2 * Routines for D-Bus dissection
3 * Copyright 2012, Jakub Zawadzki <darkjames-ws@darkjames.pl>
7 * Protocol specification available at http://dbus.freedesktop.org/doc/dbus-specification.html
9 * Wireshark - Network traffic analyzer
10 * By Gerald Combs <gerald@wireshark.org>
11 * Copyright 1998 Gerald Combs
13 * This program is free software; you can redistribute it and/or
14 * modify it under the terms of the GNU General Public License
15 * as published by the Free Software Foundation; either version 2
16 * of the License, or (at your option) any later version.
18 * This program is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU General Public License for more details.
23 * You should have received a copy of the GNU General Public License
24 * along with this program; if not, write to the Free Software
25 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
32 #include <epan/packet.h>
33 #include <epan/prefs.h>
34 #include <epan/tvbuff.h>
35 #include <epan/strutil.h>
36 #include <epan/expert.h>
37 #include <epan/dissectors/packet-tcp.h>
39 static gboolean dbus_desegment = TRUE;
41 static int hf_dbus_hdr = -1;
42 static int hf_dbus_hdr_endianess = -1;
43 static int hf_dbus_hdr_type = -1;
44 static int hf_dbus_hdr_flags = -1;
45 static int hf_dbus_hdr_version = -1;
46 static int hf_dbus_hdr_body_length = -1;
47 static int hf_dbus_hdr_serial = -1;
48 static int hf_dbus_hdr_fields_length = -1;
49 static int hf_dbus_hdr_field = -1;
50 static int hf_dbus_hdr_field_code = -1;
52 static int hf_dbus_value_bool = -1;
53 static int hf_dbus_value_int = -1;
54 static int hf_dbus_value_uint = -1;
55 static int hf_dbus_value_str = -1;
56 static int hf_dbus_value_double = -1;
58 static int hf_dbus_body = -1;
59 static int hf_dbus_type_signature = -1;
61 static int ett_dbus = -1;
62 static int ett_dbus_hdr = -1;
63 static int ett_dbus_body = -1;
64 static int ett_dbus_field = -1;
66 static int proto_dbus = -1;
68 #define DBUS_MESSAGE_TYPE_INVALID 0
69 #define DBUS_MESSAGE_TYPE_METHOD_CALL 1
70 #define DBUS_MESSAGE_TYPE_METHOD_RETURN 2
71 #define DBUS_MESSAGE_TYPE_ERROR 3
72 #define DBUS_MESSAGE_TYPE_SIGNAL 4
74 static const value_string message_type_vals[] = {
75 { DBUS_MESSAGE_TYPE_INVALID, "Invalid" },
76 { DBUS_MESSAGE_TYPE_METHOD_CALL, "Method call" },
77 { DBUS_MESSAGE_TYPE_METHOD_RETURN, "Method reply" },
78 { DBUS_MESSAGE_TYPE_ERROR, "Error reply" },
79 { DBUS_MESSAGE_TYPE_SIGNAL, "Signal emission" },
83 #define DBUS_HEADER_FIELD_INVALID 0
84 #define DBUS_HEADER_FIELD_PATH 1
85 #define DBUS_HEADER_FIELD_INTERFACE 2
86 #define DBUS_HEADER_FIELD_MEMBER 3
87 #define DBUS_HEADER_FIELD_ERROR_NAME 4
88 #define DBUS_HEADER_FIELD_REPLY_SERIAL 5
89 #define DBUS_HEADER_FIELD_DESTINATION 6
90 #define DBUS_HEADER_FIELD_SENDER 7
91 #define DBUS_HEADER_FIELD_SIGNATURE 8
92 #define DBUS_HEADER_FIELD_UNIX_FDS 9
94 static const value_string field_code_vals[] = {
95 { DBUS_HEADER_FIELD_INVALID, "INVALID" },
96 { DBUS_HEADER_FIELD_PATH, "PATH" },
97 { DBUS_HEADER_FIELD_INTERFACE, "INTERFACE" },
98 { DBUS_HEADER_FIELD_MEMBER, "MEMBER" },
99 { DBUS_HEADER_FIELD_ERROR_NAME, "ERROR_NAME" },
100 { DBUS_HEADER_FIELD_REPLY_SERIAL, "REPLY_SERIAL" },
101 { DBUS_HEADER_FIELD_DESTINATION, "DESTINATION" },
102 { DBUS_HEADER_FIELD_SENDER, "SENDER" },
103 { DBUS_HEADER_FIELD_SIGNATURE, "SIGNATURE" },
104 { DBUS_HEADER_FIELD_UNIX_FDS, "UNIX_FDS" },
111 guint16 (*get16)(tvbuff_t *, const gint);
112 guint32 (*get32)(tvbuff_t *, const gint);
113 gdouble (*getdouble)(tvbuff_t *, const gint);
128 dbus_validate_object_path(const char *path)
140 while ((*path >= 'A' && *path <= 'Z') || (*path >= 'a' && *path <= 'z') || (*path >= '0' && *path <= '9') || *path == '_')
146 } while (*path == '/');
152 dbus_validate_signature(const char *sig _U_)
159 dissect_dbus_sig(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, char sig, dbus_val_t *ret)
161 const int org_offset = offset;
169 val = tvb_get_guint8(tvb, offset);
172 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "BYTE: %u", val);
177 case 'b': /* BOOLEAN */
181 val = dinfo->get32(tvb, offset);
184 ti = proto_tree_add_boolean_format(tree, hf_dbus_value_bool, tvb, org_offset, offset - org_offset, val, "BOOLEAN: %s", val ? "True" : "False");
185 if (val != 0 && val != 1) {
186 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid boolean value (must be 0 or 1 is: %u)", val);
193 case 'n': /* INT16 */
197 val = (gint16 )dinfo->get16(tvb, offset);
200 proto_tree_add_uint_format(tree, hf_dbus_value_int, tvb, org_offset, offset - org_offset, val, "INT16: %d", val);
205 case 'q': /* UINT16 */
209 val = dinfo->get16(tvb, offset);
212 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "UINT16: %u", val);
217 case 'i': /* INT32 */
221 val = (gint32) dinfo->get32(tvb, offset);
224 proto_tree_add_int_format(tree, hf_dbus_value_int, tvb, org_offset, offset - org_offset, val, "INT32: %d", val);
229 case 'u': /* UINT32 */
233 val = dinfo->get32(tvb, offset);
236 proto_tree_add_uint_format(tree, hf_dbus_value_uint, tvb, org_offset, offset - org_offset, val, "UINT32: %u", val);
241 case 'x': /* INT64 */
242 case 't': /* UINT64 */
245 case 'd': /* DOUBLE */
249 val = dinfo->getdouble(tvb, offset);
252 proto_tree_add_double_format(tree, hf_dbus_value_double, tvb, org_offset, offset - org_offset, val, "DOUBLE: %." STRINGIFY(DBL_DIG) "g", val);
257 case 's': /* STRING */
258 case 'o': /* OBJECT_PATH */
263 len = dinfo->get32(tvb, offset);
266 val = tvb_get_ephemeral_string(tvb, offset, len);
267 offset += (len + 1 /* NUL-byte */ + 3) & ~3;
270 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "STRING: %s", val);
271 if (!g_utf8_validate(val, -1, NULL)) {
272 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid string (not UTF-8)");
276 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "OBJECT_PATH: %s", val);
277 if (!dbus_validate_object_path(val)) {
278 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid object_path");
286 case 'g': /* SIGNATURE */
291 len = tvb_get_guint8(tvb, offset);
294 val = tvb_get_ephemeral_string(tvb, offset, len);
297 ti = proto_tree_add_string_format(tree, hf_dbus_value_str, tvb, org_offset, offset - org_offset, val, "SIGNATURE: %s", val);
298 if (!dbus_validate_signature(val)) {
299 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid signature");
312 dissect_dbus_field_signature(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset, int field_code)
314 const int org_offset = offset;
320 sig_len = tvb_get_guint8(tvb, offset);
323 /* sig_len = tvb_strsize(tvb, offset); */
325 sig = tvb_get_ephemeral_string(tvb, offset, sig_len);
326 offset += (sig_len + 1);
328 ti = proto_tree_add_string(tree, hf_dbus_type_signature, tvb, org_offset, offset - org_offset, sig);
329 if (!dbus_validate_signature(sig)) {
330 expert_add_info_format(dinfo->pinfo, ti, PI_PROTOCOL, PI_WARN, "Invalid signature");
334 switch (field_code) {
335 case DBUS_HEADER_FIELD_REPLY_SERIAL:
336 if (!strcmp(sig, "u")) { /* UINT32 */
337 dbus_val_t serial_val;
339 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'u', &serial_val);
341 { /* XXX link with sending frame (serial_val.uint) */ }
346 case DBUS_HEADER_FIELD_DESTINATION:
347 case DBUS_HEADER_FIELD_SENDER:
348 if (!strcmp(sig, "s")) { /* STRING */
351 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 's', &addr_val);
353 SET_ADDRESS((field_code == DBUS_HEADER_FIELD_DESTINATION) ? &dinfo->pinfo->dst : &dinfo->pinfo->src,
354 AT_STRINGZ, (int)strlen(addr_val.str)+1, addr_val.str);
359 case DBUS_HEADER_FIELD_SIGNATURE:
360 if (!strcmp(sig, "g")) { /* SIGNATURE */
363 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, 'g', &sig_val);
365 dinfo->body_sig = sig_val.str;
374 offset = dissect_dbus_sig(tvb, dinfo, tree, offset, *sig, &val);
383 dissect_dbus_hdr_fields(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
387 end_offset = offset + dinfo->fields_len;
389 while (offset < end_offset) {
390 proto_tree *field_tree;
395 ti = proto_tree_add_item(tree, hf_dbus_hdr_field, tvb, offset, 0, ENC_NA);
396 field_tree = proto_item_add_subtree(ti, ett_dbus_field);
398 field_code = tvb_get_guint8(tvb, offset);
399 proto_tree_add_item(field_tree, hf_dbus_hdr_field_code, tvb, offset, 1, dinfo->enc);
400 proto_item_append_text(ti, ": %s", val_to_str(field_code, field_code_vals, "Unknown: %d"));
403 offset = dissect_dbus_field_signature(tvb, dinfo, field_tree, offset, field_code);
407 offset = (offset + 7) & ~7; /* XXX ? */
409 proto_item_set_end(ti, tvb, offset);
412 /* XXX, verify if all required fields are preset */
414 if (offset >= end_offset) {
422 dissect_dbus_hdr(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
424 proto_tree *hdr_tree;
429 ti = proto_tree_add_item(tree, hf_dbus_hdr, tvb, offset, 0, ENC_NA);
430 hdr_tree = proto_item_add_subtree(ti, ett_dbus_hdr);
432 proto_tree_add_item(hdr_tree, hf_dbus_hdr_endianess, tvb, offset, 1, ENC_ASCII | ENC_NA);
435 type = tvb_get_guint8(tvb, offset);
436 col_add_str(dinfo->pinfo->cinfo, COL_INFO, val_to_str_const(type, message_type_vals, ""));
437 proto_tree_add_item(hdr_tree, hf_dbus_hdr_type, tvb, offset, 1, dinfo->enc);
440 proto_tree_add_item(hdr_tree, hf_dbus_hdr_flags, tvb, offset, 1, dinfo->enc);
443 proto_tree_add_item(hdr_tree, hf_dbus_hdr_version, tvb, offset, 1, dinfo->enc);
446 dinfo->body_len = dinfo->get32(tvb, offset);
447 proto_tree_add_item(hdr_tree, hf_dbus_hdr_body_length, tvb, offset, 4, dinfo->enc);
450 proto_tree_add_item(hdr_tree, hf_dbus_hdr_serial, tvb, offset, 4, dinfo->enc);
453 dinfo->fields_len = dinfo->get32(tvb, offset);
454 proto_tree_add_item(hdr_tree, hf_dbus_hdr_fields_length, tvb, offset, 4, dinfo->enc);
461 dissect_dbus_body(tvbuff_t *tvb, dbus_info_t *dinfo, proto_tree *tree, int offset)
463 proto_tree *body_tree;
466 if (dinfo->body_len && dinfo->body_sig[0]) {
467 const char *sig = dinfo->body_sig;
469 ti = proto_tree_add_item(tree, hf_dbus_body, tvb, offset, 0, ENC_NA);
470 body_tree = proto_item_add_subtree(ti, ett_dbus_body);
475 offset = dissect_dbus_sig(tvb, dinfo, body_tree, offset, *sig, &val);
481 proto_item_set_end(ti, tvb, offset);
483 } else if (dinfo->body_len || dinfo->body_sig[0]) {
490 dissect_dbus(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree)
492 proto_tree *dbus_tree = NULL;
497 col_set_str(pinfo->cinfo, COL_PROTOCOL, "D-BUS");
498 col_clear(pinfo->cinfo, COL_INFO);
500 memset(&dinfo, 0, sizeof(dinfo));
502 switch (tvb_get_guint8(tvb, 0)) {
504 dinfo.enc = ENC_LITTLE_ENDIAN;
505 dinfo.get16 = tvb_get_letohs;
506 dinfo.get32 = tvb_get_letohl;
507 dinfo.getdouble = tvb_get_letohieee_double;
510 dinfo.enc = ENC_BIG_ENDIAN;
511 dinfo.get16 = tvb_get_ntohs;
512 dinfo.get32 = tvb_get_ntohl;
513 dinfo.getdouble = tvb_get_ntohieee_double;
515 default: /* same as BIG_ENDIAN */
516 /* XXX we should probably return 0; */
518 dinfo.get16 = tvb_get_ntohs;
519 dinfo.get32 = tvb_get_ntohl;
520 dinfo.getdouble = tvb_get_ntohieee_double;
524 proto_item *ti = proto_tree_add_item(tree, proto_dbus, tvb, 0, -1, ENC_NA);
525 dbus_tree = proto_item_add_subtree(ti, ett_dbus);
529 offset = dissect_dbus_hdr(tvb, &dinfo, dbus_tree, offset);
530 offset = dissect_dbus_hdr_fields(tvb, &dinfo, dbus_tree, offset);
531 /* header aligned to 8B */
532 offset = (offset + 7) & ~7;
537 offset = dissect_dbus_body(tvb, &dinfo, dbus_tree, offset);
542 #define DBUS_HEADER_LEN 16
545 get_dbus_message_len(packet_info *pinfo _U_, tvbuff_t *tvb, int offset)
547 guint32 (*get_guint32)(tvbuff_t *, const gint);
549 guint32 len_body, len_hdr;
551 switch (tvb_get_guint8(tvb, offset)) {
553 get_guint32 = tvb_get_letohl;
557 get_guint32 = tvb_get_ntohl;
561 len_hdr = DBUS_HEADER_LEN + get_guint32(tvb, offset + 12);
562 len_hdr = (len_hdr + 7) & ~7;
563 len_body = get_guint32(tvb, offset + 4);
565 return len_hdr + len_body;
569 dissect_dbus_pdu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree)
571 dissect_dbus(tvb, pinfo, tree);
575 dissect_dbus_tcp(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree)
577 tcp_dissect_pdus(tvb, pinfo, tree, dbus_desegment, DBUS_HEADER_LEN, get_dbus_message_len, dissect_dbus_pdu);
578 return tvb_length(tvb);
582 proto_register_dbus(void)
584 /* XXX, FT_NONE -> FT_BYTES? */
585 static hf_register_info hf[] = {
588 { "Header", "dbus.header", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
590 { &hf_dbus_hdr_endianess,
591 { "Endianess Flag", "dbus.endianess", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL }
594 { "Message Type", "dbus.type", FT_UINT8, BASE_DEC, VALS(message_type_vals), 0x00, NULL, HFILL }
596 { &hf_dbus_hdr_flags,
597 { "Message Flags", "dbus.flags", FT_UINT8, BASE_HEX, NULL, 0x00, NULL, HFILL }
599 { &hf_dbus_hdr_version,
600 { "Protocol Version", "dbus.version", FT_UINT8, BASE_DEC, NULL, 0x00, NULL, HFILL }
602 { &hf_dbus_hdr_body_length,
603 { "Message body Length", "dbus.length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
605 { &hf_dbus_hdr_serial,
606 { "Message Serial (cookie)", "dbus.serial", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
608 { &hf_dbus_hdr_fields_length,
609 { "Header fields Length", "dbus.fields_length", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
612 { &hf_dbus_hdr_field,
613 { "Header Field", "dbus.field", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
615 { &hf_dbus_hdr_field_code,
616 { "Field code", "dbus.field.code", FT_UINT8, BASE_DEC, VALS(field_code_vals), 0x00, NULL, HFILL }
619 { &hf_dbus_type_signature,
620 { "Type signature", "dbus.type_signature", FT_STRINGZ, BASE_NONE, NULL, 0x00, NULL, HFILL }
624 { "Body", "dbus.body", FT_NONE, BASE_NONE, NULL, 0x00, NULL, HFILL }
628 { &hf_dbus_value_bool,
629 { "Value", "dbus.value.bool", FT_BOOLEAN, BASE_NONE, NULL, 0x00, NULL, HFILL }
631 { &hf_dbus_value_int,
632 { "Value", "dbus.value.int", FT_INT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
634 { &hf_dbus_value_uint,
635 { "Value", "dbus.value.uint", FT_UINT32, BASE_DEC, NULL, 0x00, NULL, HFILL }
637 { &hf_dbus_value_str,
638 { "Value", "dbus.value.str", FT_STRING, BASE_NONE, NULL, 0x00, NULL, HFILL }
640 { &hf_dbus_value_double,
641 { "Value", "dbus.value.double", FT_DOUBLE, BASE_NONE, NULL, 0x00, NULL, HFILL }
645 static gint *ett[] = {
652 proto_dbus = proto_register_protocol("D-Bus", "D-BUS", "dbus");
654 proto_register_field_array(proto_dbus, hf, array_length(hf));
655 proto_register_subtree_array(ett, array_length(ett));
659 proto_reg_handoff_dbus(void)
661 dissector_handle_t dbus_handle = new_create_dissector_handle(dissect_dbus, proto_dbus);
662 dissector_handle_t dbus_handle_tcp = new_create_dissector_handle(dissect_dbus_tcp, proto_dbus);
664 dissector_add_uint("wtap_encap", WTAP_ENCAP_DBUS, dbus_handle);
665 dissector_add_handle("tcp.port", dbus_handle_tcp);