1 /* Edit capture files. We can delete packets, adjust timestamps, or
2 * simply convert from one format to another format.
6 * Originally written by Richard Sharpe.
7 * Improved by Guy Harris.
8 * Further improved by Richard Sharpe.
24 #ifdef HAVE_SYS_TIME_H
36 #include <process.h> /* getpid */
39 #ifdef NEED_STRPTIME_H
40 # include "strptime.h"
43 #include "svnversion.h"
46 * Some globals so we can pass things to various routines
56 #define ONE_MILLION 1000000
58 /* Weights of different errors we can introduce */
59 /* We should probably make these command-line arguments */
60 /* XXX - Should we add a bit-level error? */
61 #define ERR_WT_BIT 5 /* Flip a random bit */
62 #define ERR_WT_BYTE 5 /* Substitute a random byte */
63 #define ERR_WT_ALNUM 5 /* Substitute a random character in [A-Za-z0-9] */
64 #define ERR_WT_FMT 2 /* Substitute "%s" */
65 #define ERR_WT_AA 1 /* Fill the remainder of the buffer with 0xAA */
66 #define ERR_WT_TOTAL (ERR_WT_BIT + ERR_WT_BYTE + ERR_WT_ALNUM + ERR_WT_FMT + ERR_WT_AA)
68 #define ALNUM_CHARS "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"
69 #define ALNUM_LEN (sizeof(ALNUM_CHARS) - 1)
72 struct time_adjustment {
77 static struct select_item selectfrm[100];
78 static int max_selected = -1;
79 static int keep_em = 0;
80 static int out_file_type = WTAP_FILE_PCAP; /* default to "libpcap" */
81 static int out_frame_type = -2; /* Leave frame type alone */
82 static int verbose = 0; /* Not so verbose */
83 static struct time_adjustment time_adj = {{0, 0}, 0}; /* no adjustment */
84 static double err_prob = 0.0;
85 static time_t starttime = 0;
86 static time_t stoptime = 4294967295;
87 static gboolean check_startstop = FALSE;
89 /* Add a selection item, a simple parser for now */
91 static void add_selection(char *sel)
96 if (max_selected == (sizeof(selectfrm)/sizeof(struct select_item)) - 1)
99 printf("Add_Selected: %s\n", sel);
101 if ((locn = strchr(sel, '-')) == NULL) { /* No dash, so a single number? */
103 printf("Not inclusive ...");
106 selectfrm[max_selected].inclusive = 0;
107 selectfrm[max_selected].first = atoi(sel);
109 printf(" %i\n", selectfrm[max_selected].first);
114 printf("Inclusive ...");
118 selectfrm[max_selected].inclusive = 1;
119 selectfrm[max_selected].first = atoi(sel);
120 selectfrm[max_selected].second = atoi(next);
122 printf(" %i, %i\n", selectfrm[max_selected].first, selectfrm[max_selected].second);
129 /* Was the packet selected? */
131 static int selected(int recno)
135 for (i = 0; i<= max_selected; i++) {
137 if (selectfrm[i].inclusive) {
138 if (selectfrm[i].first <= recno && selectfrm[i].second >= recno)
142 if (recno == selectfrm[i].first)
151 /* is the packet in the selected timeframe */
152 static gboolean check_timestamp(wtap *wth) {
153 struct wtap_pkthdr* pkthdr = wtap_phdr(wth);
154 return ( (time_t) pkthdr->ts.secs >= starttime ) && ( (time_t) pkthdr->ts.secs <= stoptime );
158 set_time_adjustment(char *optarg)
167 /* skip leading whitespace */
168 while (*optarg == ' ' || *optarg == '\t') {
172 /* check for a negative adjustment */
173 if (*optarg == '-') {
174 time_adj.is_negative = 1;
178 /* collect whole number of seconds, if any */
179 if (*optarg == '.') { /* only fractional (i.e., .5 is ok) */
183 val = strtol(optarg, &frac, 10);
184 if (frac == NULL || frac == optarg || val == LONG_MIN || val == LONG_MAX) {
185 fprintf(stderr, "editcap: \"%s\" isn't a valid time adjustment\n",
189 if (val < 0) { /* implies '--' since we caught '-' above */
190 fprintf(stderr, "editcap: \"%s\" isn't a valid time adjustment\n",
195 time_adj.tv.tv_sec = val;
197 /* now collect the partial seconds, if any */
198 if (*frac != '\0') { /* chars left, so get fractional part */
199 val = strtol(&(frac[1]), &end, 10);
200 if (*frac != '.' || end == NULL || end == frac
201 || val < 0 || val > ONE_MILLION || val == LONG_MIN || val == LONG_MAX) {
202 fprintf(stderr, "editcap: \"%s\" isn't a valid time adjustment\n",
208 return; /* no fractional digits */
211 /* adjust fractional portion from fractional to numerator
212 * e.g., in "1.5" from 5 to 500000 since .5*10^6 = 500000 */
213 if (frac && end) { /* both are valid */
214 frac_digits = end - frac - 1; /* fractional digit count (remember '.') */
215 while(frac_digits < 6) { /* this is frac of 10^6 */
220 time_adj.tv.tv_usec = val;
223 static void usage(void)
225 fprintf(stderr, "Editcap %s"
230 fprintf(stderr, "Edit and/or translate the format of capture files.\n");
231 fprintf(stderr, "See http://www.ethereal.com for more information.\n");
232 fprintf(stderr, "\n");
233 fprintf(stderr, "Usage: editcap [options] ... <infile> <outfile> [ <packet#>[-<packet#>] ... ]\n");
234 fprintf(stderr, "\n");
235 fprintf(stderr, "A single packet or a range of packets can be selected.\n");
236 fprintf(stderr, "\n");
237 fprintf(stderr, "Packets:\n");
238 fprintf(stderr, " -C <choplen> chop each packet at the end by <choplen> bytes\n");
239 fprintf(stderr, " -E <error probability> set the probability (between 0.0 and 1.0 incl.)\n");
240 fprintf(stderr, " that a particular packet byte will be randomly changed\n");
241 fprintf(stderr, " -r keep the selected packets, default is to delete them\n");
242 fprintf(stderr, " -s <snaplen> truncate packets to max. <snaplen> bytes of data\n");
243 fprintf(stderr, " -t <time adjustment> adjust the timestamp of selected packets,\n");
244 fprintf(stderr, " <time adjustment> is in relative seconds (e.g. -0.5)\n");
245 fprintf(stderr, " -A <start time> don't output packets whose timestamp is before the\n");
246 fprintf(stderr, " given time (format as YYYY-MM-DD hh-mm-ss)\n");
247 fprintf(stderr, " -B <stop time> don't output packets whose timestamp is after the\n");
248 fprintf(stderr, " given time (format as YYYY-MM-DD hh-mm-ss)\n");
249 fprintf(stderr, "\n");
250 fprintf(stderr, "Output File(s):\n");
251 fprintf(stderr, " -c <packets per file> split the packet output to different files,\n");
252 fprintf(stderr, " with a maximum of <packets per file> each\n");
253 fprintf(stderr, " -F <capture type> set the output file type, default is libpcap\n");
254 fprintf(stderr, " an empty \"-F\" option will list the file types\n");
255 fprintf(stderr, " -T <encap type> set the output file encapsulation type,\n");
256 fprintf(stderr, " default is the same as the input file\n");
257 fprintf(stderr, " an empty \"-T\" option will list the encapsulation types\n");
258 fprintf(stderr, "\n");
259 fprintf(stderr, "Miscellaneous:\n");
260 fprintf(stderr, " -h display this help and exit\n");
261 fprintf(stderr, " -v verbose output\n");
262 fprintf(stderr, "\n");
265 static void list_capture_types(void) {
268 fprintf(stderr, "editcap: The available capture file types for \"F\":\n");
269 for (i = 0; i < WTAP_NUM_FILE_TYPES; i++) {
270 if (wtap_dump_can_open(i))
271 fprintf(stderr, " %s - %s\n",
272 wtap_file_type_short_string(i), wtap_file_type_string(i));
276 static void list_encap_types(void) {
280 fprintf(stderr, "editcap: The available encapsulation types for \"T\":\n");
281 for (i = 0; i < WTAP_NUM_ENCAP_TYPES; i++) {
282 string = wtap_encap_short_string(i);
284 fprintf(stderr, " %s - %s\n",
285 string, wtap_encap_string(i));
289 int main(int argc, char *argv[])
299 unsigned int snaplen = 0; /* No limit */
300 unsigned int choplen = 0; /* No chop */
304 struct wtap_pkthdr snap_phdr;
305 const struct wtap_pkthdr *phdr;
308 int split_packet_count = 0;
309 int written_count = 0;
312 /* Process the options first */
314 while ((opt = getopt(argc, argv, "A:B:c:C:E:F:hrs:t:T:v")) !=-1) {
319 err_prob = strtod(optarg, &p);
320 if (p == optarg || err_prob < 0.0 || err_prob > 1.0) {
321 fprintf(stderr, "editcap: probability \"%s\" must be between 0.0 and 1.0\n",
325 srand(time(NULL) + getpid());
329 out_file_type = wtap_short_string_to_file_type(optarg);
330 if (out_file_type < 0) {
331 fprintf(stderr, "editcap: \"%s\" isn't a valid capture file type\n\n",
333 list_capture_types();
339 split_packet_count = strtol(optarg, &p, 10);
340 if (p == optarg || *p != '\0') {
341 fprintf(stderr, "editcap: \"%s\" isn't a valid packet count\n",
345 if (split_packet_count <= 0) {
346 fprintf(stderr, "editcap: \"%d\" packet count must be larger than zero\n",
353 choplen = strtol(optarg, &p, 10);
354 if (p == optarg || *p != '\0') {
355 fprintf(stderr, "editcap: \"%s\" isn't a valid chop length\n",
361 case '?': /* Bad options if GNU getopt */
364 list_capture_types();
381 keep_em = !keep_em; /* Just invert */
385 snaplen = strtol(optarg, &p, 10);
386 if (p == optarg || *p != '\0') {
387 fprintf(stderr, "editcap: \"%s\" isn't a valid snapshot length\n",
394 set_time_adjustment(optarg);
398 out_frame_type = wtap_short_string_to_encap(optarg);
399 if (out_frame_type < 0) {
400 fprintf(stderr, "editcap: \"%s\" isn't a valid encapsulation type\n\n",
408 verbose = !verbose; /* Just invert */
415 if(!strptime(optarg,"%F %T",&timecode)) {
416 fprintf(stderr, "editcap: \"%s\" isn't a valid time format\n\n",
421 starttime = mktime(&timecode);
422 check_startstop = TRUE;
429 if(!strptime(optarg,"%F %T",&timecode)) {
430 fprintf(stderr, "editcap: \"%s\" isn't a valid time format\n\n",
434 check_startstop = TRUE;
435 stoptime = mktime(&timecode);
443 printf("Optind = %i, argc = %i\n", optind, argc);
446 if ((argc - optind) < 1) {
453 if (starttime > stoptime) {
454 fprintf(stderr, "editcap: start time is after the stop time\n");
458 wth = wtap_open_offline(argv[optind], &err, &err_info, FALSE);
461 fprintf(stderr, "editcap: Can't open %s: %s\n", argv[optind],
465 case WTAP_ERR_UNSUPPORTED:
466 case WTAP_ERR_UNSUPPORTED_ENCAP:
467 case WTAP_ERR_BAD_RECORD:
468 fprintf(stderr, "(%s)\n", err_info);
478 fprintf(stderr, "File %s is a %s capture file.\n", argv[optind],
479 wtap_file_type_string(wtap_file_type(wth)));
484 * Now, process the rest, if any ... we only write if there is an extra
488 if ((argc - optind) >= 2) {
490 if (out_frame_type == -2)
491 out_frame_type = wtap_file_encap(wth);
493 if (split_packet_count > 0) {
494 filename = (char *) malloc(strlen(argv[optind+1]) + 20);
498 sprintf(filename, "%s-%05d", argv[optind+1], 0);
500 filename = argv[optind+1];
503 pdh = wtap_dump_open(filename, out_file_type,
504 out_frame_type, wtap_snapshot_length(wth), FALSE /* compressed */, &err);
507 fprintf(stderr, "editcap: Can't open or create %s: %s\n", filename,
513 for (i = optind + 2; i < argc; i++)
514 add_selection(argv[i]);
516 while (wtap_read(wth, &err, &err_info, &data_offset)) {
518 if (split_packet_count > 0 && (written_count % split_packet_count == 0)) {
519 if (!wtap_dump_close(pdh, &err)) {
521 fprintf(stderr, "editcap: Error writing to %s: %s\n", filename,
526 sprintf(filename, "%s-%05d",argv[optind+1], count / split_packet_count);
529 fprintf(stderr, "Continuing writing in file %s\n", filename);
532 pdh = wtap_dump_open(filename, out_file_type,
533 out_frame_type, wtap_snapshot_length(wth), FALSE /* compressed */, &err);
536 fprintf(stderr, "editcap: Can't open or create %s: %s\n", filename,
543 if ( ((check_startstop && check_timestamp(wth)) || (!check_startstop && !check_timestamp(wth))) && ((!selected(count) && !keep_em) ||
544 (selected(count) && keep_em)) ) {
547 printf("Packet: %u\n", count);
549 /* We simply write it, perhaps after truncating it; we could do other
550 things, like modify it. */
552 phdr = wtap_phdr(wth);
554 if (choplen != 0 && phdr->caplen > choplen) {
556 snap_phdr.caplen -= choplen;
560 if (snaplen != 0 && phdr->caplen > snaplen) {
562 snap_phdr.caplen = snaplen;
566 /* assume that if the frame's tv_sec is 0, then
567 * the timestamp isn't supported */
568 if (phdr->ts.secs > 0 && time_adj.tv.tv_sec != 0) {
570 if (time_adj.is_negative)
571 snap_phdr.ts.secs -= time_adj.tv.tv_sec;
573 snap_phdr.ts.secs += time_adj.tv.tv_sec;
577 /* assume that if the frame's tv_sec is 0, then
578 * the timestamp isn't supported */
579 if (phdr->ts.secs > 0 && time_adj.tv.tv_usec != 0) {
581 if (time_adj.is_negative) { /* subtract */
582 if (snap_phdr.ts.nsecs/1000 < time_adj.tv.tv_usec) { /* borrow */
584 snap_phdr.ts.nsecs += ONE_MILLION * 1000;
586 snap_phdr.ts.nsecs -= time_adj.tv.tv_usec * 1000;
588 if (snap_phdr.ts.nsecs + time_adj.tv.tv_usec * 1000 > ONE_MILLION * 1000) {
591 snap_phdr.ts.nsecs += (time_adj.tv.tv_usec - ONE_MILLION) * 1000;
593 snap_phdr.ts.nsecs += time_adj.tv.tv_usec * 1000;
599 if (err_prob > 0.0) {
600 buf = wtap_buf_ptr(wth);
601 for (i = 0; i < (int) phdr->caplen; i++) {
602 if (rand() <= err_prob * RAND_MAX) {
603 err_type = rand() / (RAND_MAX / ERR_WT_TOTAL + 1);
605 if (err_type < ERR_WT_BIT) {
606 buf[i] ^= 1 << (rand() / (RAND_MAX / 8 + 1));
607 err_type = ERR_WT_TOTAL;
609 err_type -= ERR_WT_BYTE;
612 if (err_type < ERR_WT_BYTE) {
613 buf[i] = rand() / (RAND_MAX / 255 + 1);
614 err_type = ERR_WT_TOTAL;
616 err_type -= ERR_WT_BYTE;
619 if (err_type < ERR_WT_ALNUM) {
620 buf[i] = ALNUM_CHARS[rand() / (RAND_MAX / ALNUM_LEN + 1)];
621 err_type = ERR_WT_TOTAL;
623 err_type -= ERR_WT_ALNUM;
626 if (err_type < ERR_WT_FMT) {
627 if ((unsigned int)i < phdr->caplen - 2)
628 strcpy((char*) &buf[i], "%s");
629 err_type = ERR_WT_TOTAL;
631 err_type -= ERR_WT_FMT;
634 if (err_type < ERR_WT_AA) {
635 for (j = i; j < (int) phdr->caplen; j++) {
644 if (!wtap_dump(pdh, phdr, wtap_pseudoheader(wth), wtap_buf_ptr(wth),
647 fprintf(stderr, "editcap: Error writing to %s: %s\n",
648 filename, wtap_strerror(err));
662 /* Print a message noting that the read failed somewhere along the line. */
664 "editcap: An error occurred while reading \"%s\": %s.\n",
665 argv[optind], wtap_strerror(err));
668 case WTAP_ERR_UNSUPPORTED:
669 case WTAP_ERR_UNSUPPORTED_ENCAP:
670 case WTAP_ERR_BAD_RECORD:
671 fprintf(stderr, "(%s)\n", err_info);
676 if (!wtap_dump_close(pdh, &err)) {
678 fprintf(stderr, "editcap: Error writing to %s: %s\n", filename,