2 * Routines for capture options setting
6 * Wireshark - Network traffic analyzer
7 * By Gerald Combs <gerald@wireshark.org>
8 * Copyright 1998 Gerald Combs
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version 2
13 * of the License, or (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
38 #include <epan/packet.h>
39 #include <epan/prefs.h>
40 #include "ui/simple_dialog.h"
41 #include "capture_ui_utils.h"
43 #include "capture_opts.h"
44 #include "ringbuffer.h"
45 #include "clopts_common.h"
46 #include "console_io.h"
47 #include "cmdarg_err.h"
49 #include "capture_ifinfo.h"
50 #include "capture-pcap-util.h"
51 #include <wsutil/file_util.h>
54 #include "capture_win_ifnames.h" /* windows friendly interface names */
57 static gboolean capture_opts_output_to_pipe(const char *save_file, gboolean *is_pipe);
61 capture_opts_init(capture_options *capture_opts, void *cf)
63 capture_opts->cf = cf;
64 capture_opts->ifaces = g_array_new(FALSE, FALSE, sizeof(interface_options));
65 capture_opts->all_ifaces = g_array_new(FALSE, FALSE, sizeof(interface_t));
66 capture_opts->num_selected = 0;
67 capture_opts->default_options.name = NULL;
68 capture_opts->default_options.descr = NULL;
69 capture_opts->default_options.cfilter = NULL;
70 capture_opts->default_options.has_snaplen = FALSE;
71 capture_opts->default_options.snaplen = WTAP_MAX_PACKET_SIZE;
72 capture_opts->default_options.linktype = -1;
73 capture_opts->default_options.promisc_mode = TRUE;
74 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
75 capture_opts->default_options.buffer_size = 1; /* 1 MB */
77 capture_opts->default_options.monitor_mode = FALSE;
78 #ifdef HAVE_PCAP_REMOTE
79 capture_opts->default_options.src_type = CAPTURE_IFLOCAL;
80 capture_opts->default_options.remote_host = NULL;
81 capture_opts->default_options.remote_port = NULL;
82 capture_opts->default_options.auth_type = CAPTURE_AUTH_NULL;
83 capture_opts->default_options.auth_username = NULL;
84 capture_opts->default_options.auth_password = NULL;
85 capture_opts->default_options.datatx_udp = FALSE;
86 capture_opts->default_options.nocap_rpcap = TRUE;
87 capture_opts->default_options.nocap_local = FALSE;
89 #ifdef HAVE_PCAP_SETSAMPLING
90 capture_opts->default_options.sampling_method = CAPTURE_SAMP_NONE;
91 capture_opts->default_options.sampling_param = 0;
93 capture_opts->saving_to_file = FALSE;
94 capture_opts->save_file = NULL;
95 capture_opts->group_read_access = FALSE;
96 #ifdef PCAP_NG_DEFAULT
97 capture_opts->use_pcapng = TRUE; /* Save as pcap-ng by default */
99 capture_opts->use_pcapng = FALSE; /* Save as pcap by default */
101 capture_opts->real_time_mode = TRUE;
102 capture_opts->show_info = TRUE;
103 capture_opts->quit_after_cap = getenv("WIRESHARK_QUIT_AFTER_CAPTURE") ? TRUE : FALSE;
104 capture_opts->restart = FALSE;
106 capture_opts->multi_files_on = FALSE;
107 capture_opts->has_file_duration = FALSE;
108 capture_opts->file_duration = 60; /* 1 min */
109 capture_opts->has_ring_num_files = FALSE;
110 capture_opts->ring_num_files = RINGBUFFER_MIN_NUM_FILES;
112 capture_opts->has_autostop_files = FALSE;
113 capture_opts->autostop_files = 1;
114 capture_opts->has_autostop_packets = FALSE;
115 capture_opts->autostop_packets = 0;
116 capture_opts->has_autostop_filesize = FALSE;
117 capture_opts->autostop_filesize = 1024; /* 1 MB */
118 capture_opts->has_autostop_duration = FALSE;
119 capture_opts->autostop_duration = 60; /* 1 min */
122 capture_opts->fork_child = -1; /* invalid process handle */
124 capture_opts->signal_pipe_write_fd = -1;
126 capture_opts->state = CAPTURE_STOPPED;
127 capture_opts->output_to_pipe = FALSE;
129 capture_opts->owner = getuid();
130 capture_opts->group = getgid();
135 /* log content of capture_opts */
137 capture_opts_log(const char *log_domain, GLogLevelFlags log_level, capture_options *capture_opts) {
140 g_log(log_domain, log_level, "CAPTURE OPTIONS :");
141 g_log(log_domain, log_level, "CFile : %p", capture_opts->cf);
143 for (i = 0; i < capture_opts->ifaces->len; i++) {
144 interface_options interface_opts;
146 interface_opts = g_array_index(capture_opts->ifaces, interface_options, i);
147 g_log(log_domain, log_level, "Interface name[%02d] : %s", i, interface_opts.name ? interface_opts.name : "(unspecified)");
148 g_log(log_domain, log_level, "Interface Descr[%02d] : %s", i, interface_opts.descr ? interface_opts.descr : "(unspecified)");
149 g_log(log_domain, log_level, "Con display name[%02d]: %s", i, interface_opts.console_display_name ? interface_opts.console_display_name : "(unspecified)");
150 g_log(log_domain, log_level, "Capture filter[%02d] : %s", i, interface_opts.cfilter ? interface_opts.cfilter : "(unspecified)");
151 g_log(log_domain, log_level, "Snap length[%02d] (%u) : %d", i, interface_opts.has_snaplen, interface_opts.snaplen);
152 g_log(log_domain, log_level, "Link Type[%02d] : %d", i, interface_opts.linktype);
153 g_log(log_domain, log_level, "Promiscuous Mode[%02d]: %s", i, interface_opts.promisc_mode?"TRUE":"FALSE");
154 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
155 g_log(log_domain, log_level, "Buffer size[%02d] : %d (MB)", i, interface_opts.buffer_size);
157 g_log(log_domain, log_level, "Monitor Mode[%02d] : %s", i, interface_opts.monitor_mode?"TRUE":"FALSE");
158 #ifdef HAVE_PCAP_REMOTE
159 g_log(log_domain, log_level, "Capture source[%02d] : %s", i,
160 interface_opts.src_type == CAPTURE_IFLOCAL ? "Local interface" :
161 interface_opts.src_type == CAPTURE_IFREMOTE ? "Remote interface" :
163 if (interface_opts.src_type == CAPTURE_IFREMOTE) {
164 g_log(log_domain, log_level, "Remote host[%02d] : %s", i, interface_opts.remote_host ? interface_opts.remote_host : "(unspecified)");
165 g_log(log_domain, log_level, "Remote port[%02d] : %s", i, interface_opts.remote_port ? interface_opts.remote_port : "(unspecified)");
167 g_log(log_domain, log_level, "Authentication[%02d] : %s", i,
168 interface_opts.auth_type == CAPTURE_AUTH_NULL ? "Null" :
169 interface_opts.auth_type == CAPTURE_AUTH_PWD ? "By username/password" :
171 if (interface_opts.auth_type == CAPTURE_AUTH_PWD) {
172 g_log(log_domain, log_level, "Auth username[%02d] : %s", i, interface_opts.auth_username ? interface_opts.auth_username : "(unspecified)");
173 g_log(log_domain, log_level, "Auth password[%02d] : <hidden>", i);
175 g_log(log_domain, log_level, "UDP data tfer[%02d] : %u", i, interface_opts.datatx_udp);
176 g_log(log_domain, log_level, "No cap. RPCAP[%02d] : %u", i, interface_opts.nocap_rpcap);
177 g_log(log_domain, log_level, "No cap. local[%02d] : %u", i, interface_opts.nocap_local);
179 #ifdef HAVE_PCAP_SETSAMPLING
180 g_log(log_domain, log_level, "Sampling meth.[%02d] : %d", i, interface_opts.sampling_method);
181 g_log(log_domain, log_level, "Sampling param.[%02d] : %d", i, interface_opts.sampling_param);
184 g_log(log_domain, log_level, "Interface name[df] : %s", capture_opts->default_options.name ? capture_opts->default_options.name : "(unspecified)");
185 g_log(log_domain, log_level, "Interface Descr[df] : %s", capture_opts->default_options.descr ? capture_opts->default_options.descr : "(unspecified)");
186 g_log(log_domain, log_level, "Capture filter[df] : %s", capture_opts->default_options.cfilter ? capture_opts->default_options.cfilter : "(unspecified)");
187 g_log(log_domain, log_level, "Snap length[df] (%u) : %d", capture_opts->default_options.has_snaplen, capture_opts->default_options.snaplen);
188 g_log(log_domain, log_level, "Link Type[df] : %d", capture_opts->default_options.linktype);
189 g_log(log_domain, log_level, "Promiscuous Mode[df]: %s", capture_opts->default_options.promisc_mode?"TRUE":"FALSE");
190 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
191 g_log(log_domain, log_level, "Buffer size[df] : %d (MB)", capture_opts->default_options.buffer_size);
193 g_log(log_domain, log_level, "Monitor Mode[df] : %s", capture_opts->default_options.monitor_mode?"TRUE":"FALSE");
194 #ifdef HAVE_PCAP_REMOTE
195 g_log(log_domain, log_level, "Capture source[df] : %s",
196 capture_opts->default_options.src_type == CAPTURE_IFLOCAL ? "Local interface" :
197 capture_opts->default_options.src_type == CAPTURE_IFREMOTE ? "Remote interface" :
199 if (capture_opts->default_options.src_type == CAPTURE_IFREMOTE) {
200 g_log(log_domain, log_level, "Remote host[df] : %s", capture_opts->default_options.remote_host ? capture_opts->default_options.remote_host : "(unspecified)");
201 g_log(log_domain, log_level, "Remote port[df] : %s", capture_opts->default_options.remote_port ? capture_opts->default_options.remote_port : "(unspecified)");
203 g_log(log_domain, log_level, "Authentication[df] : %s",
204 capture_opts->default_options.auth_type == CAPTURE_AUTH_NULL ? "Null" :
205 capture_opts->default_options.auth_type == CAPTURE_AUTH_PWD ? "By username/password" :
207 if (capture_opts->default_options.auth_type == CAPTURE_AUTH_PWD) {
208 g_log(log_domain, log_level, "Auth username[df] : %s", capture_opts->default_options.auth_username ? capture_opts->default_options.auth_username : "(unspecified)");
209 g_log(log_domain, log_level, "Auth password[df] : <hidden>");
211 g_log(log_domain, log_level, "UDP data tfer[df] : %u", capture_opts->default_options.datatx_udp);
212 g_log(log_domain, log_level, "No cap. RPCAP[df] : %u", capture_opts->default_options.nocap_rpcap);
213 g_log(log_domain, log_level, "No cap. local[df] : %u", capture_opts->default_options.nocap_local);
215 #ifdef HAVE_PCAP_SETSAMPLING
216 g_log(log_domain, log_level, "Sampling meth. [df] : %d", capture_opts->default_options.sampling_method);
217 g_log(log_domain, log_level, "Sampling param.[df] : %d", capture_opts->default_options.sampling_param);
219 g_log(log_domain, log_level, "SavingToFile : %u", capture_opts->saving_to_file);
220 g_log(log_domain, log_level, "SaveFile : %s", (capture_opts->save_file) ? capture_opts->save_file : "");
221 g_log(log_domain, log_level, "GroupReadAccess : %u", capture_opts->group_read_access);
222 g_log(log_domain, log_level, "Fileformat : %s", (capture_opts->use_pcapng) ? "PCAPNG" : "PCAP");
223 g_log(log_domain, log_level, "RealTimeMode : %u", capture_opts->real_time_mode);
224 g_log(log_domain, log_level, "ShowInfo : %u", capture_opts->show_info);
225 g_log(log_domain, log_level, "QuitAfterCap : %u", capture_opts->quit_after_cap);
227 g_log(log_domain, log_level, "MultiFilesOn : %u", capture_opts->multi_files_on);
228 g_log(log_domain, log_level, "FileDuration (%u) : %u", capture_opts->has_file_duration, capture_opts->file_duration);
229 g_log(log_domain, log_level, "RingNumFiles (%u) : %u", capture_opts->has_ring_num_files, capture_opts->ring_num_files);
231 g_log(log_domain, log_level, "AutostopFiles (%u) : %u", capture_opts->has_autostop_files, capture_opts->autostop_files);
232 g_log(log_domain, log_level, "AutostopPackets (%u) : %u", capture_opts->has_autostop_packets, capture_opts->autostop_packets);
233 g_log(log_domain, log_level, "AutostopFilesize(%u) : %u (KB)", capture_opts->has_autostop_filesize, capture_opts->autostop_filesize);
234 g_log(log_domain, log_level, "AutostopDuration(%u) : %u", capture_opts->has_autostop_duration, capture_opts->autostop_duration);
236 g_log(log_domain, log_level, "ForkChild : %d", capture_opts->fork_child);
238 g_log(log_domain, log_level, "SignalPipeWrite : %d", capture_opts->signal_pipe_write_fd);
243 * Given a string of the form "<autostop criterion>:<value>", as might appear
244 * as an argument to a "-a" option, parse it and set the criterion in
245 * question. Return an indication of whether it succeeded or failed
249 set_autostop_criterion(capture_options *capture_opts, const char *autostoparg)
253 colonp = strchr(autostoparg, ':');
261 * Skip over any white space (there probably won't be any, but
262 * as we allow it in the preferences file, we might as well
265 while (isspace((guchar)*p))
269 * Put the colon back, so if our caller uses, in an
270 * error message, the string they passed us, the message
276 if (strcmp(autostoparg,"duration") == 0) {
277 capture_opts->has_autostop_duration = TRUE;
278 capture_opts->autostop_duration = get_positive_int(p,"autostop duration");
279 } else if (strcmp(autostoparg,"filesize") == 0) {
280 capture_opts->has_autostop_filesize = TRUE;
281 capture_opts->autostop_filesize = get_positive_int(p,"autostop filesize");
282 } else if (strcmp(autostoparg,"files") == 0) {
283 capture_opts->multi_files_on = TRUE;
284 capture_opts->has_autostop_files = TRUE;
285 capture_opts->autostop_files = get_positive_int(p,"autostop files");
289 *colonp = ':'; /* put the colon back */
294 * Given a string of the form "<ring buffer file>:<duration>", as might appear
295 * as an argument to a "-b" option, parse it and set the arguments in
296 * question. Return an indication of whether it succeeded or failed
300 get_ring_arguments(capture_options *capture_opts, const char *arg)
302 gchar *p = NULL, *colonp;
304 colonp = strchr(arg, ':');
312 * Skip over any white space (there probably won't be any, but
313 * as we allow it in the preferences file, we might as well
316 while (isspace((guchar)*p))
320 * Put the colon back, so if our caller uses, in an
321 * error message, the string they passed us, the message
328 if (strcmp(arg,"files") == 0) {
329 capture_opts->has_ring_num_files = TRUE;
330 capture_opts->ring_num_files = get_positive_int(p, "number of ring buffer files");
331 } else if (strcmp(arg,"filesize") == 0) {
332 capture_opts->has_autostop_filesize = TRUE;
333 capture_opts->autostop_filesize = get_positive_int(p, "ring buffer filesize");
334 } else if (strcmp(arg,"duration") == 0) {
335 capture_opts->has_file_duration = TRUE;
336 capture_opts->file_duration = get_positive_int(p, "ring buffer duration");
339 *colonp = ':'; /* put the colon back */
343 #ifdef HAVE_PCAP_SETSAMPLING
345 * Given a string of the form "<sampling type>:<value>", as might appear
346 * as an argument to a "-m" option, parse it and set the arguments in
347 * question. Return an indication of whether it succeeded or failed
351 get_sampling_arguments(capture_options *capture_opts, const char *arg)
353 gchar *p = NULL, *colonp;
355 colonp = strchr(arg, ':');
362 while (isspace((guchar)*p))
369 if (strcmp(arg, "count") == 0) {
370 if (capture_opts->ifaces->len > 0) {
371 interface_options interface_opts;
373 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
374 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
375 interface_opts.sampling_method = CAPTURE_SAMP_BY_COUNT;
376 interface_opts.sampling_param = get_positive_int(p, "sampling count");
377 g_array_append_val(capture_opts->ifaces, interface_opts);
379 capture_opts->default_options.sampling_method = CAPTURE_SAMP_BY_COUNT;
380 capture_opts->default_options.sampling_param = get_positive_int(p, "sampling count");
382 } else if (strcmp(arg, "timer") == 0) {
383 if (capture_opts->ifaces->len > 0) {
384 interface_options interface_opts;
386 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
387 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
388 interface_opts.sampling_method = CAPTURE_SAMP_BY_TIMER;
389 interface_opts.sampling_param = get_positive_int(p, "sampling timer");
390 g_array_append_val(capture_opts->ifaces, interface_opts);
392 capture_opts->default_options.sampling_method = CAPTURE_SAMP_BY_TIMER;
393 capture_opts->default_options.sampling_param = get_positive_int(p, "sampling timer");
401 #ifdef HAVE_PCAP_REMOTE
403 * Given a string of the form "<username>:<password>", as might appear
404 * as an argument to a "-A" option, parse it and set the arguments in
405 * question. Return an indication of whether it succeeded or failed
409 get_auth_arguments(capture_options *capture_opts, const char *arg)
411 gchar *p = NULL, *colonp;
413 colonp = strchr(arg, ':');
420 while (isspace((guchar)*p))
423 if (capture_opts->ifaces->len > 0) {
424 interface_options interface_opts;
426 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
427 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
428 interface_opts.auth_type = CAPTURE_AUTH_PWD;
429 interface_opts.auth_username = g_strdup(arg);
430 interface_opts.auth_password = g_strdup(p);
431 g_array_append_val(capture_opts->ifaces, interface_opts);
433 capture_opts->default_options.auth_type = CAPTURE_AUTH_PWD;
434 capture_opts->default_options.auth_username = g_strdup(arg);
435 capture_opts->default_options.auth_password = g_strdup(p);
443 capture_opts_add_iface_opt(capture_options *capture_opts, const char *optarg_str_p)
451 interface_options interface_opts;
453 /* retrieve the interface list to compare the option specfied against */
454 if_list = capture_interface_list(&err, &err_str);
455 if (if_list == NULL) {
458 case CANT_GET_INTERFACE_LIST:
460 cmdarg_err("%s", err_str);
464 case NO_INTERFACES_FOUND:
465 cmdarg_err("There are no interfaces on which a capture can be done");
473 * If the argument is a number, treat it as an index into the list
474 * of adapters, as printed by "tshark -D".
476 * This should be OK on UNIX systems, as interfaces shouldn't have
477 * names that begin with digits. It can be useful on Windows, where
478 * more than one interface can have the same name.
480 adapter_index = strtol(optarg_str_p, &p, 10);
481 if (p != NULL && *p == '\0') {
482 if (adapter_index < 0) {
483 cmdarg_err("The specified adapter index is a negative number");
486 if (adapter_index > INT_MAX) {
487 cmdarg_err("The specified adapter index is too large (greater than %d)",
491 if (adapter_index == 0) {
492 cmdarg_err("There is no interface with that adapter index");
495 if_info = (if_info_t *)g_list_nth_data(if_list, adapter_index - 1);
496 if (if_info == NULL) {
497 cmdarg_err("There is no interface with that adapter index");
500 interface_opts.name = g_strdup(if_info->name);
501 if(if_info->friendly_name!=NULL){
502 /* we know the friendlyname, so display that instead of the interface name/guid */
503 interface_opts.console_display_name = g_strdup(if_info->friendly_name);
505 /* fallback to the interface name */
506 interface_opts.console_display_name = g_strdup(if_info->name);
509 /* try and do an exact match (case insensitive) */
514 for (if_entry = g_list_first(if_list); if_entry != NULL;
515 if_entry = g_list_next(if_entry))
517 if_info = (if_info_t *)if_entry->data;
518 /* exact name check */
519 if(g_ascii_strcasecmp(if_info->name, optarg_str_p)==0){
520 /* exact match on the interface name, use that for displaying etc */
521 interface_opts.name = g_strdup(if_info->name);
523 if(if_info->friendly_name!=NULL){
524 /* if we know a friendly_name, use that for console_display_name, as
525 * it is the basis for the auto generated temp filename */
526 interface_opts.console_display_name = g_strdup(if_info->friendly_name);
528 interface_opts.console_display_name = g_strdup(if_info->name);
534 /* exact friendlyname check */
535 if(if_info->friendly_name!=NULL && g_ascii_strcasecmp(if_info->friendly_name, optarg_str_p)==0){
536 /* exact match - use the friendly name for display */
537 interface_opts.name = g_strdup(if_info->name);
538 interface_opts.console_display_name = g_strdup(if_info->friendly_name);
544 /* didn't find, attempt a case insensitive prefix match of the friendly name*/
546 size_t prefix_length;
547 prefix_length=strlen(optarg_str_p);
548 for (if_entry = g_list_first(if_list); if_entry != NULL;
549 if_entry = g_list_next(if_entry))
551 if_info = (if_info_t *)if_entry->data;
553 if(if_info->friendly_name!=NULL && g_ascii_strncasecmp(if_info->friendly_name, optarg_str_p, prefix_length)==0){
554 /* prefix match - use the friendly name for display */
555 interface_opts.name = g_strdup(if_info->name);
556 interface_opts.console_display_name = g_strdup(if_info->friendly_name);
563 cmdarg_err("Failed to match interface '%s'", optarg_str_p);
568 free_interface_list(if_list);
570 /* We don't set iface_descr here because doing so requires
571 * capture_ui_utils.c which requires epan/prefs.c which is
572 * probably a bit too much dependency for here...
574 interface_opts.descr = g_strdup(capture_opts->default_options.descr);
575 interface_opts.cfilter = g_strdup(capture_opts->default_options.cfilter);
576 interface_opts.snaplen = capture_opts->default_options.snaplen;
577 interface_opts.has_snaplen = capture_opts->default_options.has_snaplen;
578 interface_opts.linktype = capture_opts->default_options.linktype;
579 interface_opts.promisc_mode = capture_opts->default_options.promisc_mode;
580 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
581 interface_opts.buffer_size = capture_opts->default_options.buffer_size;
583 interface_opts.monitor_mode = capture_opts->default_options.monitor_mode;
584 #ifdef HAVE_PCAP_REMOTE
585 interface_opts.src_type = capture_opts->default_options.src_type;
586 interface_opts.remote_host = g_strdup(capture_opts->default_options.remote_host);
587 interface_opts.remote_port = g_strdup(capture_opts->default_options.remote_port);
588 interface_opts.auth_type = capture_opts->default_options.auth_type;
589 interface_opts.auth_username = g_strdup(capture_opts->default_options.auth_username);
590 interface_opts.auth_password = g_strdup(capture_opts->default_options.auth_password);
591 interface_opts.datatx_udp = capture_opts->default_options.datatx_udp;
592 interface_opts.nocap_rpcap = capture_opts->default_options.nocap_rpcap;
593 interface_opts.nocap_local = capture_opts->default_options.nocap_local;
595 #ifdef HAVE_PCAP_SETSAMPLING
596 interface_opts.sampling_method = capture_opts->default_options.sampling_method;
597 interface_opts.sampling_param = capture_opts->default_options.sampling_param;
600 g_array_append_val(capture_opts->ifaces, interface_opts);
607 capture_opts_add_opt(capture_options *capture_opts, int opt, const char *optarg_str_p, gboolean *start_capture)
612 case 'a': /* autostop criteria */
613 if (set_autostop_criterion(capture_opts, optarg_str_p) == FALSE) {
614 cmdarg_err("Invalid or unknown -a flag \"%s\"", optarg_str_p);
618 #ifdef HAVE_PCAP_REMOTE
620 if (get_auth_arguments(capture_opts, optarg_str_p) == FALSE) {
621 cmdarg_err("Invalid or unknown -A arg \"%s\"", optarg_str_p);
626 case 'b': /* Ringbuffer option */
627 capture_opts->multi_files_on = TRUE;
628 if (get_ring_arguments(capture_opts, optarg_str_p) == FALSE) {
629 cmdarg_err("Invalid or unknown -b arg \"%s\"", optarg_str_p);
633 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
634 case 'B': /* Buffer size */
635 if (capture_opts->ifaces->len > 0) {
636 interface_options interface_opts;
638 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
639 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
640 interface_opts.buffer_size = get_positive_int(optarg_str_p, "buffer size");
641 g_array_append_val(capture_opts->ifaces, interface_opts);
643 capture_opts->default_options.buffer_size = get_positive_int(optarg_str_p, "buffer size");
647 case 'c': /* Capture n packets */
648 capture_opts->has_autostop_packets = TRUE;
649 capture_opts->autostop_packets = get_positive_int(optarg_str_p, "packet count");
651 case 'f': /* capture filter */
652 if (capture_opts->ifaces->len > 0) {
653 interface_options interface_opts;
655 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
656 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
657 g_free(interface_opts.cfilter);
658 interface_opts.cfilter = g_strdup(optarg_str_p);
659 g_array_append_val(capture_opts->ifaces, interface_opts);
661 g_free(capture_opts->default_options.cfilter);
662 capture_opts->default_options.cfilter = g_strdup(optarg_str_p);
665 case 'H': /* Hide capture info dialog box */
666 capture_opts->show_info = FALSE;
668 case 'i': /* Use interface x */
669 status = capture_opts_add_iface_opt(capture_opts, optarg_str_p);
674 #ifdef HAVE_PCAP_CREATE
675 case 'I': /* Capture in monitor mode */
676 if (capture_opts->ifaces->len > 0) {
677 interface_options interface_opts;
679 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
680 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
681 interface_opts.monitor_mode = TRUE;
682 g_array_append_val(capture_opts->ifaces, interface_opts);
684 capture_opts->default_options.monitor_mode = TRUE;
688 case 'k': /* Start capture immediately */
689 *start_capture = TRUE;
691 /*case 'l':*/ /* Automatic scrolling in live capture mode */
692 #ifdef HAVE_PCAP_SETSAMPLING
694 if (get_sampling_arguments(capture_opts, optarg_str_p) == FALSE) {
695 cmdarg_err("Invalid or unknown -m arg \"%s\"", optarg_str_p);
700 case 'n': /* Use pcapng format */
701 capture_opts->use_pcapng = TRUE;
703 case 'p': /* Don't capture in promiscuous mode */
704 if (capture_opts->ifaces->len > 0) {
705 interface_options interface_opts;
707 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
708 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
709 interface_opts.promisc_mode = FALSE;
710 g_array_append_val(capture_opts->ifaces, interface_opts);
712 capture_opts->default_options.promisc_mode = FALSE;
715 case 'P': /* Use pcap format */
716 capture_opts->use_pcapng = FALSE;
718 #ifdef HAVE_PCAP_REMOTE
720 if (capture_opts->ifaces->len > 0) {
721 interface_options interface_opts;
723 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
724 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
725 interface_opts.nocap_rpcap = FALSE;
726 g_array_append_val(capture_opts->ifaces, interface_opts);
728 capture_opts->default_options.nocap_rpcap = FALSE;
732 case 's': /* Set the snapshot (capture) length */
733 snaplen = get_natural_int(optarg_str_p, "snapshot length");
735 * Make a snapshot length of 0 equivalent to the maximum packet
736 * length, mirroring what tcpdump does.
739 snaplen = WTAP_MAX_PACKET_SIZE;
740 if (capture_opts->ifaces->len > 0) {
741 interface_options interface_opts;
743 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
744 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
745 interface_opts.has_snaplen = TRUE;
746 interface_opts.snaplen = snaplen;
747 g_array_append_val(capture_opts->ifaces, interface_opts);
749 capture_opts->default_options.snaplen = snaplen;
750 capture_opts->default_options.has_snaplen = TRUE;
753 case 'S': /* "Real-Time" mode: used for following file ala tail -f */
754 capture_opts->real_time_mode = TRUE;
756 #ifdef HAVE_PCAP_REMOTE
758 if (capture_opts->ifaces->len > 0) {
759 interface_options interface_opts;
761 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
762 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
763 interface_opts.datatx_udp = TRUE;
764 g_array_append_val(capture_opts->ifaces, interface_opts);
766 capture_opts->default_options.datatx_udp = TRUE;
770 case 'w': /* Write to capture file x */
771 capture_opts->saving_to_file = TRUE;
772 g_free(capture_opts->save_file);
773 capture_opts->save_file = g_strdup(optarg_str_p);
774 status = capture_opts_output_to_pipe(capture_opts->save_file, &capture_opts->output_to_pipe);
776 case 'g': /* enable group read access on the capture file(s) */
777 capture_opts->group_read_access = TRUE;
779 case 'y': /* Set the pcap data link type */
780 if (capture_opts->ifaces->len > 0) {
781 interface_options interface_opts;
783 interface_opts = g_array_index(capture_opts->ifaces, interface_options, capture_opts->ifaces->len - 1);
784 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, capture_opts->ifaces->len - 1);
785 interface_opts.linktype = linktype_name_to_val(optarg_str_p);
786 if (interface_opts.linktype == -1) {
787 cmdarg_err("The specified data link type \"%s\" isn't valid",
791 g_array_append_val(capture_opts->ifaces, interface_opts);
793 capture_opts->default_options.linktype = linktype_name_to_val(optarg_str_p);
794 if (capture_opts->default_options.linktype == -1) {
795 cmdarg_err("The specified data link type \"%s\" isn't valid",
802 /* the caller is responsible to send us only the right opt's */
803 g_assert_not_reached();
810 capture_opts_print_if_capabilities(if_capabilities_t *caps, char *name,
811 gboolean monitor_mode)
814 data_link_info_t *data_link_info;
816 if (caps->can_set_rfmon)
817 fprintf_stderr("Data link types of interface %s when %sin monitor mode (use option -y to set):\n",
818 name, monitor_mode ? "" : "not ");
820 fprintf_stderr("Data link types of interface %s (use option -y to set):\n", name);
821 for (lt_entry = caps->data_link_types; lt_entry != NULL;
822 lt_entry = g_list_next(lt_entry)) {
823 data_link_info = (data_link_info_t *)lt_entry->data;
824 fprintf_stderr(" %s", data_link_info->name);
825 if (data_link_info->description != NULL)
826 fprintf_stderr(" (%s)", data_link_info->description);
828 fprintf_stderr(" (not supported)");
829 fprintf_stderr("\n");
833 /* Print an ASCII-formatted list of interfaces. */
835 capture_opts_print_interfaces(GList *if_list)
841 i = 1; /* Interface id number */
842 for (if_entry = g_list_first(if_list); if_entry != NULL;
843 if_entry = g_list_next(if_entry)) {
844 if_info = (if_info_t *)if_entry->data;
845 fprintf_stderr("%d. %s", i++, if_info->name);
847 /* print the interface friendly name if known, if not fall back to vendor description */
848 if (if_info->friendly_name != NULL){
849 fprintf_stderr(" (%s)", if_info->friendly_name);
851 /* Print the description if it exists */
852 if (if_info->description != NULL)
853 fprintf_stderr(" (%s)", if_info->description);
855 fprintf_stderr("\n");
860 void capture_opts_trim_snaplen(capture_options *capture_opts, int snaplen_min)
863 interface_options interface_opts;
865 if (capture_opts->ifaces->len > 0) {
866 for (i = 0; i < capture_opts->ifaces->len; i++) {
867 interface_opts = g_array_index(capture_opts->ifaces, interface_options, 0);
868 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, 0);
869 if (interface_opts.snaplen < 1)
870 interface_opts.snaplen = WTAP_MAX_PACKET_SIZE;
871 else if (interface_opts.snaplen < snaplen_min)
872 interface_opts.snaplen = snaplen_min;
873 g_array_append_val(capture_opts->ifaces, interface_opts);
876 if (capture_opts->default_options.snaplen < 1)
877 capture_opts->default_options.snaplen = WTAP_MAX_PACKET_SIZE;
878 else if (capture_opts->default_options.snaplen < snaplen_min)
879 capture_opts->default_options.snaplen = snaplen_min;
884 void capture_opts_trim_ring_num_files(capture_options *capture_opts)
886 /* Check the value range of the ring_num_files parameter */
887 if (capture_opts->ring_num_files > RINGBUFFER_MAX_NUM_FILES) {
888 cmdarg_err("Too many ring buffer files (%u). Reducing to %u.\n", capture_opts->ring_num_files, RINGBUFFER_MAX_NUM_FILES);
889 capture_opts->ring_num_files = RINGBUFFER_MAX_NUM_FILES;
890 } else if (capture_opts->ring_num_files > RINGBUFFER_WARN_NUM_FILES) {
891 cmdarg_err("%u is a lot of ring buffer files.\n", capture_opts->ring_num_files);
893 #if RINGBUFFER_MIN_NUM_FILES > 0
894 else if (capture_opts->ring_num_files < RINGBUFFER_MIN_NUM_FILES)
895 cmdarg_err("Too few ring buffer files (%u). Increasing to %u.\n", capture_opts->ring_num_files, RINGBUFFER_MIN_NUM_FILES);
896 capture_opts->ring_num_files = RINGBUFFER_MIN_NUM_FILES;
901 gboolean capture_opts_trim_iface(capture_options *capture_opts, const char *capture_device)
905 /* Did the user specify an interface to use? */
906 if (capture_opts->num_selected != 0 || capture_opts->ifaces->len != 0) {
907 /* yes they did, exit immediately nothing further to do here */
911 /* No - is a default specified in the preferences file? */
912 if (capture_device != NULL) {
914 status=capture_opts_add_iface_opt(capture_opts, capture_device);
916 return TRUE; /* interface found */
918 return FALSE; /* some kind of error finding interface */
920 /* No default in preferences file, just pick the first interface from the list of interfaces. */
921 status=capture_opts_add_iface_opt(capture_opts, "1");
923 return TRUE; /* success */
925 return FALSE; /* some kind of error finding the first interface */
931 #define S_IFIFO _S_IFIFO
934 #define S_ISFIFO(mode) (((mode) & S_IFMT) == S_IFIFO)
937 /* copied from filesystem.c */
938 static int capture_opts_test_for_fifo(const char *path)
942 if (ws_stat64(path, &statb) < 0)
945 if (S_ISFIFO(statb.st_mode))
951 static gboolean capture_opts_output_to_pipe(const char *save_file, gboolean *is_pipe)
957 if (save_file != NULL) {
958 /* We're writing to a capture file. */
959 if (strcmp(save_file, "-") == 0) {
960 /* Writing to stdout. */
961 /* XXX - should we check whether it's a pipe? It's arguably
962 silly to do "-w - >output_file" rather than "-w output_file",
963 but by not checking we might be violating the Principle Of
964 Least Astonishment. */
967 /* not writing to stdout, test for a FIFO (aka named pipe) */
968 err = capture_opts_test_for_fifo(save_file);
971 case ENOENT: /* it doesn't exist, so we'll be creating it,
972 and it won't be a FIFO */
973 case 0: /* found it, but it's not a FIFO */
976 case ESPIPE: /* it is a FIFO */
980 default: /* couldn't stat it */
981 break; /* ignore: later attempt to open */
982 /* will generate a nice msg */
991 * Add all non-hidden selected interfaces in the "all interfaces" list
992 * to the list of interfaces for the capture.
995 collect_ifaces(capture_options *capture_opts)
999 interface_options interface_opts;
1001 /* Empty out the existing list of interfaces. */
1002 for (i = capture_opts->ifaces->len; i != 0; i--) {
1003 interface_opts = g_array_index(capture_opts->ifaces, interface_options, i - 1);
1004 g_free(interface_opts.name);
1005 g_free(interface_opts.descr);
1006 if(interface_opts.console_display_name!=NULL){
1007 g_free(interface_opts.console_display_name);
1009 g_free(interface_opts.cfilter);
1010 #ifdef HAVE_PCAP_REMOTE
1011 if (interface_opts.src_type == CAPTURE_IFREMOTE) {
1012 g_free(interface_opts.remote_host);
1013 g_free(interface_opts.remote_port);
1014 g_free(interface_opts.auth_username);
1015 g_free(interface_opts.auth_password);
1018 capture_opts->ifaces = g_array_remove_index(capture_opts->ifaces, i - 1);
1021 /* Now fill the list up again. */
1022 for (i = 0; i < capture_opts->all_ifaces->len; i++) {
1023 device = g_array_index(capture_opts->all_ifaces, interface_t, i);
1024 if (!device.hidden && device.selected) {
1025 interface_opts.name = g_strdup(device.name);
1026 interface_opts.descr = g_strdup(device.display_name);
1027 interface_opts.console_display_name = g_strdup(device.name);
1028 interface_opts.linktype = device.active_dlt;
1029 interface_opts.cfilter = g_strdup(device.cfilter);
1030 interface_opts.snaplen = device.snaplen;
1031 interface_opts.has_snaplen = device.has_snaplen;
1032 interface_opts.promisc_mode = device.pmode;
1033 #if defined(_WIN32) || defined(HAVE_PCAP_CREATE)
1034 interface_opts.buffer_size = device.buffer;
1036 #ifdef HAVE_PCAP_CREATE
1037 interface_opts.monitor_mode = device.monitor_mode_enabled;
1039 #ifdef HAVE_PCAP_REMOTE
1040 interface_opts.src_type = CAPTURE_IFREMOTE;
1041 interface_opts.remote_host = g_strdup(device.remote_opts.remote_host_opts.remote_host);
1042 interface_opts.remote_port = g_strdup(device.remote_opts.remote_host_opts.remote_port);
1043 interface_opts.auth_type = device.remote_opts.remote_host_opts.auth_type;
1044 interface_opts.auth_username = g_strdup(device.remote_opts.remote_host_opts.auth_username);
1045 interface_opts.auth_password = g_strdup(device.remote_opts.remote_host_opts.auth_password);
1046 interface_opts.datatx_udp = device.remote_opts.remote_host_opts.datatx_udp;
1047 interface_opts.nocap_rpcap = device.remote_opts.remote_host_opts.nocap_rpcap;
1048 interface_opts.nocap_local = device.remote_opts.remote_host_opts.nocap_local;
1050 #ifdef HAVE_PCAP_SETSAMPLING
1051 interface_opts.sampling_method = device.remote_opts.sampling_method;
1052 interface_opts.sampling_param = device.remote_opts.sampling_param;
1054 g_array_append_val(capture_opts->ifaces, interface_opts);
1062 #endif /* HAVE_LIBPCAP */