2 * Routines for D-Bus dissection
3 * Copyright 2012, Jakub Zawadzki <darkjames-ws@darkjames.pl>
5 * Protocol specification available at http://dbus.freedesktop.org/doc/dbus-specification.html
7 * Wireshark - Network traffic analyzer
8 * By Gerald Combs <gerald@wireshark.org>
9 * Copyright 1998 Gerald Combs
11 * This program is free software; you can redistribute it and/or
12 * modify it under the terms of the GNU General Public License
13 * as published by the Free Software Foundation; either version 2
14 * of the License, or (at your option) any later version.
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
21 * You should have received a copy of the GNU General Public License
22 * along with this program; if not, write to the Free Software
23 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
26 #define NEW_PROTO_TREE_API
30 #include <epan/packet.h>
31 #include <wiretap/wtap.h>
32 #include <epan/expert.h>
33 #include <epan/dissectors/packet-tcp.h>
35 void proto_register_dbus(void);
36 void proto_reg_handoff_dbus(void);
38 static gboolean dbus_desegment = TRUE;
40 static dissector_handle_t dbus_handle;
41 static dissector_handle_t dbus_handle_tcp;
43 #define DBUS_MESSAGE_TYPE_INVALID 0
44 #define DBUS_MESSAGE_TYPE_METHOD_CALL 1
45 #define DBUS_MESSAGE_TYPE_METHOD_RETURN 2
46 #define DBUS_MESSAGE_TYPE_ERROR 3
47 #define DBUS_MESSAGE_TYPE_SIGNAL 4
49 static const value_string message_type_vals[] = {
50 { DBUS_MESSAGE_TYPE_INVALID, "Invalid" },
51 { DBUS_MESSAGE_TYPE_METHOD_CALL, "Method call" },
52 { DBUS_MESSAGE_TYPE_METHOD_RETURN, "Method reply" },
53 { DBUS_MESSAGE_TYPE_ERROR, "Error reply" },
54 { DBUS_MESSAGE_TYPE_SIGNAL, "Signal emission" },
58 #define DBUS_HEADER_FIELD_INVALID 0
59 #define DBUS_HEADER_FIELD_PATH 1
60 #define DBUS_HEADER_FIELD_INTERFACE 2
61 #define DBUS_HEADER_FIELD_MEMBER 3
62 #define DBUS_HEADER_FIELD_ERROR_NAME 4
63 #define DBUS_HEADER_FIELD_REPLY_SERIAL 5
64 #define DBUS_HEADER_FIELD_DESTINATION 6
65 #define DBUS_HEADER_FIELD_SENDER 7
66 #define DBUS_HEADER_FIELD_SIGNATURE 8
67 #define DBUS_HEADER_FIELD_UNIX_FDS 9
69 static const value_string field_code_vals[] = {
70 { DBUS_HEADER_FIELD_INVALID, "INVALID" },
71 { DBUS_HEADER_FIELD_PATH, "PATH" },
72 { DBUS_HEADER_FIELD_INTERFACE, "INTERFACE" },
73 { DBUS_HEADER_FIELD_MEMBER, "MEMBER" },
74 { DBUS_HEADER_FIELD_ERROR_NAME, "ERROR_NAME" },
75 { DBUS_HEADER_FIELD_REPLY_SERIAL, "REPLY_SERIAL" },
76 { DBUS_HEADER_FIELD_DESTINATION, "DESTINATION" },
77 { DBUS_HEADER_FIELD_SENDER, "SENDER" },
78 { DBUS_HEADER_FIELD_SIGNATURE, "SIGNATURE" },
79 { DBUS_HEADER_FIELD_UNIX_FDS, "UNIX_FDS" },
83 static header_field_info *hfi_dbus = NULL;
85 #define DBUS_HFI_INIT HFI_INIT(proto_dbus)
87 /* XXX, FT_NONE -> FT_BYTES? */
90 static header_field_info hfi_dbus_hdr DBUS_HFI_INIT =
91 { "Header", "dbus.header", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL };
93 static header_field_info hfi_dbus_hdr_endianness DBUS_HFI_INIT =
94 { "Endianness Flag", "dbus.endianness", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL };
96 static header_field_info hfi_dbus_hdr_type DBUS_HFI_INIT =
97 { "Message Type", "dbus.type", FT_UINT8, BASE_DEC, VALS(message_type_vals), 0x00, NULL, HFILL };
99 static header_field_info hfi_dbus_hdr_flags DBUS_HFI_INIT =
100 { "Message Flags", "dbus.flags", FT_UINT8, BASE_HEX, NULL, 0x00, NULL, HFILL };
102 static header_field_info hfi_dbus_hdr_version DBUS_HFI_INIT =
103 { "Protocol Version", "dbus.version", FT_UINT8, BASE_DEC, NULL, 0x00, NULL, HFILL };
105 static header_field_info hfi_dbus_hdr_body_length DBUS_HFI_INIT =
106 { "Message body Length", "dbus.length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL };
108 static header_field_info hfi_dbus_hdr_serial DBUS_HFI_INIT =
109 { "Message Serial (cookie)", "dbus.serial", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL };
111 static header_field_info hfi_dbus_hdr_fields_length DBUS_HFI_INIT =
112 { "Header fields Length", "dbus.fields_length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL };
115 static header_field_info hfi_dbus_hdr_field DBUS_HFI_INIT =
116 { "Header Field", "dbus.field", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL };
118 static header_field_info hfi_dbus_hdr_field_code DBUS_HFI_INIT =
119 { "Field code", "dbus.field.code", FT_UINT8, BASE_DEC, VALS(field_code_vals), 0x00, NULL, HFILL };
121 static header_field_info hfi_dbus_type_signature DBUS_HFI_INIT =
122 { "Type signature", "dbus.type_signature", FT_STRINGZ, BASE_NONE, NULL, 0x00, NULL, HFILL };
124 static header_field_info hfi_dbus_body DBUS_HFI_INIT =
125 { "Body", "dbus.body", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL };
128 static header_field_info hfi_dbus_value_bool DBUS_HFI_INIT =
129 { "Value", "dbus.value.bool", FT_BOOLEAN, BASE_NONE, NULL, 0x00, NULL, HFILL };
131 static header_field_info hfi_dbus_value_int DBUS_HFI_INIT =
132 { "Value", "dbus.value.int", FT_INT32, BASE_DEC, NULL, 0x00, NULL, HFILL };
134 static header_field_info hfi_dbus_value_uint DBUS_HFI_INIT =
135 { "Value", "dbus.value.uint", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL };
137 static header_field_info hfi_dbus_value_str DBUS_HFI_INIT =
138 { "Value", "dbus.value.str", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL };
140 static header_field_info hfi_dbus_value_double DBUS_HFI_INIT =
141 { "Value", "dbus.value.double", FT_DOUBLE, BASE_NONE, NULL, 0x00, NULL, HFILL };
144 static int ett_dbus = -1;
145 static int ett_dbus_hdr = -1;
146 static int ett_dbus_body = -1;
147 static int ett_dbus_field = -1;
149 static expert_field ei_dbus_value_bool_invalid = EI_INIT;
150 static expert_field ei_dbus_value_str_invalid = EI_INIT;
151 static expert_field ei_dbus_invalid_object_path = EI_INIT;
152 static expert_field ei_dbus_invalid_signature = EI_INIT;
157 guint16 (*get16)(tvbuff_t *, const gint);
158 guint32 (*get32)(tvbuff_t *, const gint);
159 gdouble (*getdouble)(tvbuff_t *, const gint);
164 const char *body_sig;
174 dbus_validate_object_path(const char *path)
186 while ((*path >= 'A' && *path <= 'Z') || (*path >= 'a' && *path <= 'z') || (*path >= '0' && *path <= '9') || *path == '_')
192 } while (*path == '/');
198 dbus_validate_signature(const char *sig _U_)
205 dissect_dbus_sig(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, char sig, dbus_val_t *ret)
207 const int org_offset = offset;
215 val = tvb_get_guint8(tvb, offset);
218 proto_tree_add_uint_format(tree, hfi_dbus_value_uint.id, tvb, org_offset, offset - org_offset, val, "BYTE: %u", val);
223 case 'b': /* BOOLEAN */
227 val = dinfo->get32(tvb, offset);
230 ti = proto_tree_add_boolean_format(tree, hfi_dbus_value_bool.id, tvb, org_offset, offset - org_offset, val, "BOOLEAN: %s", val ? "True" : "False");
231 if (val != 0 && val != 1) {
232 expert_add_info_format(dinfo->pinfo, ti, &ei_dbus_value_bool_invalid, "Invalid boolean value (must be 0 or 1 is: %u)", val);
239 case 'n': /* INT16 */
243 val = (gint16 )dinfo->get16(tvb, offset);
246 proto_tree_add_uint_format(tree, hfi_dbus_value_int.id, tvb, org_offset, offset - org_offset, val, "INT16: %d", val);
251 case 'q': /* UINT16 */
255 val = dinfo->get16(tvb, offset);
258 proto_tree_add_uint_format(tree, hfi_dbus_value_uint.id, tvb, org_offset, offset - org_offset, val, "UINT16: %u", val);
263 case 'i': /* INT32 */
267 val = (gint32) dinfo->get32(tvb, offset);
270 proto_tree_add_int_format(tree, hfi_dbus_value_int.id, tvb, org_offset, offset - org_offset, val, "INT32: %d", val);
275 case 'u': /* UINT32 */
279 val = dinfo->get32(tvb, offset);
282 proto_tree_add_uint_format(tree, hfi_dbus_value_uint.id, tvb, org_offset, offset - org_offset, val, "UINT32: %u", val);
287 case 'x': /* INT64 */
288 case 't': /* UINT64 */
291 case 'd': /* DOUBLE */
295 val = dinfo->getdouble(tvb, offset);
298 proto_tree_add_double_format(tree, hfi_dbus_value_double.id, tvb, org_offset, offset - org_offset, val, "DOUBLE: %." G_STRINGIFY(DBL_DIG) "g", val);
303 case 's': /* STRING */
304 case 'o': /* OBJECT_PATH */
309 len = dinfo->get32(tvb, offset);
312 val = tvb_get_string_enc(wmem_packet_scope(), tvb, offset, len, ENC_ASCII);
313 offset += (len + 1 /* NUL-byte */ + 3) & ~3;
316 ti = proto_tree_add_string_format(tree, hfi_dbus_value_str.id, tvb, org_offset, offset - org_offset, val, "STRING: %s", val);
317 if (!g_utf8_validate(val, -1, NULL)) {
318 expert_add_info(dinfo->pinfo, ti, &ei_dbus_value_str_invalid);
322 ti = proto_tree_add_string_format(tree, hfi_dbus_value_str.id, tvb, org_offset, offset - org_offset, val, "OBJECT_PATH: %s", val);
323 if (!dbus_validate_object_path(val)) {
324 expert_add_info(dinfo->pinfo, ti, &ei_dbus_invalid_object_path);
332 case 'g': /* SIGNATURE */
337 len = tvb_get_guint8(tvb, offset);
340 val = tvb_get_string_enc(wmem_packet_scope(), tvb, offset, len, ENC_ASCII);
343 ti = proto_tree_add_string_format(tree, hfi_dbus_value_str.id, tvb, org_offset, offset - org_offset, val, "SIGNATURE: %s", val);
344 if (!dbus_validate_signature(val)) {
345 expert_add_info(dinfo->pinfo, ti, &ei_dbus_invalid_signature);
358 dissect_dbus_field_signature(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, int field_code)
360 const int org_offset = offset;
366 sig_len = tvb_get_guint8(tvb, offset);
369 /* sig_len = tvb_strsize(tvb, offset); */
371 sig = tvb_get_string_enc(wmem_packet_scope(), tvb, offset, sig_len, ENC_ASCII);
372 offset += (sig_len + 1);
374 ti = proto_tree_add_string(tree, &hfi_dbus_type_signature, tvb, org_offset, offset - org_offset, sig);
375 if (!dbus_validate_signature(sig)) {
376 expert_add_info(dinfo->pinfo, ti, &ei_dbus_invalid_signature);
380 switch (field_code) {
381 case DBUS_HEADER_FIELD_REPLY_SERIAL:
382 if (!strcmp(sig, "u")) { /* UINT32 */
383 dbus_val_t serial_val;
385 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'u', &serial_val);
387 { /* XXX link with sending frame (serial_val.uint) */ }
392 case DBUS_HEADER_FIELD_DESTINATION:
393 case DBUS_HEADER_FIELD_SENDER:
394 if (!strcmp(sig, "s")) { /* STRING */
397 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 's', &addr_val);
399 SET_ADDRESS((field_code == DBUS_HEADER_FIELD_DESTINATION) ? &dinfo->pinfo->dst : &dinfo->pinfo->src,
400 AT_STRINGZ, (int)strlen(addr_val.str)+1, addr_val.str);
405 case DBUS_HEADER_FIELD_SIGNATURE:
406 if (!strcmp(sig, "g")) { /* SIGNATURE */
409 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'g', &sig_val);
411 dinfo->body_sig = sig_val.str;
420 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, *sig, &val);
429 dissect_dbus_hdr_fields(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
433 end_offset = offset + dinfo->fields_len;
435 while (offset < end_offset) {
436 proto_tree *field_tree;
441 ti = proto_tree_add_item(tree, &hfi_dbus_hdr_field, tvb, offset, 0, ENC_NA);
442 field_tree = proto_item_add_subtree(ti, ett_dbus_field);
444 field_code = tvb_get_guint8(tvb, offset);
445 proto_tree_add_item(field_tree, &hfi_dbus_hdr_field_code, tvb, offset, 1, dinfo->enc);
446 proto_item_append_text(ti, ": %s", val_to_str(field_code, field_code_vals, "Unknown: %d"));
449 offset = dissect_dbus_field_signature(tvb, dinfo, field_tree, offset, field_code);
453 offset = (offset + 7) & ~7; /* XXX ? */
455 proto_item_set_end(ti, tvb, offset);
458 /* XXX, verify if all required fields are preset */
460 if (offset >= end_offset) {
468 dissect_dbus_hdr(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
470 proto_tree *hdr_tree;
475 ti = proto_tree_add_item(tree, &hfi_dbus_hdr, tvb, offset, 0, ENC_NA);
476 hdr_tree = proto_item_add_subtree(ti, ett_dbus_hdr);
478 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_endianness, tvb, offset, 1, ENC_ASCII | ENC_NA);
481 type = tvb_get_guint8(tvb, offset);
482 col_set_str(dinfo->pinfo->cinfo, COL_INFO, val_to_str_const(type, message_type_vals, ""));
483 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_type, tvb, offset, 1, dinfo->enc);
486 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_flags, tvb, offset, 1, dinfo->enc);
489 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_version, tvb, offset, 1, dinfo->enc);
492 dinfo->body_len = dinfo->get32(tvb, offset);
493 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_body_length, tvb, offset, 4, dinfo->enc);
496 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_serial, tvb, offset, 4, dinfo->enc);
499 dinfo->fields_len = dinfo->get32(tvb, offset);
500 proto_tree_add_item(hdr_tree, &hfi_dbus_hdr_fields_length, tvb, offset, 4, dinfo->enc);
507 dissect_dbus_body(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
509 proto_tree *body_tree;
512 if (dinfo->body_len && dinfo->body_sig[0]) {
513 const char *sig = dinfo->body_sig;
515 ti = proto_tree_add_item(tree, &hfi_dbus_body, tvb, offset, 0, ENC_NA);
516 body_tree = proto_item_add_subtree(ti, ett_dbus_body);
521 offset = dissect_dbus_sig(tvb, dinfo, body_tree, offset, *sig, &val);
527 proto_item_set_end(ti, tvb, offset);
529 } else if (dinfo->body_len || dinfo->body_sig[0]) {
536 dissect_dbus(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data _U_)
538 proto_tree *dbus_tree = NULL;
543 col_set_str(pinfo->cinfo, COL_PROTOCOL, "D-BUS");
544 col_clear(pinfo->cinfo, COL_INFO);
546 memset(&dinfo, 0, sizeof(dinfo));
548 switch (tvb_get_guint8(tvb, 0)) {
550 dinfo.enc = ENC_LITTLE_ENDIAN;
551 dinfo.get16 = tvb_get_letohs;
552 dinfo.get32 = tvb_get_letohl;
553 dinfo.getdouble = tvb_get_letohieee_double;
556 dinfo.enc = ENC_BIG_ENDIAN;
557 dinfo.get16 = tvb_get_ntohs;
558 dinfo.get32 = tvb_get_ntohl;
559 dinfo.getdouble = tvb_get_ntohieee_double;
561 default: /* same as BIG_ENDIAN */
562 /* XXX we should probably return 0; */
564 dinfo.get16 = tvb_get_ntohs;
565 dinfo.get32 = tvb_get_ntohl;
566 dinfo.getdouble = tvb_get_ntohieee_double;
570 proto_item *ti = proto_tree_add_item(tree, hfi_dbus, tvb, 0, -1, ENC_NA);
571 dbus_tree = proto_item_add_subtree(ti, ett_dbus);
575 offset = dissect_dbus_hdr(tvb, &dinfo, dbus_tree, offset);
576 offset = dissect_dbus_hdr_fields(tvb, &dinfo, dbus_tree, offset);
577 /* header aligned to 8B */
578 offset = (offset + 7) & ~7;
583 offset = dissect_dbus_body(tvb, &dinfo, dbus_tree, offset);
588 #define DBUS_HEADER_LEN 16
591 get_dbus_message_len(packet_info *pinfo _U_, tvbuff_t *tvb, int offset)
593 guint32 (*get_guint32)(tvbuff_t *, const gint);
595 guint32 len_body, len_hdr;
597 switch (tvb_get_guint8(tvb, offset)) {
599 get_guint32 = tvb_get_letohl;
603 get_guint32 = tvb_get_ntohl;
607 len_hdr = DBUS_HEADER_LEN + get_guint32(tvb, offset + 12);
608 len_hdr = (len_hdr + 7) & ~7;
609 len_body = get_guint32(tvb, offset + 4);
611 return len_hdr + len_body;
615 dissect_dbus_pdu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data)
617 return dissect_dbus(tvb, pinfo, tree, data);
621 dissect_dbus_tcp(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree, void *data)
623 tcp_dissect_pdus(tvb, pinfo, tree, dbus_desegment, DBUS_HEADER_LEN, get_dbus_message_len, dissect_dbus_pdu, data);
624 return tvb_length(tvb);
628 proto_register_dbus(void)
630 #ifndef HAVE_HFI_SECTION_INIT
631 static header_field_info *hfi[] = {
634 &hfi_dbus_hdr_endianness,
637 &hfi_dbus_hdr_version,
638 &hfi_dbus_hdr_body_length,
639 &hfi_dbus_hdr_serial,
640 &hfi_dbus_hdr_fields_length,
643 &hfi_dbus_hdr_field_code,
644 &hfi_dbus_type_signature,
647 &hfi_dbus_value_bool,
649 &hfi_dbus_value_uint,
651 &hfi_dbus_value_double,
655 static gint *ett[] = {
662 static ei_register_info ei[] = {
663 { &ei_dbus_value_bool_invalid, { "dbus.value.bool.invalid", PI_PROTOCOL, PI_WARN, "Invalid boolean value", EXPFILL }},
664 { &ei_dbus_value_str_invalid, { "dbus.value.str.invalid", PI_PROTOCOL, PI_WARN, "Invalid string (not UTF-8)", EXPFILL }},
665 { &ei_dbus_invalid_object_path, { "dbus.invalid_object_path", PI_PROTOCOL, PI_WARN, "Invalid object_path", EXPFILL }},
666 { &ei_dbus_invalid_signature, { "dbus.invalid_signature", PI_PROTOCOL, PI_WARN, "Invalid signature", EXPFILL }},
669 expert_module_t *expert_dbus;
673 proto_dbus = proto_register_protocol("D-Bus", "D-BUS", "dbus");
674 hfi_dbus = proto_registrar_get_nth(proto_dbus);
676 proto_register_fields(proto_dbus, hfi, array_length(hfi));
677 proto_register_subtree_array(ett, array_length(ett));
678 expert_dbus = expert_register_protocol(proto_dbus);
679 expert_register_field_array(expert_dbus, ei, array_length(ei));
681 dbus_handle = new_create_dissector_handle(dissect_dbus, proto_dbus);
682 dbus_handle_tcp = new_create_dissector_handle(dissect_dbus_tcp, proto_dbus);
686 proto_reg_handoff_dbus(void)
688 dissector_add_uint("wtap_encap", WTAP_ENCAP_DBUS, dbus_handle);
689 dissector_add_for_decode_as("tcp.port", dbus_handle_tcp);