2 * Routines for D-Bus dissection
3 * Copyright 2012, Jakub Zawadzki <darkjames-ws@darkjames.pl>
7 * Protocol specification available at http://dbus.freedesktop.org/doc/dbus-specification.html
9 * Wireshark - Network traffic analyzer
10 * By Gerald Combs <gerald@wireshark.org>
11 * Copyright 1998 Gerald Combs
13 * This program is free software; you can redistribute it and/or
14 * modify it under the terms of the GNU General Public License
15 * as published by the Free Software Foundation; either version 2
16 * of the License, or (at your option) any later version.
18 * This program is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU General Public License for more details.
23 * You should have received a copy of the GNU General Public License
24 * along with this program; if not, write to the Free Software
25 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
30 #include <epan/packet.h>
31 #include <epan/strutil.h>
32 #include <epan/expert.h>
33 #include <epan/dissectors/packet-tcp.h>
35 void proto_register_dbus(void);
36 void proto_reg_handoff_dbus(void);
38 static gboolean dbus_desegment = TRUE;
40 static int hf_dbus_hdr = -1;
41 static int hf_dbus_hdr_endianness = -1;
42 static int hf_dbus_hdr_type = -1;
43 static int hf_dbus_hdr_flags = -1;
44 static int hf_dbus_hdr_version = -1;
45 static int hf_dbus_hdr_body_length = -1;
46 static int hf_dbus_hdr_serial = -1;
47 static int hf_dbus_hdr_fields_length = -1;
48 static int hf_dbus_hdr_field = -1;
49 static int hf_dbus_hdr_field_code = -1;
51 static int hf_dbus_value_bool = -1;
52 static int hf_dbus_value_int = -1;
53 static int hf_dbus_value_uint = -1;
54 static int hf_dbus_value_str = -1;
55 static int hf_dbus_value_double = -1;
57 static int hf_dbus_body = -1;
58 static int hf_dbus_type_signature = -1;
60 static int ett_dbus = -1;
61 static int ett_dbus_hdr = -1;
62 static int ett_dbus_body = -1;
63 static int ett_dbus_field = -1;
65 static int proto_dbus = -1;
67 #define DBUS_MESSAGE_TYPE_INVALID 0
68 #define DBUS_MESSAGE_TYPE_METHOD_CALL 1
69 #define DBUS_MESSAGE_TYPE_METHOD_RETURN 2
70 #define DBUS_MESSAGE_TYPE_ERROR 3
71 #define DBUS_MESSAGE_TYPE_SIGNAL 4
73 static const value_string message_type_vals[] = {
74 { DBUS_MESSAGE_TYPE_INVALID, "Invalid" },
75 { DBUS_MESSAGE_TYPE_METHOD_CALL, "Method call" },
76 { DBUS_MESSAGE_TYPE_METHOD_RETURN, "Method reply" },
77 { DBUS_MESSAGE_TYPE_ERROR, "Error reply" },
78 { DBUS_MESSAGE_TYPE_SIGNAL, "Signal emission" },
82 #define DBUS_HEADER_FIELD_INVALID 0
83 #define DBUS_HEADER_FIELD_PATH 1
84 #define DBUS_HEADER_FIELD_INTERFACE 2
85 #define DBUS_HEADER_FIELD_MEMBER 3
86 #define DBUS_HEADER_FIELD_ERROR_NAME 4
87 #define DBUS_HEADER_FIELD_REPLY_SERIAL 5
88 #define DBUS_HEADER_FIELD_DESTINATION 6
89 #define DBUS_HEADER_FIELD_SENDER 7
90 #define DBUS_HEADER_FIELD_SIGNATURE 8
91 #define DBUS_HEADER_FIELD_UNIX_FDS 9
93 static const value_string field_code_vals[] = {
94 { DBUS_HEADER_FIELD_INVALID, "INVALID" },
95 { DBUS_HEADER_FIELD_PATH, "PATH" },
96 { DBUS_HEADER_FIELD_INTERFACE, "INTERFACE" },
97 { DBUS_HEADER_FIELD_MEMBER, "MEMBER" },
98 { DBUS_HEADER_FIELD_ERROR_NAME, "ERROR_NAME" },
99 { DBUS_HEADER_FIELD_REPLY_SERIAL, "REPLY_SERIAL" },
100 { DBUS_HEADER_FIELD_DESTINATION, "DESTINATION" },
101 { DBUS_HEADER_FIELD_SENDER, "SENDER" },
102 { DBUS_HEADER_FIELD_SIGNATURE, "SIGNATURE" },
103 { DBUS_HEADER_FIELD_UNIX_FDS, "UNIX_FDS" },
110 guint16 (*get16)(tvbuff_t *, const gint);
111 guint32 (*get32)(tvbuff_t *, const gint);
112 gdouble (*getdouble)(tvbuff_t *, const gint);
117 const char *body_sig;
127 dbus_validate_object_path(const char *path)
139 while ((*path >= 'A' && *path <= 'Z') || (*path >= 'a' && *path <= 'z') || (*path >= '0' && *path <= '9') || *path == '_')
145 } while (*path == '/');
151 dbus_validate_signature(const char *sig _U_)
158 dissect_dbus_sig(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, char sig, dbus_val_t *ret)
160 const int org_offset = offset;
168 val = tvb_get_guint8(tvb, offset);
171 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "BYTE: %u", val);
176 case 'b': /* BOOLEAN */
180 val = dinfo->get32(tvb, offset);
183 ti = proto_tree_add_boolean_format(tree, hf_dbus_value_bool, tvb, org_offset, offset - org_offset, val, "BOOLEAN: %s", val ? "True" : "False");
184 if (val != 0 && val != 1) {
185 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid boolean value (must be 0 or 1 is: %u)", val);
192 case 'n': /* INT16 */
196 val = (gint16 )dinfo->get16(tvb, offset);
199 proto_tree_add_uint_format(tree, hf_dbus_value_int, tvb, org_offset, offset - org_offset, val, "INT16: %d", val);
204 case 'q': /* UINT16 */
208 val = dinfo->get16(tvb, offset);
211 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "UINT16: %u", val);
216 case 'i': /* INT32 */
220 val = (gint32) dinfo->get32(tvb, offset);
223 proto_tree_add_int_format(tree, hf_dbus_value_int, tvb, org_offset, offset - org_offset, val, "INT32: %d", val);
228 case 'u': /* UINT32 */
232 val = dinfo->get32(tvb, offset);
235 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "UINT32: %u", val);
240 case 'x': /* INT64 */
241 case 't': /* UINT64 */
244 case 'd': /* DOUBLE */
248 val = dinfo->getdouble(tvb, offset);
251 proto_tree_add_double_format(tree, hf_dbus_value_double, tvb, org_offset, offset - org_offset, val, "DOUBLE: %." STRINGIFY(DBL_DIG) "g", val);
256 case 's': /* STRING */
257 case 'o': /* OBJECT_PATH */
262 len = dinfo->get32(tvb, offset);
265 val = tvb_get_ephemeral_string(tvb, offset, len);
266 offset += (len + 1 /* NUL-byte */ + 3) & ~3;
269 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "STRING: %s", val);
270 if (!g_utf8_validate(val, -1, NULL)) {
271 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid string (not UTF-8)");
275 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "OBJECT_PATH: %s", val);
276 if (!dbus_validate_object_path(val)) {
277 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid object_path");
285 case 'g': /* SIGNATURE */
290 len = tvb_get_guint8(tvb, offset);
293 val = tvb_get_ephemeral_string(tvb, offset, len);
296 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "SIGNATURE: %s", val);
297 if (!dbus_validate_signature(val)) {
298 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid signature");
311 dissect_dbus_field_signature(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, int field_code)
313 const int org_offset = offset;
319 sig_len = tvb_get_guint8(tvb, offset);
322 /* sig_len = tvb_strsize(tvb, offset); */
324 sig = tvb_get_ephemeral_string(tvb, offset, sig_len);
325 offset += (sig_len + 1);
327 ti = proto_tree_add_string(tree, hf_dbus_type_signature, tvb, org_offset, offset - org_offset, sig);
328 if (!dbus_validate_signature(sig)) {
329 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid signature");
333 switch (field_code) {
334 case DBUS_HEADER_FIELD_REPLY_SERIAL:
335 if (!strcmp(sig, "u")) { /* UINT32 */
336 dbus_val_t serial_val;
338 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'u', &serial_val);
340 { /* XXX link with sending frame (serial_val.uint) */ }
345 case DBUS_HEADER_FIELD_DESTINATION:
346 case DBUS_HEADER_FIELD_SENDER:
347 if (!strcmp(sig, "s")) { /* STRING */
350 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 's', &addr_val);
352 SET_ADDRESS((field_code == DBUS_HEADER_FIELD_DESTINATION) ? &dinfo->pinfo->dst : &dinfo->pinfo->src,
353 AT_STRINGZ, (int)strlen(addr_val.str)+1, addr_val.str);
358 case DBUS_HEADER_FIELD_SIGNATURE:
359 if (!strcmp(sig, "g")) { /* SIGNATURE */
362 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'g', &sig_val);
364 dinfo->body_sig = sig_val.str;
373 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, *sig, &val);
382 dissect_dbus_hdr_fields(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
386 end_offset = offset + dinfo->fields_len;
388 while (offset < end_offset) {
389 proto_tree *field_tree;
394 ti = proto_tree_add_item(tree, hf_dbus_hdr_field, tvb, offset, 0, ENC_NA);
395 field_tree = proto_item_add_subtree(ti, ett_dbus_field);
397 field_code = tvb_get_guint8(tvb, offset);
398 proto_tree_add_item(field_tree, hf_dbus_hdr_field_code, tvb, offset, 1, dinfo->enc);
399 proto_item_append_text(ti, ": %s", val_to_str(field_code, field_code_vals, "Unknown: %d"));
402 offset = dissect_dbus_field_signature(tvb, dinfo, field_tree, offset, field_code);
406 offset = (offset + 7) & ~7; /* XXX ? */
408 proto_item_set_end(ti, tvb, offset);
411 /* XXX, verify if all required fields are preset */
413 if (offset >= end_offset) {
421 dissect_dbus_hdr(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
423 proto_tree *hdr_tree;
428 ti = proto_tree_add_item(tree, hf_dbus_hdr, tvb, offset, 0, ENC_NA);
429 hdr_tree = proto_item_add_subtree(ti, ett_dbus_hdr);
431 proto_tree_add_item(hdr_tree, hf_dbus_hdr_endianness, tvb, offset, 1, ENC_ASCII | ENC_NA);
434 type = tvb_get_guint8(tvb, offset);
435 col_add_str(dinfo->pinfo->cinfo, COL_INFO, val_to_str_const(type, message_type_vals, ""));
436 proto_tree_add_item(hdr_tree, hf_dbus_hdr_type, tvb, offset, 1, dinfo->enc);
439 proto_tree_add_item(hdr_tree, hf_dbus_hdr_flags, tvb, offset, 1, dinfo->enc);
442 proto_tree_add_item(hdr_tree, hf_dbus_hdr_version, tvb, offset, 1, dinfo->enc);
445 dinfo->body_len = dinfo->get32(tvb, offset);
446 proto_tree_add_item(hdr_tree, hf_dbus_hdr_body_length, tvb, offset, 4, dinfo->enc);
449 proto_tree_add_item(hdr_tree, hf_dbus_hdr_serial, tvb, offset, 4, dinfo->enc);
452 dinfo->fields_len = dinfo->get32(tvb, offset);
453 proto_tree_add_item(hdr_tree, hf_dbus_hdr_fields_length, tvb, offset, 4, dinfo->enc);
460 dissect_dbus_body(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
462 proto_tree *body_tree;
465 if (dinfo->body_len && dinfo->body_sig[0]) {
466 const char *sig = dinfo->body_sig;
468 ti = proto_tree_add_item(tree, hf_dbus_body, tvb, offset, 0, ENC_NA);
469 body_tree = proto_item_add_subtree(ti, ett_dbus_body);
474 offset = dissect_dbus_sig(tvb, dinfo, body_tree, offset, *sig, &val);
480 proto_item_set_end(ti, tvb, offset);
482 } else if (dinfo->body_len || dinfo->body_sig[0]) {
489 dissect_dbus(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_)
491 proto_tree *dbus_tree = NULL;
496 col_set_str(pinfo->cinfo, COL_PROTOCOL, "D-BUS");
497 col_clear(pinfo->cinfo, COL_INFO);
499 memset(&dinfo, 0, sizeof(dinfo));
501 switch (tvb_get_guint8(tvb, 0)) {
503 dinfo.enc = ENC_LITTLE_ENDIAN;
504 dinfo.get16 = tvb_get_letohs;
505 dinfo.get32 = tvb_get_letohl;
506 dinfo.getdouble = tvb_get_letohieee_double;
509 dinfo.enc = ENC_BIG_ENDIAN;
510 dinfo.get16 = tvb_get_ntohs;
511 dinfo.get32 = tvb_get_ntohl;
512 dinfo.getdouble = tvb_get_ntohieee_double;
514 default: /* same as BIG_ENDIAN */
515 /* XXX we should probably return 0; */
517 dinfo.get16 = tvb_get_ntohs;
518 dinfo.get32 = tvb_get_ntohl;
519 dinfo.getdouble = tvb_get_ntohieee_double;
523 proto_item *ti = proto_tree_add_item(tree, proto_dbus, tvb, 0, -1, ENC_NA);
524 dbus_tree = proto_item_add_subtree(ti, ett_dbus);
528 offset = dissect_dbus_hdr(tvb, &dinfo, dbus_tree, offset);
529 offset = dissect_dbus_hdr_fields(tvb, &dinfo, dbus_tree, offset);
530 /* header aligned to 8B */
531 offset = (offset + 7) & ~7;
536 offset = dissect_dbus_body(tvb, &dinfo, dbus_tree, offset);
541 #define DBUS_HEADER_LEN 16
544 get_dbus_message_len(packet_info *pinfo _U_, tvbuff_t *tvb, int offset)
546 guint32 (*get_guint32)(tvbuff_t *, const gint);
548 guint32 len_body, len_hdr;
550 switch (tvb_get_guint8(tvb, offset)) {
552 get_guint32 = tvb_get_letohl;
556 get_guint32 = tvb_get_ntohl;
560 len_hdr = DBUS_HEADER_LEN + get_guint32(tvb, offset + 12);
561 len_hdr = (len_hdr + 7) & ~7;
562 len_body = get_guint32(tvb, offset + 4);
564 return len_hdr + len_body;
568 dissect_dbus_pdu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree)
570 dissect_dbus(tvb, pinfo, tree, NULL);
574 dissect_dbus_tcp(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_)
576 tcp_dissect_pdus(tvb, pinfo, tree, dbus_desegment, DBUS_HEADER_LEN, get_dbus_message_len, dissect_dbus_pdu);
577 return tvb_length(tvb);
581 proto_register_dbus(void)
583 /* XXX, FT_NONE -> FT_BYTES? */
584 static hf_register_info hf[] = {
587 { "Header", "dbus.header", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
589 { &hf_dbus_hdr_endianness,
590 { "Endianness Flag", "dbus.endianness", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL }
593 { "Message Type", "dbus.type", FT_UINT8, BASE_DEC, VALS(message_type_vals), 0x00, NULL, HFILL }
595 { &hf_dbus_hdr_flags,
596 { "Message Flags", "dbus.flags", FT_UINT8, BASE_HEX, NULL, 0x00, NULL, HFILL }
598 { &hf_dbus_hdr_version,
599 { "Protocol Version", "dbus.version", FT_UINT8, BASE_DEC, NULL, 0x00, NULL, HFILL }
601 { &hf_dbus_hdr_body_length,
602 { "Message body Length", "dbus.length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
604 { &hf_dbus_hdr_serial,
605 { "Message Serial (cookie)", "dbus.serial", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
607 { &hf_dbus_hdr_fields_length,
608 { "Header fields Length", "dbus.fields_length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
611 { &hf_dbus_hdr_field,
612 { "Header Field", "dbus.field", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
614 { &hf_dbus_hdr_field_code,
615 { "Field code", "dbus.field.code", FT_UINT8, BASE_DEC, VALS(field_code_vals), 0x00, NULL, HFILL }
618 { &hf_dbus_type_signature,
619 { "Type signature", "dbus.type_signature", FT_STRINGZ, BASE_NONE, NULL, 0x00, NULL, HFILL }
623 { "Body", "dbus.body", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
627 { &hf_dbus_value_bool,
628 { "Value", "dbus.value.bool", FT_BOOLEAN, BASE_NONE, NULL, 0x00, NULL, HFILL }
630 { &hf_dbus_value_int,
631 { "Value", "dbus.value.int", FT_INT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
633 { &hf_dbus_value_uint,
634 { "Value", "dbus.value.uint", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
636 { &hf_dbus_value_str,
637 { "Value", "dbus.value.str", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL }
639 { &hf_dbus_value_double,
640 { "Value", "dbus.value.double", FT_DOUBLE, BASE_NONE, NULL, 0x00, NULL, HFILL }
644 static gint *ett[] = {
651 proto_dbus = proto_register_protocol("D-Bus", "D-BUS", "dbus");
653 proto_register_field_array(proto_dbus, hf, array_length(hf));
654 proto_register_subtree_array(ett, array_length(ett));
658 proto_reg_handoff_dbus(void)
660 dissector_handle_t dbus_handle = new_create_dissector_handle(dissect_dbus, proto_dbus);
661 dissector_handle_t dbus_handle_tcp = new_create_dissector_handle(dissect_dbus_tcp, proto_dbus);
663 dissector_add_uint("wtap_encap", WTAP_ENCAP_DBUS, dbus_handle);
664 dissector_add_handle("tcp.port", dbus_handle_tcp);