_TYPE_TURBO 1 /* If we don't know whether it's static or dynamic */
642#define PHDR_802_11A_TURBO_TYPE_DYNAMIC_TURBO 2
643#define PHDR_802_11A_TURBO_TYPE_STATIC_TURBO 3
644
653 unsigned has_mode : 1;
654
655 uint32_t mode;
656};
657
658/*
659 * Mode values.
660 */
661#define PHDR_802_11G_MODE_NORMAL 0
662#define PHDR_802_11G_MODE_SUPER_G 1 /* Atheros Super G */
663
668 unsigned has_mcs_index : 1;
669 unsigned has_bandwidth : 1;
670 unsigned has_short_gi : 1;
671 unsigned has_greenfield : 1;
672 unsigned has_fec : 1;
673 unsigned has_stbc_streams : 1;
674 unsigned has_ness : 1;
675
676 uint16_t mcs_index;
677 unsigned bandwidth;
678 unsigned short_gi : 1;
679 unsigned greenfield : 1;
680 unsigned fec : 1;
681 unsigned stbc_streams : 2;
682 unsigned ness;
683};
684
685/*
686 * Bandwidth values; used for both 11n and 11ac.
687 */
688#define PHDR_802_11_BANDWIDTH_20_MHZ 0 /* 20 MHz */
689#define PHDR_802_11_BANDWIDTH_40_MHZ 1 /* 40 MHz */
690#define PHDR_802_11_BANDWIDTH_20_20L 2 /* 20 + 20L, 40 MHz */
691#define PHDR_802_11_BANDWIDTH_20_20U 3 /* 20 + 20U, 40 MHz */
692#define PHDR_802_11_BANDWIDTH_80_MHZ 4 /* 80 MHz */
693#define PHDR_802_11_BANDWIDTH_40_40L 5 /* 40 + 40L MHz, 80 MHz */
694#define PHDR_802_11_BANDWIDTH_40_40U 6 /* 40 + 40U MHz, 80 MHz */
695#define PHDR_802_11_BANDWIDTH_20LL 7 /* ???, 80 MHz */
696#define PHDR_802_11_BANDWIDTH_20LU 8 /* ???, 80 MHz */
697#define PHDR_802_11_BANDWIDTH_20UL 9 /* ???, 80 MHz */
698#define PHDR_802_11_BANDWIDTH_20UU 10 /* ???, 80 MHz */
699#define PHDR_802_11_BANDWIDTH_160_MHZ 11 /* 160 MHz */
700#define PHDR_802_11_BANDWIDTH_80_80L 12 /* 80 + 80L, 160 MHz */
701#define PHDR_802_11_BANDWIDTH_80_80U 13 /* 80 + 80U, 160 MHz */
702#define PHDR_802_11_BANDWIDTH_40LL 14 /* ???, 160 MHz */
703#define PHDR_802_11_BANDWIDTH_40LU 15 /* ???, 160 MHz */
704#define PHDR_802_11_BANDWIDTH_40UL 16 /* ???, 160 MHz */
705#define PHDR_802_11_BANDWIDTH_40UU 17 /* ???, 160 MHz */
706#define PHDR_802_11_BANDWIDTH_20LLL 18 /* ???, 160 MHz */
707#define PHDR_802_11_BANDWIDTH_20LLU 19 /* ???, 160 MHz */
708#define PHDR_802_11_BANDWIDTH_20LUL 20 /* ???, 160 MHz */
709#define PHDR_802_11_BANDWIDTH_20LUU 21 /* ???, 160 MHz */
710#define PHDR_802_11_BANDWIDTH_20ULL 22 /* ???, 160 MHz */
711#define PHDR_802_11_BANDWIDTH_20ULU 23 /* ???, 160 MHz */
712#define PHDR_802_11_BANDWIDTH_20UUL 24 /* ???, 160 MHz */
713#define PHDR_802_11_BANDWIDTH_20UUU 25 /* ???, 160 MHz */
714
719 unsigned has_stbc : 1;
721 unsigned has_short_gi : 1;
724 unsigned has_beamformed : 1;
725 unsigned has_bandwidth : 1;
726 unsigned has_fec : 1;
727 unsigned has_group_id : 1;
728 unsigned has_partial_aid : 1;
729
730 unsigned stbc : 1;
731 unsigned txop_ps_not_allowed : 1;
732 unsigned short_gi : 1;
735 unsigned beamformed : 1;
736 uint8_t bandwidth;
737 uint8_t mcs[4];
738 uint8_t nss[4];
739 uint8_t fec;
740 uint8_t group_id;
741 uint16_t partial_aid;
742};
743
744/*
745 * 802.11ad.
746 */
747
748/*
749 * Min and Max frequencies for 802.11ad and a macro for checking for 802.11ad.
750 */
751
752#define PHDR_802_11AD_MIN_FREQUENCY 57000
753#define PHDR_802_11AD_MAX_FREQUENCY 71000
754
755#define IS_80211AD(frequency) (((frequency) >= PHDR_802_11AD_MIN_FREQUENCY) &&\
756 ((frequency) <= PHDR_802_11AD_MAX_FREQUENCY))
757
762 unsigned has_mcs_index : 1;
763
764 uint8_t mcs;
765};
766
767
772 unsigned has_mcs_index : 1;
773 unsigned has_bwru : 1;
774 unsigned has_gi : 1;
775
776 uint8_t nsts : 4;
777 uint8_t mcs : 4;
778 uint8_t bwru : 4;
779 uint8_t gi : 2;
780};
781
782
787 unsigned sta_id_known : 1;
788 unsigned mcs_known : 1;
789 unsigned coding_known : 1;
790 unsigned rsv_known : 1;
791 unsigned nsts_known : 1;
792 unsigned bf_known : 1;
793 unsigned spatial_config_known : 1;
794 unsigned data_for_this_user : 1;
795 unsigned sta_id : 11;
796 unsigned ldpc_coding : 1;
797 unsigned mcs : 4;
798 unsigned nsts : 4;
799 unsigned rsv : 1;
800 unsigned beamform : 1;
801 unsigned rsv2 : 2;
802};
803
804#define PHDR_802_11BE_MAX_USERS 4
805
810 unsigned has_ru_mru_size : 1;
811 unsigned has_gi : 1;
812 unsigned has_bandwidth : 1;
813
814 uint8_t bandwidth;
815 uint8_t ru_mru_size : 4;
816 uint8_t gi : 2;
817 uint8_t num_users;
819};
820
821
843
849 unsigned decrypted : 1;
850 unsigned datapad : 1;
851 unsigned no_a_msdus : 1;
852 unsigned phy;
854
855 unsigned has_channel : 1;
856 unsigned has_frequency : 1;
857 unsigned has_data_rate : 1;
858 unsigned has_signal_percent : 1;
859 unsigned has_noise_percent : 1;
860 unsigned has_signal_dbm : 1;
861 unsigned has_noise_dbm : 1;
862 unsigned has_signal_db : 1;
863 unsigned has_noise_db : 1;
864 unsigned has_tsf_timestamp : 1;
865 unsigned has_aggregate_info : 1;
867
868 uint16_t channel;
869 uint32_t frequency;
870 uint16_t data_rate;
873 int8_t signal_dbm;
874 int8_t noise_dbm;
875 uint8_t signal_db;
876 uint8_t noise_db;
877 uint64_t tsf_timestamp;
879 uint32_t aggregate_id;
881};
882
883/*
884 * A-MPDU flags.
885 */
886#define PHDR_802_11_LAST_PART_OF_A_MPDU 0x00000001 /* this is the last part of an A-MPDU */
887#define PHDR_802_11_A_MPDU_DELIM_CRC_ERROR 0x00000002 /* delimiter CRC error after this part */
888
889/*
890 * Zero-length PSDU types.
891 */
892#define PHDR_802_11_SOUNDING_PSDU 0 /* sounding PPDU */
893#define PHDR_802_11_DATA_NOT_CAPTURED 1 /* data not captured, (e.g. multi-user PPDU) */
894#define PHDR_802_11_0_LENGTH_PSDU_VENDOR_SPECIFIC 0xff
895
896/* Packet "pseudo-header" for the output from CoSine L2 debug output. */
897
898#define COSINE_MAX_IF_NAME_LEN 128
899
900#define COSINE_ENCAP_TEST 1
901#define COSINE_ENCAP_PPoATM 2
902#define COSINE_ENCAP_PPoFR 3
903#define COSINE_ENCAP_ATM 4
904#define COSINE_ENCAP_FR 5
905#define COSINE_ENCAP_HDLC 6
906#define COSINE_ENCAP_PPP 7
907#define COSINE_ENCAP_ETH 8
908#define COSINE_ENCAP_UNKNOWN 99
909
910#define COSINE_DIR_TX 1
911#define COSINE_DIR_RX 2
912
917 uint8_t encap;
918 uint8_t direction;
919 char if_name[COSINE_MAX_IF_NAME_LEN];
920 uint16_t pro;
921 uint16_t off;
922 uint16_t pri;
923 uint16_t rm;
924 uint16_t err;
925};
926
927/* Packet "pseudo-header" for IrDA capture files. */
928
929/*
930 * Direction of the packet
931 */
932#define IRDA_INCOMING 0x0000
933#define IRDA_OUTGOING 0x0004
934
935/*
936 * "Inline" log messages produced by IrCOMM2k on Windows
937 */
938#define IRDA_LOG_MESSAGE 0x0100 /* log message */
939#define IRDA_MISSED_MSG 0x0101 /* missed log entry or frame */
940
941/*
942 * Differentiate between frames and log messages
943 */
944#define IRDA_CLASS_FRAME 0x0000
945#define IRDA_CLASS_LOG 0x0100
946#define IRDA_CLASS_MASK 0xFF00
947
951struct irda_phdr {
952 uint16_t pkttype;
953};
954
959 uint16_t subsys;
960 uint32_t devid;
961 uint32_t kind;
962 int32_t pid;
963 uint32_t uid;
964};
965
966/* Packet "pseudo-header" for MTP2 files. */
967
968#define MTP2_ANNEX_A_NOT_USED 0
969#define MTP2_ANNEX_A_USED 1
970#define MTP2_ANNEX_A_USED_UNKNOWN 2
971
975struct mtp2_phdr {
976 uint8_t sent;
977 uint8_t annex_a_used;
978 uint16_t link_number;
979};
980
988typedef union {
994 struct {
995 uint16_t vp;
996 uint16_t vc;
997 uint16_t cid;
998 } atm;
999
1006 uint32_t ds0mask;
1008
1012struct k12_phdr {
1013 uint32_t input;
1014 const char *input_name;
1015 const char *stack_file;
1016 uint32_t input_type;
1018 uint8_t *extra_info;
1019 uint32_t extra_length;
1020 void *stuff;
1021};
1022
1023#define K12_PORT_DS0S 0x00010008
1024#define K12_PORT_DS1 0x00100008
1025#define K12_PORT_ATMPVC 0x01020000
1026
1035 uint16_t pkttype;
1036 uint8_t we_network;
1037};
1038
1047 union {
1049 struct atm_phdr atm;
1050 struct p2p_phdr p2p;
1051 } inner_pseudo_header;
1052
1053 int64_t seek_off;
1054 struct wtap *wth;
1055};
1056
1060struct erf_phdr {
1061 uint64_t ts;
1062 uint8_t type;
1063 uint8_t flags;
1064 uint16_t rlen;
1065 uint16_t lctr;
1066 uint16_t wlen;
1067};
1068
1072struct erf_ehdr {
1073 uint64_t ehdr;
1074};
1075
1076#define MAX_ERF_EHDR 16
1077
1082 uint8_t offset;
1083 uint8_t pad;
1084};
1085
1096
1098
1104 union {
1106 uint32_t mc_hdr;
1107 uint32_t aal2_hdr;
1109};
1110
1111#define SITA_FRAME_DIR_TXED (0x00) /* values of sita_phdr.flags */
1112#define SITA_FRAME_DIR_RXED (0x01)
1113#define SITA_FRAME_DIR (0x01) /* mask */
1114#define SITA_ERROR_NO_BUFFER (0x80)
1115
1116#define SITA_SIG_DSR (0x01) /* values of sita_phdr.signals */
1117#define SITA_SIG_DTR (0x02)
1118#define SITA_SIG_CTS (0x04)
1119#define SITA_SIG_RTS (0x08)
1120#define SITA_SIG_DCD (0x10)
1121#define SITA_SIG_UNDEF1 (0x20)
1122#define SITA_SIG_UNDEF2 (0x40)
1123#define SITA_SIG_UNDEF3 (0x80)
1124
1125#define SITA_ERROR_TX_UNDERRUN (0x01) /* values of sita_phdr.errors2 (if SITA_FRAME_DIR_TXED) */
1126#define SITA_ERROR_TX_CTS_LOST (0x02)
1127#define SITA_ERROR_TX_UART_ERROR (0x04)
1128#define SITA_ERROR_TX_RETX_LIMIT (0x08)
1129#define SITA_ERROR_TX_UNDEF1 (0x10)
1130#define SITA_ERROR_TX_UNDEF2 (0x20)
1131#define SITA_ERROR_TX_UNDEF3 (0x40)
1132#define SITA_ERROR_TX_UNDEF4 (0x80)
1133
1134#define SITA_ERROR_RX_FRAMING (0x01) /* values of sita_phdr.errors1 (if SITA_FRAME_DIR_RXED) */
1135#define SITA_ERROR_RX_PARITY (0x02)
1136#define SITA_ERROR_RX_COLLISION (0x04)
1137#define SITA_ERROR_RX_FRAME_LONG (0x08)
1138#define SITA_ERROR_RX_FRAME_SHORT (0x10)
1139#define SITA_ERROR_RX_UNDEF1 (0x20)
1140#define SITA_ERROR_RX_UNDEF2 (0x40)
1141#define SITA_ERROR_RX_UNDEF3 (0x80)
1142
1143#define SITA_ERROR_RX_NONOCTET_ALIGNED (0x01) /* values of sita_phdr.errors2 (if SITA_FRAME_DIR_RXED) */
1144#define SITA_ERROR_RX_ABORT (0x02)
1145#define SITA_ERROR_RX_CD_LOST (0x04)
1146#define SITA_ERROR_RX_DPLL (0x08)
1147#define SITA_ERROR_RX_OVERRUN (0x10)
1148#define SITA_ERROR_RX_FRAME_LEN_VIOL (0x20)
1149#define SITA_ERROR_RX_CRC (0x40)
1150#define SITA_ERROR_RX_BREAK (0x80)
1151
1152#define SITA_PROTO_UNUSED (0x00) /* values of sita_phdr.proto */
1153#define SITA_PROTO_BOP_LAPB (0x01)
1154#define SITA_PROTO_ETHERNET (0x02)
1155#define SITA_PROTO_ASYNC_INTIO (0x03)
1156#define SITA_PROTO_ASYNC_BLKIO (0x04)
1157#define SITA_PROTO_ALC (0x05)
1158#define SITA_PROTO_UTS (0x06)
1159#define SITA_PROTO_PPP_HDLC (0x07)
1160#define SITA_PROTO_SDLC (0x08)
1161#define SITA_PROTO_TOKENRING (0x09)
1162#define SITA_PROTO_I2C (0x10)
1163#define SITA_PROTO_DPM_LINK (0x11)
1164#define SITA_PROTO_BOP_FRL (0x12)
1165
1170 uint8_t sita_flags;
1174 uint8_t sita_proto;
1175};
1176
1181 bool sent;
1182 uint32_t channel;
1183};
1184
1185#define BTHCI_CHANNEL_COMMAND 1
1186#define BTHCI_CHANNEL_ACL 2
1187#define BTHCI_CHANNEL_SCO 3
1188#define BTHCI_CHANNEL_EVENT 4
1189#define BTHCI_CHANNEL_ISO 5
1190
1195 uint16_t adapter_id;
1196 uint16_t opcode;
1197};
1198
1203 bool uton;
1204};
1205
1209struct i2c_phdr {
1210 uint8_t is_event;
1211 uint8_t bus;
1212 uint32_t flags;
1213};
1214
1219 bool uplink;
1220 uint8_t channel;
1221 /* The following are only populated for downlink */
1222 uint8_t bsic;
1223 uint16_t arfcn;
1224 uint32_t tdma_frame;
1225 uint8_t error;
1226 uint16_t timeshift;
1227};
1228
1229#define GSM_UM_CHANNEL_UNKNOWN 0
1230#define GSM_UM_CHANNEL_BCCH 1
1231#define GSM_UM_CHANNEL_SDCCH 2
1232#define GSM_UM_CHANNEL_SACCH 3
1233#define GSM_UM_CHANNEL_FACCH 4
1234#define GSM_UM_CHANNEL_CCCH 5
1235#define GSM_UM_CHANNEL_RACH 6
1236#define GSM_UM_CHANNEL_AGCH 7
1237#define GSM_UM_CHANNEL_PCH 8
1238
1263
1268 struct eth_phdr eth;
1269 uint8_t stuff[4];
1270};
1271
1272#define LLCP_PHDR_FLAG_SENT 0
1273
1278 uint8_t adapter;
1279 uint8_t flags;
1280};
1281
1287};
1288
1297 uint8_t* title;
1298 uint32_t descLength;
1299 uint8_t* description;
1300
1301 unsigned sub_encap;
1302
1313};
1314
1315/* Record "pseudo-header" information for header data from MS ProcMon files. */
1316
1317struct procmon_process_t;
1318
1329
1330
1334struct ber_phdr {
1335 const char *pathname;
1336};
1337
1338
1343 uint8_t chunktype;
1344};
1345
1383
1384/*
1385 * Record type values.
1386 *
1387 * This list will expand over time, so don't assume everything will
1388 * forever be one of the types listed below.
1389 *
1390 * For file-type-specific records, the "ftsrec" field of the pseudo-header
1391 * contains a file-type-specific subtype value, such as a block type for
1392 * a pcapng file.
1393 *
1394 * An "event" is an indication that something happened during the capture
1395 * process, such as a status transition of some sort on the network.
1396 * These should, ideally, have a time stamp and, if they're relevant to
1397 * a particular interface on a multi-interface capture, should also have
1398 * an interface ID. The data for the event is file-type-specific and
1399 * subtype-specific. These should be dissected and displayed just as
1400 * packets are.
1401 *
1402 * A "report" supplies information not corresponding to an event;
1403 * for example, a pcapng Interface Statistics Block would be a report,
1404 * as it doesn't correspond to something happening on the network.
1405 * They may have a time stamp, and should be dissected and displayed
1406 * just as packets are.
1407 *
1408 * We distinguish between "events" and "reports" so that, for example,
1409 * the packet display can show the delta between a packet and an event
1410 * but not show the delta between a packet and a report, as the time
1411 * stamp of a report may not correspond to anything interesting on
1412 * the network but the time stamp of an event would.
1413 *
1414 * XXX - are there any file-type-specific records that *shouldn't* be
1415 * dissected and displayed? If so, they should be parsed and the
1416 * information in them stored somewhere, and used somewhere, whether
1417 * it's just used when saving the file in its native format or also
1418 * used to parse *other* file-type-specific records.
1419 *
1420 * These would be similar to, for example, pcapng Interface Description
1421 * Blocks, for which the position within the file is significant only
1422 * in that an IDB for an interface must appear before any packets from
1423 * the interface; the fact that an IDB appears at some point doesn't
1424 * necessarily mean something happened in the capture at that point.
1425 * Name Resolution Blocks are another example of such a record.
1426 *
1427 * (XXX - if you want to have a record that says "this interface first
1428 * showed up at this time", that needs to be a separate record type
1429 * from the IDB. We *could* add a "New Interface Description Block",
1430 * with a time stamp, for that purpose, but we'd *still* have to
1431 * provide IDBs for those interfaces, for compatibility with programs
1432 * that don't know about the NIDB. An ISB with only an isb_starttime
1433 * option would suffice for this purpose, so nothing needs to be
1434 * added to pcapng for this.)
1435 */
1436#define REC_TYPE_PACKET 0
1437#define REC_TYPE_FT_SPECIFIC_EVENT 1
1438#define REC_TYPE_FT_SPECIFIC_REPORT 2
1439#define REC_TYPE_SYSCALL 3
1440#define REC_TYPE_SYSTEMD_JOURNAL_EXPORT 4
1441#define REC_TYPE_CUSTOM_BLOCK 5
1442
1446typedef struct {
1447 uint32_t caplen;
1448 uint32_t len;
1450 uint32_t interface_id;
1451
1454
1455/*
1456 * The pcapng specification says "The word is encoded as an unsigned
1457 * 32-bit integer, using the endianness of the Section Header Block
1458 * scope it is in. In the following table, the bits are numbered with
1459 * 0 being the most-significant bit and 31 being the least-significant
1460 * bit of the 32-bit unsigned integer."
1461 *
1462 * From that, the direction, in bits 0 and 1, is at the *top* of the word.
1463 *
1464 * However, several implementations, such as:
1465 *
1466 * the Wireshark pcapng file reading code;
1467 *
1468 * macOS libpcap and tcpdump;
1469 *
1470 * text2pcap;
1471 *
1472 * and probably the software that generated the capture in bug 11665;
1473 *
1474 * treat 0 as the *least*-significant bit and bit 31 being the *most*-
1475 * significant bit of the flags word, and put the direction at the
1476 * *bottom* of the word.
1477 *
1478 * For now, we go with the known implementations.
1479 */
1480
1481/* Direction field of the packet flags */
1482#define PACK_FLAGS_DIRECTION_MASK 0x00000003 /* unshifted */
1483#define PACK_FLAGS_DIRECTION_SHIFT 0
1484#define PACK_FLAGS_DIRECTION(pack_flags) (((pack_flags) & PACK_FLAGS_DIRECTION_MASK) >> PACK_FLAGS_DIRECTION_SHIFT)
1485#define PACK_FLAGS_DIRECTION_UNKNOWN 0
1486#define PACK_FLAGS_DIRECTION_INBOUND 1
1487#define PACK_FLAGS_DIRECTION_OUTBOUND 2
1488
1489/* Reception type field of the packet flags */
1490#define PACK_FLAGS_RECEPTION_TYPE_MASK 0x0000001C /* unshifted */
1491#define PACK_FLAGS_RECEPTION_TYPE_SHIFT 2
1492#define PACK_FLAGS_RECEPTION_TYPE(pack_flags) (((pack_flags) & PACK_FLAGS_RECEPTION_TYPE_MASK) >> PACK_FLAGS_RECEPTION_TYPE_SHIFT)
1493#define PACK_FLAGS_RECEPTION_TYPE_UNSPECIFIED 0
1494#define PACK_FLAGS_RECEPTION_TYPE_UNICAST 1
1495#define PACK_FLAGS_RECEPTION_TYPE_MULTICAST 2
1496#define PACK_FLAGS_RECEPTION_TYPE_BROADCAST 3
1497#define PACK_FLAGS_RECEPTION_TYPE_PROMISCUOUS 4
1498
1499/* FCS length field of the packet flags */
1500#define PACK_FLAGS_FCS_LENGTH_MASK 0x000001E0 /* unshifted */
1501#define PACK_FLAGS_FCS_LENGTH_SHIFT 5
1502#define PACK_FLAGS_FCS_LENGTH(pack_flags) (((pack_flags) & PACK_FLAGS_FCS_LENGTH_MASK) >> PACK_FLAGS_FCS_LENGTH_SHIFT)
1503
1504/* Reserved bits of the packet flags */
1505#define PACK_FLAGS_RESERVED_MASK 0x0000FE00
1506
1507/* Link-layer-dependent errors of the packet flags */
1508
1509/* For Ethernet and possibly some other network types */
1510#define PACK_FLAGS_CRC_ERROR 0x01000000
1511#define PACK_FLAGS_PACKET_TOO_LONG 0x02000000
1512#define PACK_FLAGS_PACKET_TOO_SHORT 0x04000000
1513#define PACK_FLAGS_WRONG_INTER_FRAME_GAP 0x08000000
1514#define PACK_FLAGS_UNALIGNED_FRAME 0x10000000
1515#define PACK_FLAGS_START_FRAME_DELIMITER_ERROR 0x20000000
1516#define PACK_FLAGS_PREAMBLE_ERROR 0x40000000
1517#define PACK_FLAGS_SYMBOL_ERROR 0x80000000
1518
1519/* Construct a pack_flags value from its subfield values */
1520#define PACK_FLAGS_VALUE(direction, reception_type, fcs_length, ll_dependent_errors) \
1521 (((direction) << 30) | \
1522 ((reception_type) << 27) | \
1523 ((fcs_length) << 23) | \
1524 (ll_dependent_errors))
1525
1536
1540typedef struct {
1541 const char *pathname;
1542 unsigned record_type;
1544 uint64_t timestamp;
1545 uint64_t thread_id;
1546 uint32_t event_len;
1548 uint32_t nparams;
1549 uint32_t flags;
1550 uint16_t event_type;
1551 uint16_t cpu_id;
1553
1557typedef struct {
1558 uint32_t record_len;
1560
1564typedef struct {
1565 uint32_t pen;
1566 uint32_t length;
1569
1570/*
1571 * The largest nstime.secs value that can be put into an unsigned
1572 * 32-bit quantity.
1573 *
1574 * We assume that time_t is signed; it is signed on Windows/MSVC and
1575 * on many UN*Xes.
1576 *
1577 * So, if time_t is 32-bit, we define this as INT32_MAX, as that's
1578 * the largest value a time_t can have, and it fits in an unsigned
1579 * 32-bit quantity. If it's 64-bit or larger, we define this as
1580 * UINT32_MAX, as, even if it's signed, it can be as large as
1581 * UINT32_MAX, and that's the largest value that can fit in
1582 * a 32-bit unsigned quantity.
1583 *
1584 * Comparing against this, rather than against G_MAXINT2, when checking
1585 * whether a time stamp will fit in a 32-bit unsigned integer seconds
1586 * field in a capture file being written avoids signed vs. unsigned
1587 * warnings if time_t is a signed 32-bit type.
1588 *
1589 * XXX - what if time_t is unsigned? Are there any platforms where
1590 * it is?
1591 */
1592#define WTAP_NSTIME_32BIT_SECS_MAX ((time_t)(sizeof(time_t) > sizeof(int32_t) ? UINT32_MAX : INT32_MAX))
1593
1636
1637/*
1638 * Bits in presence_flags, indicating which of the fields we have.
1639 *
1640 * For the time stamp, we may need some more flags to indicate
1641 * whether the time stamp is an absolute date-and-time stamp, an
1642 * absolute time-only stamp (which can make relative time
1643 * calculations tricky, as you could in theory have two time
1644 * stamps separated by an unknown number of days), or a time stamp
1645 * relative to some unspecified time in the past (see mpeg.c).
1646 *
1647 * There is no presence flag for len - there has to be *some* length
1648 * value for the packet. (The "captured length" can be missing if
1649 * the file format doesn't report a captured length distinct from
1650 * the on-the-network length because the application(s) producing those
1651 * files don't support slicing packets.)
1652 *
1653 * There could be a presence flag for the packet encapsulation - if it's
1654 * absent, use the file encapsulation - but it's not clear that's useful;
1655 * we currently do that in the module for the file format.
1656 *
1657 * Only WTAP_HAS_TS and WTAP_HAS_SECTION_NUMBER apply to all record types.
1658 */
1659#define WTAP_HAS_TS 0x00000001
1660#define WTAP_HAS_CAP_LEN 0x00000002
1661#define WTAP_HAS_INTERFACE_ID 0x00000004
1662#define WTAP_HAS_SECTION_NUMBER 0x00000008
1663
1664/*
1665 * The old max name length define, both for backwards compatibility and because
1666 * other name types (in epan) use it. While Name Resolution Blocks (NRBs) only
1667 * support IPv4 and IPv6 currently, they could later support other name types.
1668 */
1669#ifndef MAXNAMELEN
1670#define MAXNAMELEN 64 /* max name length (most names: DNS labels, services, eth) */
1671#endif
1672
1673#ifndef MAXDNSNAMELEN
1674#define MAXDNSNAMELEN 256 /* max total length of a domain name in DNS */
1675#endif
1676
1680typedef struct hashipv4 {
1681 unsigned addr;
1682 uint8_t flags;
1683 char ip[WS_INET_ADDRSTRLEN];
1684 char name[MAXDNSNAMELEN];
1687
1688
1692typedef struct hashipv6 {
1693 uint8_t addr[16];
1694 uint8_t flags;
1695 char ip6[WS_INET6_ADDRSTRLEN];
1696 char name[MAXDNSNAMELEN];
1697 char cidr_addr[WS_INET6_CIDRADDRSTRLEN];
1699
1700
1708
1749
1750/* Zero-initializer for wtap_dump_params. */
1751#define WTAP_DUMP_PARAMS_INIT {.snaplen=0}
1752
1753struct wtap_dumper;
1754
1755typedef struct wtap wtap;
1756typedef struct wtap_dumper wtap_dumper;
1757
1758typedef struct wtap_reader *FILE_T;
1759
1778
1818 const char *name;
1820 const char *extensions;
1821};
1822
1854
1855typedef wtap_open_return_val (*wtap_open_routine_t)(struct wtap*, int *,
1856 char **);
1857
1882
1889WS_DLL_PUBLIC void init_open_routines(void);
1890
1897void cleanup_open_routines(void);
1898
1926 const char *name;
1928 wtap_open_routine_t open_routine;
1929 const char *extensions;
1932};
1933
1940WS_DLL_PUBLIC struct open_info *open_routines;
1941
1942/*
1943 * Types of comments.
1944 */
1950#define WTAP_COMMENT_PER_SECTION 0x00000001 /* per-file/per-file-section */
1951
1957#define WTAP_COMMENT_PER_INTERFACE 0x00000002 /* per-interface */
1958
1964#define WTAP_COMMENT_PER_PACKET 0x00000004 /* per-packet */
1965
1981
1992
1998#define OPTION_TYPES_SUPPORTED(option_type_array) \
1999 array_length(option_type_array), option_type_array
2000
2006#define NO_OPTIONS_SUPPORTED \
2007 0, NULL
2008
2017
2027
2028#define BLOCKS_SUPPORTED(block_type_array) \
2029 array_length(block_type_array), block_type_array
2030
2038 const char *description;
2039
2044 const char *name;
2045
2051
2059
2064
2069
2074
2083 int (*can_write_encap)(int);
2084
2089 bool (*dump_open)(wtap_dumper *, int *, char **);
2090
2096};
2097
2098#define WTAP_TYPE_AUTO 0
2099
2108WS_DLL_PUBLIC
2109void wtap_init(bool load_wiretap_plugins, const char* app_env_var_prefix, const struct file_extension_info* file_extensions, unsigned num_extensions);
2110
2128WS_DLL_PUBLIC
2129struct wtap* wtap_open_offline(const char *filename, unsigned int type, int *err,
2130 char **err_info, bool do_random, const char* app_env_var_prefix);
2131
2140WS_DLL_PUBLIC
2141void wtap_cleareof(wtap *wth);
2142
2153typedef void (*wtap_new_ipv4_callback_t) (const unsigned addr, const char *name, const bool static_entry);
2154
2164WS_DLL_PUBLIC
2166
2177typedef void (*wtap_new_ipv6_callback_t) (const ws_in6_addr *addrp, const char *name, const bool static_entry);
2178
2188WS_DLL_PUBLIC
2190
2201typedef void (*wtap_new_secrets_callback_t)(uint32_t secrets_type, const void *secrets, unsigned size);
2202
2212WS_DLL_PUBLIC
2214
2230WS_DLL_PUBLIC
2231bool wtap_read(wtap *wth, wtap_rec *rec, int *err, char **err_info,
2232 int64_t *offset);
2233
2250WS_DLL_PUBLIC
2251bool wtap_seek_read(wtap *wth, int64_t seek_off, wtap_rec *rec,
2252 int *err, char **err_info);
2253
2262WS_DLL_PUBLIC
2263void wtap_rec_init(wtap_rec *rec, size_t space);
2264
2273WS_DLL_PUBLIC
2274void wtap_rec_apply_snapshot(wtap_rec *rec, uint32_t snaplen);
2275
2283WS_DLL_PUBLIC
2284void wtap_rec_reset(wtap_rec *rec);
2285
2293WS_DLL_PUBLIC
2294void wtap_rec_cleanup(wtap_rec *rec);
2295
2305WS_DLL_PUBLIC
2307
2316WS_DLL_PUBLIC
2317void wtap_setup_packet_rec(wtap_rec *rec, int encap);
2318
2328WS_DLL_PUBLIC
2330 unsigned record_type);
2331
2341WS_DLL_PUBLIC
2343 unsigned record_type);
2344
2352WS_DLL_PUBLIC
2354
2362WS_DLL_PUBLIC
2364
2376WS_DLL_PUBLIC
2377void wtap_setup_custom_block_rec(wtap_rec *rec, uint32_t pen,
2378 uint32_t payload_length, bool copy_allowed);
2379
2388WS_DLL_PUBLIC
2389ws_compression_type wtap_get_compression_type(wtap *wth);
2390
2391/*** get various information snippets about the current file ***/
2392
2402WS_DLL_PUBLIC
2403int64_t wtap_read_so_far(wtap *wth);
2404
2414WS_DLL_PUBLIC
2415int64_t wtap_file_size(wtap *wth, int *err);
2416
2425WS_DLL_PUBLIC
2426unsigned wtap_snapshot_length(wtap *wth);
2427
2436WS_DLL_PUBLIC
2438
2447WS_DLL_PUBLIC
2448int wtap_file_encap(wtap *wth);
2449
2458WS_DLL_PUBLIC
2459int wtap_file_tsprec(wtap *wth);
2460
2469WS_DLL_PUBLIC
2470const nstime_t* wtap_file_start_ts(wtap *wth);
2471
2480WS_DLL_PUBLIC
2481const nstime_t* wtap_file_end_ts(wtap *wth);
2482
2490WS_DLL_PUBLIC
2491unsigned wtap_file_get_num_shbs(wtap *wth);
2492
2505WS_DLL_PUBLIC
2506wtap_block_t wtap_file_get_shb(wtap *wth, unsigned shb_num);
2507
2518WS_DLL_PUBLIC
2519void wtap_write_shb_comment(wtap *wth, char *comment);
2520
2532WS_DLL_PUBLIC
2533unsigned wtap_file_get_shb_global_interface_id(wtap *wth, unsigned shb_num, uint32_t interface_id);
2534
2545WS_DLL_PUBLIC
2547
2548
2555WS_DLL_PUBLIC
2557
2567WS_DLL_PUBLIC
2568wtap_block_t wtap_get_next_interface_description(wtap *wth);
2569
2582WS_DLL_PUBLIC
2584
2596WS_DLL_PUBLIC
2597char *wtap_get_debug_if_descr(const wtap_block_t if_descr,
2598 const int indent,
2599 const char* line_end);
2600
2613WS_DLL_PUBLIC
2614wtap_block_t wtap_file_get_nrb(wtap *wth);
2615
2623WS_DLL_PUBLIC
2624unsigned wtap_file_get_num_dsbs(wtap *wth);
2625
2636WS_DLL_PUBLIC
2637wtap_block_t wtap_file_get_dsb(wtap *wth, unsigned dsb_num);
2638
2647WS_DLL_PUBLIC
2648void wtap_file_add_decryption_secrets(wtap *wth, const wtap_block_t dsb);
2649
2658WS_DLL_PUBLIC
2660
2668WS_DLL_PUBLIC
2669void wtap_fdclose(wtap *wth);
2670
2681WS_DLL_PUBLIC
2682bool wtap_fdreopen(wtap *wth, const char *filename, int *err);
2683
2691WS_DLL_PUBLIC
2692void wtap_sequential_close(wtap *wth);
2693
2701WS_DLL_PUBLIC
2702void wtap_close(wtap *wth);
2703
2712WS_DLL_PUBLIC
2713bool wtap_dump_can_open(int filetype);
2714
2725WS_DLL_PUBLIC
2726int wtap_dump_required_file_encap_type(const GArray *file_encaps);
2727
2738WS_DLL_PUBLIC
2739bool wtap_dump_can_write_encap(int file_type_subtype, int encap);
2740
2749WS_DLL_PUBLIC
2751
2762WS_DLL_PUBLIC
2763void wtap_dump_params_init(wtap_dump_params *params, wtap *wth);
2764
2781WS_DLL_PUBLIC
2783
2791WS_DLL_PUBLIC
2793
2801WS_DLL_PUBLIC
2803
2810WS_DLL_PUBLIC
2812
2825WS_DLL_PUBLIC
2826wtap_dumper* wtap_dump_open(const char *filename, int file_type_subtype,
2827 ws_compression_type compression_type, const wtap_dump_params *params,
2828 int *err, char **err_info);
2829
2845WS_DLL_PUBLIC
2846wtap_dumper* wtap_dump_open_tempfile(const char *tmpdir, char **filenamep,
2847 const char *pfx,
2848 int file_type_subtype, ws_compression_type compression_type,
2849 const wtap_dump_params *params, int *err, char **err_info);
2850
2863WS_DLL_PUBLIC
2865 ws_compression_type compression_type, const wtap_dump_params *params,
2866 int *err, char **err_info);
2867
2879WS_DLL_PUBLIC
2881 ws_compression_type compression_type, const wtap_dump_params *params,
2882 int *err, char **err_info);
2883
2895WS_DLL_PUBLIC
2896bool wtap_dump_add_idb(wtap_dumper *wdh, wtap_block_t idb, int *err,
2897 char **err_info);
2898
2909WS_DLL_PUBLIC
2910bool wtap_dump(wtap_dumper *wdh, const wtap_rec *rec, int *err, char **err_info);
2911
2919WS_DLL_PUBLIC
2920bool wtap_dump_flush(wtap_dumper *wdh, int *err);
2921
2928WS_DLL_PUBLIC
2930
2937WS_DLL_PUBLIC
2938int64_t wtap_get_bytes_dumped(const wtap_dumper *wdh);
2939
2946WS_DLL_PUBLIC
2947void wtap_set_bytes_dumped(wtap_dumper *wdh, int64_t bytes_dumped);
2948
2949struct addrinfo;
2950
2957WS_DLL_PUBLIC
2959
2967WS_DLL_PUBLIC
2969
2975WS_DLL_PUBLIC
2977
2983WS_DLL_PUBLIC
2985
3002WS_DLL_PUBLIC
3003bool wtap_dump_close(wtap_dumper *wdh, bool *needs_reload,
3004 int *err, char **err_info);
3005
3022WS_DLL_PUBLIC
3023bool wtap_dump_can_write(const GArray *file_encaps, uint32_t required_comment_types);
3024
3038WS_DLL_PUBLIC
3039void wtap_buffer_append_epdu_tag(Buffer *buf, uint16_t epdu_tag, const uint8_t *data, uint16_t data_len);
3040
3049WS_DLL_PUBLIC
3050void wtap_buffer_append_epdu_uint(Buffer *buf, uint16_t epdu_tag, uint32_t val);
3051
3060WS_DLL_PUBLIC
3061void wtap_buffer_append_epdu_string(Buffer *buf, uint16_t epdu_tag, const char *val);
3062
3071WS_DLL_PUBLIC
3073
3081
3098WS_DLL_PUBLIC
3099GArray *wtap_get_savable_file_types_subtypes_for_file(int file_type_subtype,
3100 const GArray *file_encaps, uint32_t required_comment_types,
3101 ft_sort_order sort_order);
3102
3114WS_DLL_PUBLIC
3116
3117/*** various file type/subtype functions ***/
3127WS_DLL_PUBLIC
3128const char *wtap_file_type_subtype_description(int file_type_subtype);
3129
3138WS_DLL_PUBLIC
3139const char *wtap_file_type_subtype_name(int file_type_subtype);
3140
3150WS_DLL_PUBLIC
3151int wtap_name_to_file_type_subtype(const char *name);
3152
3158WS_DLL_PUBLIC
3160
3166WS_DLL_PUBLIC
3168
3174WS_DLL_PUBLIC
3176
3187WS_DLL_PUBLIC
3189 wtap_block_type_t type);
3190
3205WS_DLL_PUBLIC
3207 wtap_block_type_t type, unsigned opttype);
3208
3232WS_DLL_PUBLIC
3234
3250WS_DLL_PUBLIC
3252
3267WS_DLL_PUBLIC
3268void wtap_free_extensions_list(GSList *extensions);
3269
3281WS_DLL_PUBLIC
3282const char *wtap_default_file_extension(int file_type_subtype);
3283
3299WS_DLL_PUBLIC
3300GSList *wtap_get_file_extensions_list(int file_type_subtype, bool include_compressed);
3301
3310WS_DLL_PUBLIC
3311const char *wtap_encap_name(int encap);
3312
3321WS_DLL_PUBLIC
3322const char *wtap_encap_description(int encap);
3323
3333WS_DLL_PUBLIC
3334int wtap_name_to_encap(const char *short_name);
3335
3344WS_DLL_PUBLIC
3345const char* wtap_tsprec_string(int tsprec);
3346
3355WS_DLL_PUBLIC
3356const char *wtap_strerror(int err);
3357
3358
3359/*** get available number of file types and encapsulations ***/
3368WS_DLL_PUBLIC
3370
3378WS_DLL_PUBLIC
3379int wtap_get_num_encap_types(void);
3380
3381/*** get information for file type extension ***/
3382
3394WS_DLL_PUBLIC
3395const char *wtap_get_file_extension_type_name(int extension_type);
3396
3408WS_DLL_PUBLIC
3409GSList *wtap_get_file_extension_type_extensions(unsigned extension_type);
3410
3411/*** dynamically register new file types and encapsulations ***/
3412
3424WS_DLL_PUBLIC
3426
3437typedef struct {
3438 void (*register_wtap_module)(void);
3439} wtap_plugin;
3440
3452WS_DLL_PUBLIC
3454
3455
3469WS_DLL_PUBLIC
3470int wtap_plugins_supported(void);
3471
3472/* Registration and open-info */
3473
3479WS_DLL_PUBLIC
3480void wtap_register_open_info(struct open_info *oi, const bool first_routine);
3481
3487WS_DLL_PUBLIC
3488bool wtap_has_open_info(const char *name);
3489
3495WS_DLL_PUBLIC
3496bool wtap_uses_lua_filehandler(const wtap* wth);
3497
3502WS_DLL_PUBLIC
3503void wtap_deregister_open_info(const char *name);
3504
3505/* Type mapping and registration */
3506
3512WS_DLL_PUBLIC
3513unsigned int open_info_name_to_type(const char *name);
3514
3520WS_DLL_PUBLIC
3522
3527WS_DLL_PUBLIC
3528void wtap_deregister_file_type_subtype(const int file_type_subtype);
3529
3530/* Encapsulation and cleanup */
3537WS_DLL_PUBLIC
3538int wtap_register_encap_type(const char *description, const char *name);
3539
3543WS_DLL_PUBLIC
3544void wtap_cleanup(void);
3545
3549#define WTAP_ERR_NOT_REGULAR_FILE -1
3551
3552#define WTAP_ERR_RANDOM_OPEN_PIPE -2
3554
3555#define WTAP_ERR_FILE_UNKNOWN_FORMAT -3
3557
3558#define WTAP_ERR_UNSUPPORTED -4
3561
3562#define WTAP_ERR_CANT_WRITE_TO_PIPE -5
3564
3565#define WTAP_ERR_CANT_OPEN -6
3567
3568#define WTAP_ERR_UNWRITABLE_FILE_TYPE -7
3570
3571#define WTAP_ERR_UNWRITABLE_ENCAP -8
3574
3575#define WTAP_ERR_ENCAP_PER_PACKET_UNSUPPORTED -9
3577
3578#define WTAP_ERR_CANT_WRITE -10
3580
3581#define WTAP_ERR_CANT_CLOSE -11
3583
3584#define WTAP_ERR_SHORT_READ -12
3586
3587#define WTAP_ERR_BAD_FILE -13
3589
3590#define WTAP_ERR_SHORT_WRITE -14
3592
3593#define WTAP_ERR_UNC_OVERFLOW -15
3595
3596#define WTAP_ERR_RANDOM_OPEN_STDIN -16
3598
3599#define WTAP_ERR_COMPRESSION_NOT_SUPPORTED -17
3601
3602#define WTAP_ERR_CANT_SEEK -18
3604
3605#define WTAP_ERR_CANT_SEEK_COMPRESSED -19
3607
3608#define WTAP_ERR_DECOMPRESS -20
3610
3611#define WTAP_ERR_INTERNAL -21
3613
3614#define WTAP_ERR_PACKET_TOO_LARGE -22
3617
3618#define WTAP_ERR_CHECK_WSLUA -23
3621
3622#define WTAP_ERR_UNWRITABLE_REC_TYPE -24
3624
3625#define WTAP_ERR_UNWRITABLE_REC_DATA -25
3627
3628#define WTAP_ERR_DECOMPRESSION_NOT_SUPPORTED -26
3630
3631#define WTAP_ERR_TIME_STAMP_NOT_SUPPORTED -27
3634
3635#define WTAP_ERR_REC_MALFORMED -28
3638
3639#ifdef __cplusplus
3640}
3641#endif /* __cplusplus */
3642
3643#endif /* __WTAP_H__ */
3644
3645/*
3646 * Editor modelines - https://www.wireshark.org/tools/modelines.html
3647 *
3648 * Local variables:
3649 * c-basic-offset: 4
3650 * tab-width: 8
3651 * indent-tabs-mode: nil
3652 * End:
3653 *
3654 * vi: set shiftwidth=4 tabstop=8 expandtab:
3655 * :indentSize=4:tabSize=8:noTabs=true:
3656 */
struct e_in6_addr ws_in6_addr
Represents a 128-bit IPv6 address.
#define WS_INET_CIDRADDRSTRLEN
Convert an IPv6 address to a string representation.
Definition inet_addr.h:155
A dynamic byte buffer with adjustable start and end positions.
Definition buffer.h:30
Aggregates lists of resolved IPv4 and IPv6 addresses for writing into a pcapng Name Resolution Block ...
Definition wtap.h:1704
GList * ipv6_addr_list
Definition wtap.h:1706
GList * ipv4_addr_list
Definition wtap.h:1705
Pseudo-header for Ascend WAN capture files carrying session, call, and task metadata.
Definition wtap.h:528
uint32_t chunk
Definition wtap.h:533
uint16_t type
Definition wtap.h:529
char call_num[64]
Definition wtap.h:532
uint32_t sess
Definition wtap.h:531
uint32_t task
Definition wtap.h:534
char user[64]
Definition wtap.h:530
Pseudo-header for ATM capture files carrying cell, circuit, and AAL-layer metadata.
Definition wtap.h:498
uint16_t vpi
Definition wtap.h:503
uint16_t aal5t_len
Definition wtap.h:509
uint16_t aal5t_u2u
Definition wtap.h:508
uint16_t channel
Definition wtap.h:506
uint8_t aal2_cid
Definition wtap.h:505
uint16_t cells
Definition wtap.h:507
uint8_t subtype
Definition wtap.h:502
uint32_t aal5t_chksum
Definition wtap.h:510
uint8_t aal
Definition wtap.h:500
uint16_t vci
Definition wtap.h:504
uint32_t flags
Definition wtap.h:499
uint8_t type
Definition wtap.h:501
Pseudo-header for BER (Basic Encoding Rules) data files.
Definition wtap.h:1334
const char * pathname
Definition wtap.h:1335
Pseudo-header for Bluetooth HCI capture files carrying direction and channel metadata.
Definition wtap.h:1180
bool sent
Definition wtap.h:1181
uint32_t channel
Definition wtap.h:1182
Pseudo-header for Linux Bluetooth Monitor (WTAP_ENCAP_BLUETOOTH_LINUX_MONITOR) capture files.
Definition wtap.h:1194
uint16_t opcode
Definition wtap.h:1196
uint16_t adapter_id
Definition wtap.h:1195
Pseudo-header for Catapult DCT2000 captures.
Definition wtap.h:1046
int64_t seek_off
Definition wtap.h:1053
struct wtap * wth
Definition wtap.h:1054
struct isdn_phdr isdn
Definition wtap.h:1048
struct p2p_phdr p2p
Definition wtap.h:1050
struct atm_phdr atm
Definition wtap.h:1049
Pseudo-header for CoSine Systems capture files carrying encapsulation, direction, and QoS metadata.
Definition wtap.h:916
uint16_t err
Definition wtap.h:924
uint16_t rm
Definition wtap.h:923
uint8_t direction
Definition wtap.h:918
uint16_t pro
Definition wtap.h:920
char if_name[128]
Definition wtap.h:919
uint16_t off
Definition wtap.h:921
uint16_t pri
Definition wtap.h:922
uint8_t encap
Definition wtap.h:917
Pseudo-header for DTE/DCE capture files (LAPB, V.120, Frame Relay) carrying direction metadata.
Definition wtap.h:405
uint8_t flags
Definition wtap.h:406
Holds a single ERF extension header word appended after the main ERF header.
Definition wtap.h:1072
uint64_t ehdr
Definition wtap.h:1073
Extended pseudo-header for ERF multi-channel (MC) packet records.
Definition wtap.h:1094
union erf_mc_phdr::@031203371227322325321065306065226045005243346162 subhdr
Protocol-specific subheader union.
struct wtap_erf_eth_hdr eth_hdr
Definition wtap.h:1105
struct erf_ehdr ehdr_list[16]
Definition wtap.h:1097
struct erf_phdr phdr
Definition wtap.h:1095
uint32_t aal2_hdr
Definition wtap.h:1107
uint32_t mc_hdr
Definition wtap.h:1106
Pseudo-header for Endace ERF (Extensible Record Format) capture files carrying timestamp and record m...
Definition wtap.h:1060
uint16_t lctr
Definition wtap.h:1065
uint16_t rlen
Definition wtap.h:1064
uint8_t type
Definition wtap.h:1062
uint8_t flags
Definition wtap.h:1063
uint64_t ts
Definition wtap.h:1061
uint16_t wlen
Definition wtap.h:1066
Pseudo-header for Ethernet capture files carrying FCS length metadata.
Definition wtap.h:396
int fcs_len
Definition wtap.h:397
For registering extensions used for file formats.
Definition wtap.h:1817
const char * extensions
Definition wtap.h:1820
const char * name
Definition wtap.h:1818
bool is_capture_file
Definition wtap.h:1819
Describes a single capture file type/subtype, including its metadata, capability flags,...
Definition wtap.h:2034
wtap_wslua_file_info_t * wslua_info
Definition wtap.h:2095
const char * name
Definition wtap.h:2044
const char * additional_file_extensions
Definition wtap.h:2058
int(* can_write_encap)(int)
Definition wtap.h:2083
const struct supported_block_type * supported_blocks
Definition wtap.h:2073
bool writing_must_seek
Definition wtap.h:2063
const char * description
Definition wtap.h:2038
bool(* dump_open)(wtap_dumper *, int *, char **)
Definition wtap.h:2089
size_t num_supported_blocks
Definition wtap.h:2068
const char * default_file_extension
Definition wtap.h:2050
Pseudo-header for GSM Um air interface (WTAP_ENCAP_GSM_UM) capture files.
Definition wtap.h:1218
bool uplink
Definition wtap.h:1219
uint8_t bsic
Definition wtap.h:1222
uint32_t tdma_frame
Definition wtap.h:1224
uint16_t arfcn
Definition wtap.h:1223
uint8_t channel
Definition wtap.h:1220
uint8_t error
Definition wtap.h:1225
uint16_t timeshift
Definition wtap.h:1226
Hash table entry for a resolved or unresolved IPv4 address.
Definition wtap.h:1680
char ip[WS_INET_ADDRSTRLEN]
Definition wtap.h:1683
char cidr_addr[WS_INET_CIDRADDRSTRLEN]
Definition wtap.h:1685
char name[256]
Definition wtap.h:1684
unsigned addr
Definition wtap.h:1681
uint8_t flags
Definition wtap.h:1682
Hash table entry for a resolved or unresolved IPv6 address.
Definition wtap.h:1692
char name[256]
Definition wtap.h:1696
char ip6[WS_INET6_ADDRSTRLEN]
Definition wtap.h:1695
uint8_t flags
Definition wtap.h:1694
uint8_t addr[16]
Definition wtap.h:1693
char cidr_addr[WS_INET6_CIDRADDRSTRLEN]
Definition wtap.h:1697
Pseudo-header for I2C bus capture files carrying bus number, event type, and flag metadata.
Definition wtap.h:1209
uint32_t flags
Definition wtap.h:1212
uint8_t bus
Definition wtap.h:1211
uint8_t is_event
Definition wtap.h:1210
Definition pcapio.c:117
PHY metadata for 802.11 legacy FHSS (Frequency Hopping Spread Spectrum) captures.
Definition wtap.h:593
unsigned has_hop_pattern
Definition wtap.h:595
uint8_t hop_set
Definition wtap.h:598
uint8_t hop_index
Definition wtap.h:600
uint8_t hop_pattern
Definition wtap.h:599
unsigned has_hop_set
Definition wtap.h:594
unsigned has_hop_index
Definition wtap.h:596
Pseudo-header for 802.11 wireless capture files carrying full PHY, signal, and frame metadata.
Definition wtap.h:847
unsigned has_noise_percent
Definition wtap.h:859
unsigned has_frequency
Definition wtap.h:856
uint32_t frequency
Definition wtap.h:869
unsigned has_signal_dbm
Definition wtap.h:860
unsigned has_signal_db
Definition wtap.h:862
int8_t noise_dbm
Definition wtap.h:874
unsigned phy
Definition wtap.h:852
unsigned has_aggregate_info
Definition wtap.h:865
unsigned has_signal_percent
Definition wtap.h:858
unsigned has_channel
Definition wtap.h:855
union ieee_802_11_phy_info phy_info
Definition wtap.h:853
unsigned has_zero_length_psdu_type
Definition wtap.h:866
unsigned datapad
Definition wtap.h:850
unsigned decrypted
Definition wtap.h:849
int fcs_len
Definition wtap.h:848
uint16_t channel
Definition wtap.h:868
uint8_t signal_db
Definition wtap.h:875
unsigned has_tsf_timestamp
Definition wtap.h:864
uint32_t aggregate_id
Definition wtap.h:879
uint16_t data_rate
Definition wtap.h:870
uint8_t signal_percent
Definition wtap.h:871
unsigned has_data_rate
Definition wtap.h:857
uint8_t zero_length_psdu_type
Definition wtap.h:880
uint8_t noise_percent
Definition wtap.h:872
uint64_t tsf_timestamp
Definition wtap.h:877
unsigned has_noise_db
Definition wtap.h:863
unsigned has_noise_dbm
Definition wtap.h:861
unsigned no_a_msdus
Definition wtap.h:851
uint8_t noise_db
Definition wtap.h:876
int8_t signal_dbm
Definition wtap.h:873
uint32_t aggregate_flags
Definition wtap.h:878
PHY metadata for 802.11a captures.
Definition wtap.h:617
unsigned channel_type
Definition wtap.h:621
unsigned has_channel_type
Definition wtap.h:618
unsigned has_turbo_type
Definition wtap.h:619
unsigned turbo_type
Definition wtap.h:622
PHY metadata for 802.11ac (VHT) captures.
Definition wtap.h:718
uint8_t fec
Definition wtap.h:739
unsigned has_short_gi
Definition wtap.h:721
unsigned short_gi_nsym_disambig
Definition wtap.h:733
unsigned txop_ps_not_allowed
Definition wtap.h:731
unsigned stbc
Definition wtap.h:730
uint8_t nss[4]
Definition wtap.h:738
uint16_t partial_aid
Definition wtap.h:741
unsigned has_beamformed
Definition wtap.h:724
unsigned has_ldpc_extra_ofdm_symbol
Definition wtap.h:723
uint8_t mcs[4]
Definition wtap.h:737
unsigned has_bandwidth
Definition wtap.h:725
unsigned has_stbc
Definition wtap.h:719
unsigned has_partial_aid
Definition wtap.h:728
unsigned has_fec
Definition wtap.h:726
unsigned beamformed
Definition wtap.h:735
unsigned short_gi
Definition wtap.h:732
unsigned has_short_gi_nsym_disambig
Definition wtap.h:722
uint8_t bandwidth
Definition wtap.h:736
unsigned has_group_id
Definition wtap.h:727
uint8_t group_id
Definition wtap.h:740
unsigned has_txop_ps_not_allowed
Definition wtap.h:720
unsigned ldpc_extra_ofdm_symbol
Definition wtap.h:734
PHY metadata for 802.11ad (WiGig/DMG) captures.
Definition wtap.h:761
uint8_t mcs
Definition wtap.h:764
unsigned has_mcs_index
Definition wtap.h:762
PHY metadata for 802.11ax (HE — High Efficiency) captures.
Definition wtap.h:771
uint8_t bwru
Definition wtap.h:778
uint8_t gi
Definition wtap.h:779
unsigned has_gi
Definition wtap.h:774
uint8_t mcs
Definition wtap.h:777
uint8_t nsts
Definition wtap.h:776
unsigned has_bwru
Definition wtap.h:773
unsigned has_mcs_index
Definition wtap.h:772
PHY metadata for 802.11b captures.
Definition wtap.h:607
unsigned has_short_preamble
Definition wtap.h:608
bool short_preamble
Definition wtap.h:610
Per-user PHY metadata for a single user within an 802.11be (EHT) MU transmission.
Definition wtap.h:786
unsigned data_for_this_user
Definition wtap.h:794
unsigned coding_known
Definition wtap.h:789
unsigned mcs_known
Definition wtap.h:788
unsigned sta_id
Definition wtap.h:795
unsigned spatial_config_known
Definition wtap.h:793
unsigned ldpc_coding
Definition wtap.h:796
unsigned bf_known
Definition wtap.h:792
unsigned nsts_known
Definition wtap.h:791
unsigned sta_id_known
Definition wtap.h:787
unsigned mcs
Definition wtap.h:797
unsigned rsv
Definition wtap.h:799
unsigned nsts
Definition wtap.h:798
unsigned beamform
Definition wtap.h:800
unsigned rsv_known
Definition wtap.h:790
unsigned rsv2
Definition wtap.h:801
PHY metadata for 802.11be (EHT — Extremely High Throughput) captures.
Definition wtap.h:809
uint8_t bandwidth
Definition wtap.h:814
unsigned has_bandwidth
Definition wtap.h:812
unsigned has_ru_mru_size
Definition wtap.h:810
uint8_t ru_mru_size
Definition wtap.h:815
unsigned has_gi
Definition wtap.h:811
uint8_t gi
Definition wtap.h:816
uint8_t num_users
Definition wtap.h:817
struct ieee_802_11be_user_info user[4]
Definition wtap.h:818
PHY metadata for 802.11g OFDM captures.
Definition wtap.h:652
uint32_t mode
Definition wtap.h:655
unsigned has_mode
Definition wtap.h:653
PHY metadata for 802.11n (HT) captures.
Definition wtap.h:667
unsigned fec
Definition wtap.h:680
unsigned short_gi
Definition wtap.h:678
unsigned has_fec
Definition wtap.h:672
unsigned has_greenfield
Definition wtap.h:671
uint16_t mcs_index
Definition wtap.h:676
unsigned has_stbc_streams
Definition wtap.h:673
unsigned ness
Definition wtap.h:682
unsigned greenfield
Definition wtap.h:679
unsigned has_ness
Definition wtap.h:674
unsigned stbc_streams
Definition wtap.h:681
unsigned has_mcs_index
Definition wtap.h:668
unsigned has_bandwidth
Definition wtap.h:669
unsigned bandwidth
Definition wtap.h:677
unsigned has_short_gi
Definition wtap.h:670
Pseudo-header carrying IrDA packet type metadata for captured IrDA frames.
Definition wtap.h:951
uint16_t pkttype
Definition wtap.h:952
Pseudo-header for ISDN capture files carrying direction and channel metadata.
Definition wtap.h:412
bool uton
Definition wtap.h:413
uint8_t channel
Definition wtap.h:414
Pseudo-header for Tektronix K12 capture files carrying input port, stack, and protocol metadata.
Definition wtap.h:1012
const char * input_name
Definition wtap.h:1014
uint32_t input
Definition wtap.h:1013
void * stuff
Definition wtap.h:1020
uint8_t * extra_info
Definition wtap.h:1018
k12_input_info_t input_info
Definition wtap.h:1017
uint32_t extra_length
Definition wtap.h:1019
uint32_t input_type
Definition wtap.h:1016
const char * stack_file
Definition wtap.h:1015
Pseudo-header for layer 1 event (WTAP_ENCAP_LAYER1_EVENT) capture files carrying signal direction met...
Definition wtap.h:1202
bool uton
Definition wtap.h:1203
LAPD pseudo-header for packet metadata.
Definition wtap.h:1034
uint8_t we_network
Definition wtap.h:1036
uint16_t pkttype
Definition wtap.h:1035
Pseudo-header for NFC Logical Link Control Protocol (LLCP) capture files.
Definition wtap.h:1277
uint8_t adapter
Definition wtap.h:1278
uint8_t flags
Definition wtap.h:1279
Pseudo-header for Android Logcat (WTAP_ENCAP_LOGCAT) capture files.
Definition wtap.h:1285
int version
Definition wtap.h:1286
Pseudo-header for M-Module binary files.
Definition wtap.h:1342
uint8_t chunktype
Definition wtap.h:1343
Pseudo-header carrying MTP2 link metadata for captured SS7 MTP2 frames.
Definition wtap.h:975
uint8_t annex_a_used
Definition wtap.h:977
uint16_t link_number
Definition wtap.h:978
uint8_t sent
Definition wtap.h:976
Pseudo-header metadata for packets captured in NetMon (Network Monitor) files.
Definition wtap.h:1296
unsigned sub_encap
Definition wtap.h:1301
uint8_t * description
Definition wtap.h:1299
uint8_t * title
Definition wtap.h:1297
uint32_t descLength
Definition wtap.h:1298
Pseudo-header for HP-UX nettl capture files carrying subsystem, device, and process metadata.
Definition wtap.h:958
int32_t pid
Definition wtap.h:962
uint16_t subsys
Definition wtap.h:959
uint32_t devid
Definition wtap.h:960
uint32_t kind
Definition wtap.h:961
uint32_t uid
Definition wtap.h:963
Pseudo-header for Nokia firewall capture files, extending the Ethernet pseudo-header with device-spec...
Definition wtap.h:1267
struct eth_phdr eth
Definition wtap.h:1268
uint8_t stuff[4]
Definition wtap.h:1269
Definition nstime.h:26
Pseudo-header for Citrix NetScaler nstrace capture files carrying field offset and record layout meta...
Definition wtap.h:1242
uint8_t dir_len
Definition wtap.h:1248
uint8_t src_vmname_len_offset
Definition wtap.h:1258
uint8_t clflags_offset
Definition wtap.h:1257
uint8_t srcnodeid_offset
Definition wtap.h:1255
uint8_t ns_activity_offset
Definition wtap.h:1260
uint8_t pcb_offset
Definition wtap.h:1250
uint8_t dst_vmname_len_offset
Definition wtap.h:1259
uint8_t coreid_offset
Definition wtap.h:1254
uint8_t data_offset
Definition wtap.h:1261
uint8_t rec_type
Definition wtap.h:1252
uint8_t destnodeid_offset
Definition wtap.h:1256
uint8_t nicno_offset
Definition wtap.h:1245
int64_t rec_offset
Definition wtap.h:1243
uint8_t nicno_len
Definition wtap.h:1246
uint8_t l_pcb_offset
Definition wtap.h:1251
uint8_t vlantag_offset
Definition wtap.h:1253
int32_t rec_len
Definition wtap.h:1244
uint8_t dir_offset
Definition wtap.h:1247
uint16_t eth_offset
Definition wtap.h:1249
Information about a given file type that applies to all subtypes of the file type.
Definition wtap.h:1925
const char * name
Definition wtap.h:1926
wtap_open_routine_t open_routine
Definition wtap.h:1928
void * wslua_data
Definition wtap.h:1931
const char * extensions
Definition wtap.h:1929
wtap_open_type type
Definition wtap.h:1927
char ** extensions_set
Definition wtap.h:1930
Pseudo-header for point-to-point link capture files carrying packet direction metadata.
Definition wtap.h:540
bool sent
Definition wtap.h:541
Pseudo-header for Microsoft ProcMon (Process Monitor) captures.
Definition wtap.h:1322
struct procmon_process_t * process_array
Definition wtap.h:1325
uint32_t * process_index_map
Definition wtap.h:1323
size_t process_array_size
Definition wtap.h:1326
size_t process_index_map_size
Definition wtap.h:1324
bool system_bitness
Definition wtap.h:1327
Describes a single process observed by Process Monitor, including its identity, security context,...
Definition procmon.h:30
Definition ngsniffer.c:82
Pseudo-header for SITA WAN capture files carrying signal, error, and protocol metadata.
Definition wtap.h:1169
uint8_t sita_signals
Definition wtap.h:1171
uint8_t sita_flags
Definition wtap.h:1170
uint8_t sita_errors2
Definition wtap.h:1173
uint8_t sita_proto
Definition wtap.h:1174
uint8_t sita_errors1
Definition wtap.h:1172
Describes a single block type supported by a file format, including its option support.
Definition wtap.h:2021
const struct supported_option_type * supported_options
Definition wtap.h:2025
block_support_t support
Definition wtap.h:2023
wtap_block_type_t type
Definition wtap.h:2022
size_t num_supported_options
Definition wtap.h:2024
Entry describing support level for a specific option type.
Definition wtap.h:1988
unsigned opt
Definition wtap.h:1989
option_support_t support
Definition wtap.h:1990
Header metadata for a pcapng Custom Block record.
Definition wtap.h:1564
uint32_t pen
Definition wtap.h:1565
uint32_t length
Definition wtap.h:1566
bool copy_allowed
Definition wtap.h:1567
Definition wtap.h:1725
const GArray * nrbs_growing
Definition wtap.h:1734
const GArray * dsbs_growing
Definition wtap.h:1738
int tsprec
Definition wtap.h:1728
GArray * shb_hdrs
Definition wtap.h:1729
int encap
Definition wtap.h:1726
bool dont_copy_idbs
Definition wtap.h:1747
GArray * dsbs_initial
Definition wtap.h:1737
wtapng_iface_descriptions_t * idb_inf
Definition wtap.h:1733
const GArray * mevs_growing
Definition wtap.h:1741
const GArray * shb_iface_to_global
Definition wtap.h:1730
const GArray * dpibs_growing
Definition wtap.h:1744
int snaplen
Definition wtap.h:1727
Wiretap dumper handle and associated state.
Definition wtap_module.h:163
ERF Ethernet subheader providing the frame offset for Ethernet ERF records.
Definition wtap.h:1081
uint8_t pad
Definition wtap.h:1083
uint8_t offset
Definition wtap.h:1082
Header metadata for a file-type-specific event or report record.
Definition wtap.h:1529
union wtap_pseudo_header pseudo_header
Definition wtap.h:1534
uint32_t record_len
Definition wtap.h:1532
int file_type_subtype
Definition wtap.h:1530
unsigned record_type
Definition wtap.h:1531
Header metadata for a captured network packet.
Definition wtap.h:1446
uint32_t caplen
Definition wtap.h:1447
uint32_t interface_id
Definition wtap.h:1450
int pkt_encap
Definition wtap.h:1449
union wtap_pseudo_header pseudo_header
Definition wtap.h:1452
uint32_t len
Definition wtap.h:1448
Plugin registration callback table.
Definition wtap.h:3437
Definition file_wrappers.c:96
Represents a single capture record read from or written to a capture file, regardless of record type.
Definition wtap.h:1597
wtap_syscall_header syscall_header
Definition wtap.h:1611
bool block_was_modified
Definition wtap.h:1625
unsigned rec_type
Definition wtap.h:1598
unsigned section_number
Definition wtap.h:1600
const char * rec_type_name
Definition wtap.h:1603
wtap_packet_header packet_header
Definition wtap.h:1609
wtap_block_t block
Block-level metadata associated with this record.
Definition wtap.h:1623
wtap_ft_specific_header ft_specific_header
Definition wtap.h:1610
wtap_custom_block_header custom_block_header
Definition wtap.h:1613
wtap_systemd_journal_export_header systemd_journal_export_header
Definition wtap.h:1612
int tsprec
Definition wtap.h:1602
Buffer options_buf
Reusable buffer holding serialized file-type-specific option data for this record.
Definition wtap.h:1632
uint32_t presence_flags
Definition wtap.h:1599
nstime_t ts
Definition wtap.h:1601
Buffer data
Definition wtap.h:1634
Header metadata for a system call record (e.g. from Sysdig/Falco captures).
Definition wtap.h:1540
uint16_t cpu_id
Definition wtap.h:1551
uint32_t event_data_len
Definition wtap.h:1547
const char * pathname
Definition wtap.h:1541
uint64_t thread_id
Definition wtap.h:1545
uint64_t timestamp
Definition wtap.h:1544
uint32_t nparams
Definition wtap.h:1548
uint32_t flags
Definition wtap.h:1549
unsigned record_type
Definition wtap.h:1542
uint16_t event_type
Definition wtap.h:1550
uint32_t event_len
Definition wtap.h:1546
int byte_order
Definition wtap.h:1543
Header metadata for a systemd journal export record.
Definition wtap.h:1557
uint32_t record_len
Definition wtap.h:1558
Companion metadata block for Lua-based file writers registered via wslua, carrying the write-open cal...
Definition wtap.h:1774
void * wslua_data
Definition wtap.h:1776
int(* wslua_can_write_encap)(int, void *)
Definition wtap.h:1775
Definition wtap_module.h:58
wtap_new_secrets_callback_t add_new_secrets
Definition wtap_module.h:113
const char * app_env_var_prefix
Definition wtap_module.h:74
int file_type_subtype
Definition wtap_module.h:62
wtap_new_ipv4_callback_t add_new_ipv4
Definition wtap_module.h:111
wtap_new_ipv6_callback_t add_new_ipv6
Definition wtap_module.h:112
Union representing physical layer information for IEEE 802.11 variants.
Definition wtap.h:832
struct ieee_802_11_fhss info_11_fhss
Definition wtap.h:833
struct ieee_802_11ac info_11ac
Definition wtap.h:838
struct ieee_802_11n info_11n
Definition wtap.h:837
struct ieee_802_11g info_11g
Definition wtap.h:836
struct ieee_802_11ax info_11ax
Definition wtap.h:840
struct ieee_802_11b info_11b
Definition wtap.h:834
struct ieee_802_11be info_11be
Definition wtap.h:841
struct ieee_802_11ad info_11ad
Definition wtap.h:839
struct ieee_802_11a info_11a
Definition wtap.h:835
Pseudo-header metadata for packets in K12 capture files.
Definition wtap.h:988
uint16_t vp
Definition wtap.h:995
uint16_t cid
Definition wtap.h:997
uint16_t vc
Definition wtap.h:996
uint32_t ds0mask
DS0 channel bitmask.
Definition wtap.h:1006
Protocol-specific subheader union.
Definition wtap.h:1308
struct eth_phdr eth
Definition wtap.h:1309
struct atm_phdr atm
Definition wtap.h:1310
struct ieee_802_11_phdr ieee_802_11
Definition wtap.h:1311
Top-level union of all Wiretap pseudo-headers.
Definition wtap.h:1352
struct l1event_phdr l1event
Definition wtap.h:1371
struct lapd_phdr lapd
Definition wtap.h:1365
struct i2c_phdr i2c
Definition wtap.h:1372
struct p2p_phdr p2p
Definition wtap.h:1358
struct ieee_802_11_phdr ieee_802_11
Definition wtap.h:1359
struct k12_phdr k12
Definition wtap.h:1364
struct btmon_phdr btmon
Definition wtap.h:1370
struct nokia_phdr nokia
Definition wtap.h:1375
struct ber_phdr ber
Definition wtap.h:1380
struct sita_phdr sita
Definition wtap.h:1368
struct bthci_phdr bthci
Definition wtap.h:1369
struct llcp_phdr llcp
Definition wtap.h:1376
struct mtp2_phdr mtp2
Definition wtap.h:1363
struct logcat_phdr logcat
Definition wtap.h:1377
struct atm_phdr atm
Definition wtap.h:1356
struct dte_dce_phdr dte_dce
Definition wtap.h:1354
struct isdn_phdr isdn
Definition wtap.h:1355
struct catapult_dct2000_phdr dct2000
Definition wtap.h:1366
struct irda_phdr irda
Definition wtap.h:1361
struct netmon_phdr netmon
Definition wtap.h:1378
struct gsm_um_phdr gsm_um
Definition wtap.h:1373
struct nettl_phdr nettl
Definition wtap.h:1362
struct cosine_phdr cosine
Definition wtap.h:1360
struct erf_mc_phdr erf
Definition wtap.h:1367
struct ascend_phdr ascend
Definition wtap.h:1357
struct nstr_phdr nstr
Definition wtap.h:1374
struct mmodule_phdr mmodule
Definition wtap.h:1381
struct procmon_phdr procmon
Definition wtap.h:1379
struct eth_phdr eth
Definition wtap.h:1353
WS_DLL_PUBLIC bool wtap_dump_can_open(int filetype)
Check if a file type can be opened for dumping.
Definition file_access.c:2068
WS_DLL_PUBLIC void wtap_buffer_append_epdu_tag(Buffer *buf, uint16_t epdu_tag, const uint8_t *data, uint16_t data_len)
Generates arbitrary packet data in "exported PDU" format and appends it to buf.
Definition wtap.c:2281
WS_DLL_PUBLIC GSList * wtap_get_all_file_extensions_list(void)
Return a list of all extensions that are used by all file types that we can read, including compresse...
Definition file_access.c:2012
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open(const char *filename, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Opens a new capture file for writing.
Definition file_access.c:2241
void(* wtap_new_secrets_callback_t)(uint32_t secrets_type, const void *secrets, unsigned size)
Callback type for receiving new decryption secrets.
Definition wtap.h:2201
WS_DLL_PUBLIC int wtap_register_file_type_subtype(const struct file_type_subtype_info *fi)
Register a file type/subtype.
Definition file_access.c:1172
WS_DLL_PUBLIC bool wtap_dump_flush(wtap_dumper *wdh, int *err)
Flushes the dump file.
Definition file_access.c:2563
WS_DLL_PUBLIC int64_t wtap_file_size(wtap *wth, int *err)
Get the size of the capture file.
Definition wtap.c:81
WS_DLL_PUBLIC GSList * wtap_get_all_capture_file_extensions_list(void)
Return a list of all extensions that are used by all capture file types, including compressed extensi...
Definition file_access.c:1963
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open_tempfile(const char *tmpdir, char **filenamep, const char *pfx, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for a temporary file.
Definition file_access.c:2283
option_support_t
Indicates how a file format supports a given option type.
Definition wtap.h:1976
@ MULTIPLE_OPTIONS_SUPPORTED
Definition wtap.h:1979
@ OPTION_NOT_SUPPORTED
Definition wtap.h:1977
@ ONE_OPTION_SUPPORTED
Definition wtap.h:1978
WS_DLL_PUBLIC GSList * wtap_get_file_extensions_list(int file_type_subtype, bool include_compressed)
Return a list of file extensions that are used by the specified file type and subtype.
Definition file_access.c:1906
struct hashipv6 hashipv6_t
Hash table entry for a resolved or unresolved IPv6 address.
WS_DLL_PUBLIC GArray * wtap_get_savable_file_types_subtypes_for_file(int file_type_subtype, const GArray *file_encaps, uint32_t required_comment_types, ft_sort_order sort_order)
Get savable file type/subtype candidates for saving a capture file.
Definition file_access.c:1455
WS_DLL_PUBLIC char * wtap_unwritable_rec_type_err_string(const wtap_rec *rec)
Return an error string for WTAP_ERR_UNWRITABLE_REC_TYPE.
Definition wtap.c:1781
WS_DLL_PUBLIC int wtap_plugins_supported(void)
Query whether libwiretap plugin loading is available.
Definition wtap.c:57
WS_DLL_PUBLIC const char * wtap_encap_description(int encap)
Get a human-readable description for an encapsulation type.
Definition wtap.c:1403
WS_DLL_PUBLIC wtap_block_t wtap_file_get_shb(wtap *wth, unsigned shb_num)
Gets existing section header block, not for new file.
Definition wtap.c:146
WS_DLL_PUBLIC const char * wtap_file_type_subtype_description(int file_type_subtype)
Get a human-readable description for a file type/subtype.
Definition file_access.c:1631
WS_DLL_PUBLIC void wtap_dump_params_cleanup(wtap_dump_params *params)
Free memory associated with the wtap_dump_params when it is no longer in use by wtap_dumper.
Definition wtap.c:644
void(* wtap_new_ipv6_callback_t)(const ws_in6_addr *addrp, const char *name, const bool static_entry)
Callback type for registering new IPv6 hostnames.
Definition wtap.h:2177
WS_DLL_PUBLIC wtapng_iface_descriptions_t * wtap_file_get_idb_info(wtap *wth)
Gets existing interface descriptions.
Definition wtap.c:198
WS_DLL_PUBLIC void wtap_setup_packet_rec(wtap_rec *rec, int encap)
Set up a wtap_rec for a packet (REC_TYPE_PACKET).
Definition wtap.c:1791
WS_DLL_PUBLIC GSList * wtap_get_file_extension_type_extensions(unsigned extension_type)
Get the list of extensions for a file extension type.
Definition file_access.c:207
WS_DLL_PUBLIC void wtap_deregister_open_info(const char *name)
Deregister an open_info handler by name.
Definition file_access.c:498
struct hashipv4 hashipv4_t
Hash table entry for a resolved or unresolved IPv4 address.
WS_DLL_PUBLIC void wtap_set_bytes_dumped(wtap_dumper *wdh, int64_t bytes_dumped)
Set the number of bytes dumped by a capture file.
Definition file_access.c:2636
WS_DLL_PUBLIC bool wtap_dump_close(wtap_dumper *wdh, bool *needs_reload, int *err, char **err_info)
Definition file_access.c:2592
WS_DLL_PUBLIC wtap_block_t wtap_get_next_interface_description(wtap *wth)
Gets next interface description.
Definition wtap.c:221
ft_sort_order
Controls the sort key used when enumerating or presenting file type lists.
Definition wtap.h:3077
@ FT_SORT_BY_NAME
Definition wtap.h:3078
@ FT_SORT_BY_DESCRIPTION
Definition wtap.h:3079
WS_DLL_PUBLIC bool wtap_read(wtap *wth, wtap_rec *rec, int *err, char **err_info, int64_t *offset)
Read the next record in the file, filling in *phdr and *buf.
Definition wtap.c:1852
WS_DLL_PUBLIC void wtap_buffer_append_epdu_string(Buffer *buf, uint16_t epdu_tag, const char *val)
Generates packet data for a string in "exported PDU" format. For filetype readers to transform non-pa...
Definition wtap.c:2328
WS_DLL_PUBLIC void wtap_free_idb_info(wtapng_iface_descriptions_t *idb_info)
Free's a interface description block and all of its members.
Definition wtap.c:396
WS_DLL_PUBLIC struct wtap * wtap_open_offline(const char *filename, unsigned int type, int *err, char **err_info, bool do_random, const char *app_env_var_prefix)
Open a capture file for offline analysis.
Definition file_access.c:846
WS_DLL_PUBLIC int wtap_dump_file_type_subtype(const wtap_dumper *wdh)
Get the file type subtype of a dump file.
Definition file_access.c:2624
WS_DLL_PUBLIC int wtap_file_type_subtype(wtap *wth)
Get the file type subtype.
Definition wtap.c:104
WS_DLL_PUBLIC void wtap_register_file_type_extension(const struct file_extension_info *ei)
Register file extension information for a file type.
Definition file_access.c:151
WS_DLL_PUBLIC const char * wtap_get_file_extension_type_name(int extension_type)
Get the short name for a file extension type.
Definition file_access.c:165
WS_DLL_PUBLIC bool wtap_dump_add_idb(wtap_dumper *wdh, wtap_block_t idb, int *err, char **err_info)
Add an IDB to the list of IDBs for a file we're writing. Makes a copy of the IDB, so it can be freed ...
Definition file_access.c:2525
wtap_open_type
Strategy used to identify a file format.
Definition wtap.h:1878
@ OPEN_INFO_MAGIC
Definition wtap.h:1879
@ OPEN_INFO_HEURISTIC
Definition wtap.h:1880
WS_DLL_PUBLIC void wtap_dump_params_discard_decryption_secrets(wtap_dump_params *params)
Remove any decryption secret information from the per-file information; used if we're stripping decry...
Definition wtap.c:631
WS_DLL_PUBLIC void wtap_fdclose(wtap *wth)
Close all file descriptors for the current wiretap file.
Definition wtap.c:1599
wtap_open_return_val
For registering file types that we can open.
Definition wtap.h:1849
@ WTAP_OPEN_MINE
Definition wtap.h:1851
@ WTAP_OPEN_NOT_MINE
Definition wtap.h:1850
@ WTAP_OPEN_ERROR
Definition wtap.h:1852
#define MAX_ERF_EHDR
Definition wtap.h:1076
WS_DLL_PUBLIC void wtap_rec_reset(wtap_rec *rec)
Re-initialize a wtap_rec structure.
Definition wtap.c:2118
WS_DLL_PUBLIC bool wtap_has_open_info(const char *name)
Check if an open_info handler with the given name is registered.
Definition file_access.c:522
WS_DLL_PUBLIC int wtap_dump_required_file_encap_type(const GArray *file_encaps)
Determine the required per-file encapsulation type.
Definition file_access.c:1289
WS_DLL_PUBLIC void wtap_dump_discard_name_resolution(wtap_dumper *wdh)
Discard name resolution information for a dump file.
Definition file_access.c:2661
WS_DLL_PUBLIC int wtap_file_encap(wtap *wth)
Get the encapsulation type for the capture file.
Definition wtap.c:116
WS_DLL_PUBLIC void wtap_dump_params_discard_name_resolution(wtap_dump_params *params)
Remove any name resolution information from the per-file information; used if we're stripping name re...
Definition wtap.c:625
WS_DLL_PUBLIC wtap_dumper * wtap_dump_open_stdout(int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for the standard output.
Definition file_access.c:2386
WS_DLL_PUBLIC void wtap_dump_params_init_no_idbs(wtap_dump_params *params, wtap *wth)
Initialize the per-file information based on an existing file, but don't copy over the interface info...
Definition wtap.c:602
WS_DLL_PUBLIC wtap_dumper * wtap_dump_fdopen(int fd, int file_type_subtype, ws_compression_type compression_type, const wtap_dump_params *params, int *err, char **err_info)
Creates a dumper for an existing file descriptor.
Definition file_access.c:2348
WS_DLL_PUBLIC void wtap_buffer_append_epdu_uint(Buffer *buf, uint16_t epdu_tag, uint32_t val)
Generates packet data for an unsigned integer in "exported PDU" format. For filetype readers to trans...
Definition wtap.c:2312
WS_DLL_PUBLIC void wtap_dump_discard_decryption_secrets(wtap_dumper *wdh)
Discard decryption secrets for a dump file.
Definition file_access.c:2673
WS_DLL_PUBLIC const nstime_t * wtap_file_start_ts(wtap *wth)
Get the start timestamp of the capture file.
Definition wtap.c:128
WS_DLL_PUBLIC int wtap_get_num_file_type_extensions(void)
Return the number of registered file type extension groups.
Definition file_access.c:159
WS_DLL_PUBLIC void wtap_setup_custom_block_rec(wtap_rec *rec, uint32_t pen, uint32_t payload_length, bool copy_allowed)
Set up a wtap_rec for a custom block.
Definition wtap.c:1841
WS_DLL_PUBLIC const char * wtap_strerror(int err)
Return a human-readable error string for a WTAP error code.
Definition wtap.c:1548
WS_DLL_PUBLIC unsigned wtap_file_get_shb_global_interface_id(wtap *wth, unsigned shb_num, uint32_t interface_id)
Gets the unique interface id for a SHB's interface.
Definition wtap.c:155
WS_DLL_PUBLIC unsigned wtap_file_get_num_shbs(wtap *wth)
Gets number of section header blocks.
Definition wtap.c:140
WS_DLL_PUBLIC void wtap_register_plugin(const wtap_plugin *plug)
Register a wiretap plugin.
WS_DLL_PUBLIC void wtap_deregister_file_type_subtype(const int file_type_subtype)
Deregister a previously registered file type/subtype.
Definition file_access.c:1249
WS_DLL_PUBLIC void wtap_dump_params_init(wtap_dump_params *params, wtap *wth)
Initialize the per-file information based on an existing file.
Definition wtap.c:575
WS_DLL_PUBLIC bool wtap_dump(wtap_dumper *wdh, const wtap_rec *rec, int *err, char **err_info)
Write a record to the dump file.
Definition file_access.c:2555
WS_DLL_PUBLIC void wtap_free_extensions_list(GSList *extensions)
Free a list of file extension strings returned by extension helpers.
Definition file_access.c:2039
WS_DLL_PUBLIC bool wtap_uses_lua_filehandler(const wtap *wth)
Check whether a wtap handle uses a Lua-based file handler.
Definition file_access.c:542
WS_DLL_PUBLIC void wtap_write_shb_comment(wtap *wth, char *comment)
Sets or replaces the section header comment.
Definition wtap.c:190
block_support_t
Indicates how many instances of a given block type a file format supports.
Definition wtap.h:2012
@ MULTIPLE_BLOCKS_SUPPORTED
Definition wtap.h:2015
@ ONE_BLOCK_SUPPORTED
Definition wtap.h:2014
@ BLOCK_NOT_SUPPORTED
Definition wtap.h:2013
struct wtap_wslua_file_info wtap_wslua_file_info_t
Companion metadata block for Lua-based file writers registered via wslua, carrying the write-open cal...
WS_DLL_PUBLIC void init_open_routines(void)
Initialize registered file open routines.
Definition file_access.c:417
WS_DLL_PUBLIC int64_t wtap_read_so_far(wtap *wth)
Return an approximation of the amount of data read sequentially.
Definition wtap.c:2072
WS_DLL_PUBLIC void wtap_file_add_decryption_secrets(wtap *wth, const wtap_block_t dsb)
Adds a Decryption Secrets Block to the open wiretap session.
Definition wtap.c:262
WS_DLL_PUBLIC void wtap_set_cb_new_secrets(wtap *wth, wtap_new_secrets_callback_t add_new_secrets)
Set the callback for receiving new decryption secrets.
Definition wtap.c:1720
WS_DLL_PUBLIC void wtap_setup_systemd_journal_export_rec(wtap_rec *rec)
Set up a wtap_rec for a systemd journal export entry.
Definition wtap.c:1831
WS_DLL_PUBLIC void wtap_cleanup(void)
Clean up libwiretap internal registrations and plugin state.
Definition wtap.c:2381
WS_DLL_PUBLIC int wtap_pcapng_file_type_subtype(void)
Get the file type/subtype identifier for pcapng.
Definition file_access.c:1728
void cleanup_open_routines(void)
Clean up registered file open routines.
Definition file_access.c:2858
WS_DLL_PUBLIC int64_t wtap_get_bytes_dumped(const wtap_dumper *wdh)
Get the number of bytes dumped by a packet capture.
Definition file_access.c:2630
WS_DLL_PUBLIC void wtap_cleareof(wtap *wth)
Clear EOF status for a wiretap file.
Definition wtap.c:1639
struct addrinfo_lists addrinfo_lists_t
Aggregates lists of resolved IPv4 and IPv6 addresses for writing into a pcapng Name Resolution Block ...
WS_DLL_PUBLIC const nstime_t * wtap_file_end_ts(wtap *wth)
Get the end timestamp of the capture file.
Definition wtap.c:134
WS_DLL_PUBLIC unsigned wtap_file_get_num_dsbs(wtap *wth)
Gets number of decryption secrets blocks.
Definition wtap.c:244
WS_DLL_PUBLIC ws_compression_type wtap_get_compression_type(wtap *wth)
Get the compression type used for the capture file.
Definition file_wrappers.c:46
WS_DLL_PUBLIC int wtap_pcap_nsec_file_type_subtype(void)
Get the file type/subtype identifier for pcap with nanosecond timestamps.
Definition file_access.c:1714
WS_DLL_PUBLIC void wtap_close(wtap *wth)
Fully close the wiretap file and release all resources.
Definition wtap.c:1608
WS_DLL_PUBLIC void wtap_setup_syscall_rec(wtap_rec *rec)
Set up a wtap_rec for a system call.
Definition pcapng-sysdig.c:40
WS_DLL_PUBLIC bool wtap_dump_set_addrinfo_list(wtap_dumper *wdh, addrinfo_lists_t *addrinfo_lists)
Set the address information list for a dump file.
Definition file_access.c:2650
WS_DLL_PUBLIC void wtap_rec_apply_snapshot(wtap_rec *rec, uint32_t snaplen)
Apply a snapshot length to a wtap_rec.
Definition wtap.c:2092
WS_DLL_PUBLIC int wtap_file_tsprec(wtap *wth)
Get the timestamp precision for the capture file.
Definition wtap.c:122
WS_DLL_PUBLIC void wtap_init(bool load_wiretap_plugins, const char *app_env_var_prefix, const struct file_extension_info *file_extensions, unsigned num_extensions)
Initialize the Wiretap library.
Definition wtap.c:2362
WS_DLL_PUBLIC bool wtap_dump_can_write_encap(int file_type_subtype, int encap)
Check if a file type/subtype supports writing a given encapsulation.
Definition file_access.c:1302
WS_DLL_PUBLIC bool wtap_dump_can_write(const GArray *file_encaps, uint32_t required_comment_types)
Determine whether a capture file can be written with the specified options.
Definition file_access.c:1404
WS_DLL_PUBLIC const char * wtap_file_type_subtype_name(int file_type_subtype)
Get a short name for a file type/subtype.
Definition file_access.c:1644
WS_DLL_PUBLIC void wtap_setup_ft_specific_report_rec(wtap_rec *rec, int file_type_subtype, unsigned record_type)
Set up a wtap_rec for a file-type specific report.
Definition wtap.c:1817
WS_DLL_PUBLIC int wtap_get_num_encap_types(void)
Return the number of known encapsulation types.
Definition wtap.c:1369
WS_DLL_PUBLIC void wtap_rec_cleanup(wtap_rec *rec)
Clean up a wtap_rec structure.
Definition wtap.c:2127
WS_DLL_PUBLIC const char * wtap_tsprec_string(int tsprec)
Convert a timestamp precision constant to a string.
Definition wtap.c:1446
WS_DLL_PUBLIC unsigned int open_info_name_to_type(const char *name)
Convert an open_info short name to its numeric type.
Definition file_access.c:580
WS_DLL_PUBLIC wtap_block_t wtap_file_get_dsb(wtap *wth, unsigned dsb_num)
Gets existing decryption secrets block, not for new file.
Definition wtap.c:253
WS_DLL_PUBLIC bool wtap_dump_can_compress(int file_type_subtype)
Check if a file type/subtype supports compression.
Definition file_access.c:2100
WS_DLL_PUBLIC unsigned wtap_snapshot_length(wtap *wth)
Get the snapshot length for the capture file.
Definition wtap.c:110
WS_DLL_PUBLIC bool wtap_fdreopen(wtap *wth, const char *filename, int *err)
Reopen the random-access file descriptor for the current file.
Definition file_access.c:1031
WS_DLL_PUBLIC void wtap_rec_init(wtap_rec *rec, size_t space)
Initialize a wtap_rec structure.
Definition wtap.c:2079
WS_DLL_PUBLIC bool wtap_file_discard_decryption_secrets(wtap *wth)
Remove any decryption secret information from the per-file information; used if we're stripping decry...
Definition wtap.c:271
WS_DLL_PUBLIC void wtap_setup_ft_specific_event_rec(wtap_rec *rec, int file_type_subtype, unsigned record_type)
Set up a wtap_rec for a file-type specific event.
Definition wtap.c:1803
WS_DLL_PUBLIC void wtap_set_cb_new_ipv6(wtap *wth, wtap_new_ipv6_callback_t add_new_ipv6)
Set the callback for adding new IPv6 hostnames.
Definition wtap.c:1693
WS_DLL_PUBLIC const char * wtap_default_file_extension(int file_type_subtype)
Get the default file extension for a file type/subtype.
Definition file_access.c:2055
WS_DLL_PUBLIC int wtap_pcap_file_type_subtype(void)
Get the file type/subtype identifier for classic pcap (microsecond timestamps).
Definition file_access.c:1700
WS_DLL_PUBLIC void wtap_register_open_info(struct open_info *oi, const bool first_routine)
Register an open_info probe/open handler.
Definition file_access.c:462
WS_DLL_PUBLIC int wtap_buffer_append_epdu_end(Buffer *buf)
Close off a set of "exported PDUs" added to the buffer. For filetype readers to transform non-packeti...
Definition wtap.c:2345
WS_DLL_PUBLIC bool wtap_addrinfo_list_empty(const addrinfo_lists_t *addrinfo_lists)
Checks if the address information list is empty.
Definition file_access.c:2642
WS_DLL_PUBLIC wtapng_dpib_lookup_info_t * wtap_file_get_dpib_lookup_info(wtap *wth)
Gets the DPIB lookup information for the current file.
Definition wtap.c:210
WS_DLL_PUBLIC block_support_t wtap_file_type_subtype_supports_block(int file_type_subtype, wtap_block_type_t type)
Determine whether a capture file format supports a given block type.
Definition file_access.c:1742
WS_DLL_PUBLIC GArray * wtap_get_writable_file_types_subtypes(ft_sort_order sort_order)
Get a list of all writable file type/subtype values.
Definition file_access.c:1567
WS_DLL_PUBLIC const char * wtap_encap_name(int encap)
Get a short name for an encapsulation type.
Definition wtap.c:1389
WS_DLL_PUBLIC int wtap_register_encap_type(const char *description, const char *name)
Register a new packet encapsulation type.
Definition wtap.c:1375
WS_DLL_PUBLIC char * wtap_get_debug_if_descr(const wtap_block_t if_descr, const int indent, const char *line_end)
Gets a debug string of an interface description.
Definition wtap.c:406
#define PHDR_802_11BE_MAX_USERS
Definition wtap.h:804
WS_DLL_PUBLIC wtap_block_t wtap_file_get_nrb(wtap *wth)
Gets existing name resolution block, not for new file.
Definition wtap.c:545
WS_DLL_PUBLIC void wtap_set_cb_new_ipv4(wtap *wth, wtap_new_ipv4_callback_t add_new_ipv4)
Set the callback for adding new IPv4 hostnames.
Definition wtap.c:1673
WS_DLL_PUBLIC int wtap_name_to_file_type_subtype(const char *name)
Convert a file type/subtype name to its identifier.
Definition file_access.c:1668
WS_DLL_PUBLIC void wtap_sequential_close(wtap *wth)
Close the sequential-access side of the file.
Definition wtap.c:1575
void(* wtap_new_ipv4_callback_t)(const unsigned addr, const char *name, const bool static_entry)
Callback type for registering new IPv4 hostnames.
Definition wtap.h:2153
WS_DLL_PUBLIC option_support_t wtap_file_type_subtype_supports_option(int file_type_subtype, wtap_block_type_t type, unsigned opttype)
Determine whether a capture file format supports a specific option for a block.
Definition file_access.c:1777
WS_DLL_PUBLIC int wtap_name_to_encap(const char *short_name)
Convert a short encapsulation name to its WTAP_ENCAP_ value.
Definition wtap.c:1417
WS_DLL_PUBLIC bool wtap_seek_read(wtap *wth, int64_t seek_off, wtap_rec *rec, int *err, char **err_info)
Read the record at a specified offset in a capture file, filling in *phdr and *buf.
Definition wtap.c:2149
wtap_block_type_t
Currently supported blocks; these are not the pcapng block type values for them, they're identifiers ...
Definition wtap_opttypes.h:234
struct wtapng_dpib_lookup_info_s wtapng_dpib_lookup_info_t
struct wtapng_iface_descriptions_s wtapng_iface_descriptions_t