1 /* capture-pcap-util-unix.c
2 * UN*X-specific utility routines for packet capture
4 * Wireshark - Network traffic analyzer
5 * By Gerald Combs <gerald@wireshark.org>
6 * Copyright 1998 Gerald Combs
8 * This program is free software; you can redistribute it and/or
9 * modify it under the terms of the GNU General Public License
10 * as published by the Free Software Foundation; either version 2
11 * of the License, or (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
29 #ifdef HAVE_PCAP_FINDALLDEVS
33 #else /* HAVE_PCAP_FINDALLDEVS */
44 #ifdef HAVE_SYS_SOCKET_H
45 #include <sys/socket.h>
48 #ifdef HAVE_SYS_IOCTL_H
49 #include <sys/ioctl.h>
53 * Keep Digital UNIX happy when including <net/if.h>.
59 #ifdef HAVE_SYS_SOCKIO_H
60 # include <sys/sockio.h>
63 #include "capture-pcap-util.h"
65 #endif /* HAVE_PCAP_FINDALLDEVS */
67 #include <capchild/capture_ifinfo.h>
68 #include "capture-pcap-util.h"
69 #include "capture-pcap-util-int.h"
71 #ifdef HAVE_PCAP_REMOTE
73 get_remote_interface_list(const char *hostname, const char *port,
74 int auth_type, const char *username,
75 const char *passwd, int *err, char **err_str)
77 struct pcap_rmtauth auth;
78 char source[PCAP_BUF_SIZE];
79 char errbuf[PCAP_ERRBUF_SIZE];
82 if (pcap_createsrcstr(source, PCAP_SRC_IFREMOTE, hostname, port,
83 NULL, errbuf) == -1) {
84 *err = CANT_GET_INTERFACE_LIST;
86 *err_str = cant_get_if_list_error_message(errbuf);
90 auth.type = auth_type;
91 auth.username = g_strdup(username);
92 auth.password = g_strdup(passwd);
94 result = get_interface_list_findalldevs_ex(source, &auth, err, err_str);
95 g_free(auth.username);
96 g_free(auth.password);
102 #ifdef HAVE_PCAP_FINDALLDEVS
104 get_interface_list(int *err, char **err_str)
106 return get_interface_list_findalldevs(err, err_str);
108 #else /* HAVE_PCAP_FINDALLDEVS */
109 struct search_user_data {
115 search_for_if_cb(gpointer data, gpointer user_data)
117 struct search_user_data *search_user_data = user_data;
118 if_info_t *if_info = data;
120 if (strcmp(if_info->name, search_user_data->name) == 0)
121 search_user_data->if_info = if_info;
125 get_interface_list(int *err, char **err_str)
128 gint nonloopback_pos = 0;
129 struct ifreq *ifr, *last;
131 struct ifreq ifrflags;
132 int sock = socket(AF_INET, SOCK_DGRAM, 0);
133 struct search_user_data user_data;
138 char errbuf[PCAP_ERRBUF_SIZE];
142 *err = CANT_GET_INTERFACE_LIST;
143 if (err_str != NULL) {
144 *err_str = g_strdup_printf(
145 "Can't get list of interfaces: error opening socket: %s",
152 * This code came from: W. Richard Stevens: "UNIX Network Programming",
153 * Networking APIs: Sockets and XTI, Vol 1, page 434.
156 len = 100 * sizeof(struct ifreq);
161 memset (buf, 0, len);
162 if (ioctl(sock, SIOCGIFCONF, &ifc) < 0) {
163 if (errno != EINVAL || lastlen != 0) {
164 if (err_str != NULL) {
165 *err_str = g_strdup_printf(
166 "Can't get list of interfaces: SIOCGIFCONF ioctl error: %s",
172 if ((unsigned int) ifc.ifc_len < sizeof(struct ifreq)) {
173 if (err_str != NULL) {
175 "Can't get list of interfaces: SIOCGIFCONF ioctl gave too small return buffer");
179 if (ifc.ifc_len == lastlen)
180 break; /* success, len has not changed */
181 lastlen = ifc.ifc_len;
183 len += 10 * sizeof(struct ifreq); /* increment */
186 ifr = (struct ifreq *) ifc.ifc_req;
187 last = (struct ifreq *) ((char *) ifr + ifc.ifc_len);
190 * Skip entries that begin with "dummy", or that include
191 * a ":" (the latter are Solaris virtuals).
193 if (strncmp(ifr->ifr_name, "dummy", 5) == 0 ||
194 strchr(ifr->ifr_name, ':') != NULL)
198 * If we already have this interface name on the list,
199 * don't add it, but, if we don't already have an IP
200 * address for it, add that address (SIOCGIFCONF returns,
201 * at least on BSD-flavored systems, one entry per
202 * interface *address*; if an interface has multiple
203 * addresses, we get multiple entries for it).
205 user_data.name = ifr->ifr_name;
206 user_data.if_info = NULL;
207 g_list_foreach(il, search_for_if_cb, &user_data);
208 if (user_data.if_info != NULL) {
209 if_info_add_address(user_data.if_info, &ifr->ifr_addr);
214 * Get the interface flags.
216 memset(&ifrflags, 0, sizeof ifrflags);
217 g_strlcpy(ifrflags.ifr_name, ifr->ifr_name,
218 sizeof ifrflags.ifr_name);
219 if (ioctl(sock, SIOCGIFFLAGS, (char *)&ifrflags) < 0) {
222 if (err_str != NULL) {
223 *err_str = g_strdup_printf(
224 "Can't get list of interfaces: SIOCGIFFLAGS error getting flags for interface %s: %s",
225 ifr->ifr_name, g_strerror(errno));
231 * Skip interfaces that aren't up.
233 if (!(ifrflags.ifr_flags & IFF_UP))
237 * Skip interfaces that we can't open with "libpcap".
238 * Open with the minimum packet size - it appears that the
239 * IRIX SIOCSNOOPLEN "ioctl" may fail if the capture length
240 * supplied is too large, rather than just truncating it.
242 pch = pcap_open_live(ifr->ifr_name, MIN_PACKET_SIZE, 0, 0,
249 * If it's a loopback interface, add it at the end of the
250 * list, otherwise add it after the last non-loopback
251 * interface, so all loopback interfaces go at the end - we
252 * don't want a loopback interface to be the default capture
253 * device unless there are no non-loopback devices.
255 loopback = ((ifrflags.ifr_flags & IFF_LOOPBACK) ||
256 strncmp(ifr->ifr_name, "lo", 2) == 0);
257 if_info = if_info_new(ifr->ifr_name, NULL, loopback);
258 if_info_add_address(if_info, &ifr->ifr_addr);
260 il = g_list_append(il, if_info);
262 il = g_list_insert(il, if_info, nonloopback_pos);
264 * Insert the next non-loopback interface after this
272 ifr = (struct ifreq *) ((char *) ifr +
273 (ifr->ifr_addr.sa_len > sizeof(ifr->ifr_addr) ?
274 ifr->ifr_addr.sa_len : sizeof(ifr->ifr_addr)) +
277 ifr = (struct ifreq *) ((char *) ifr + sizeof(struct ifreq));
283 * OK, maybe we have support for the "any" device, to do a cooked
284 * capture on all interfaces at once.
285 * Try opening it and, if that succeeds, add it to the end of
286 * the list of interfaces.
288 pch = pcap_open_live("any", MIN_PACKET_SIZE, 0, 0, errbuf);
291 * It worked; we can use the "any" device.
293 if_info = if_info_new("any",
294 "Pseudo-device that captures on all interfaces", FALSE);
295 il = g_list_insert(il, if_info, -1);
305 * No interfaces found.
307 *err = NO_INTERFACES_FOUND;
315 free_interface_list(il);
318 *err = CANT_GET_INTERFACE_LIST;
321 #endif /* HAVE_PCAP_FINDALLDEVS */
324 * Get an error message string for a CANT_GET_INTERFACE_LIST error from
325 * "get_interface_list()".
328 cant_get_if_list_error_message(const char *err_str)
330 return g_strdup_printf("Can't get list of interfaces: %s", err_str);
334 * Append the version of libpcap with which we were compiled to a GString.
337 get_compiled_pcap_version(GString *str)
340 * NOTE: in *some* flavors of UN*X, the data from a shared
341 * library might be linked into executable images that are
342 * linked with that shared library, in which case you could
343 * look at pcap_version[] to get the version with which
344 * the program was compiled.
346 * In other flavors of UN*X, that doesn't happen, so
347 * pcap_version[] gives you the version the program is
348 * running with, not the version it was built with, and,
349 * in at least some of them, if the length of a data item
350 * referred to by the executable - such as the pcap_version[]
351 * string - isn't the same in the version of the library
352 * with which the program was built and the version with
353 * which it was run, the run-time linker will complain,
356 * So, for now, we just give up on reporting the version
357 * of libpcap with which we were compiled.
359 g_string_append(str, "with libpcap");
363 * Append the version of libpcap with which we we're running to a GString.
366 get_runtime_pcap_version(GString *str)
368 g_string_append_printf(str, "with ");
369 #ifdef HAVE_PCAP_LIB_VERSION
370 g_string_append(str, pcap_lib_version());
372 g_string_append(str, "libpcap (version unknown)");
376 #else /* HAVE_LIBPCAP */
379 * Append an indication that we were not compiled with libpcap
383 get_compiled_pcap_version(GString *str)
385 g_string_append(str, "without libpcap");
389 * Don't append anything, as we weren't even compiled to use WinPcap.
392 get_runtime_pcap_version(GString *str _U_)
396 #endif /* HAVE_LIBPCAP */