1 /* Reorder the frames from an input dump file, and write to output dump file.
2 * Martin Mathieson and Jakub Jawadzki
4 * Wireshark - Network traffic analyzer
5 * By Gerald Combs <gerald@wireshark.org>
6 * Copyright 1998 Gerald Combs
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License along
19 * with this program; if not, write to the Free Software Foundation, Inc.,
20 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
35 #include <wiretap/wtap.h>
37 #ifndef HAVE_GETOPT_LONG
38 #include "wsutil/wsgetopt.h"
41 #include <wsutil/cmdarg_err.h>
42 #include <wsutil/crash_info.h>
43 #include <wsutil/filesystem.h>
44 #include <wsutil/file_util.h>
45 #include <wsutil/privileges.h>
46 #include <version_info.h>
47 #include <wiretap/wtap_opttypes.h>
50 #include <wsutil/plugins.h>
53 #include <wsutil/report_message.h>
55 #include "ui/failure_message.h"
57 #define INVALID_OPTION 1
59 #define OUTPUT_FILE_ERROR 1
61 /* Show command-line usage */
63 print_usage(FILE *output)
65 fprintf(output, "\n");
66 fprintf(output, "Usage: reordercap [options] <infile> <outfile>\n");
67 fprintf(output, "\n");
68 fprintf(output, "Options:\n");
69 fprintf(output, " -n don't write to output file if the input file is ordered.\n");
70 fprintf(output, " -h display this help and exit.\n");
73 /* Remember where this frame was in the file */
74 typedef struct FrameRecord_t {
82 /**************************************************/
85 /* Enable this symbol to see debug output */
86 /* #define REORDER_DEBUG */
89 #define DEBUG_PRINT printf
91 #define DEBUG_PRINT(...)
93 /**************************************************/
97 frame_write(FrameRecord_t *frame, wtap *wth, wtap_dumper *pdh,
98 struct wtap_pkthdr *phdr, Buffer *buf, const char *infile,
104 DEBUG_PRINT("\nDumping frame (offset=%" G_GINT64_MODIFIER "u)\n",
108 /* Re-read the frame from the stored location */
109 if (!wtap_seek_read(wth, frame->offset, phdr, buf, &err, &err_info)) {
111 /* Print a message noting that the read failed somewhere along the line. */
113 "reordercap: An error occurred while re-reading \"%s\".\n",
115 cfile_read_failure_message("reordercap", infile, err, err_info);
120 /* Copy, and set length and timestamp from item. */
121 /* TODO: remove when wtap_seek_read() fills in phdr,
122 including time stamps, for all file types */
123 phdr->ts = frame->frame_time;
125 /* Dump frame to outfile */
126 if (!wtap_dump(pdh, phdr, ws_buffer_start_ptr(buf), &err, &err_info)) {
127 cfile_write_failure_message("reordercap", infile, outfile, err,
128 err_info, frame->num,
129 wtap_file_type_subtype(wth));
134 /* Comparing timestamps between 2 frames.
135 negative if (t1 < t2)
137 positive if (t1 > t2)
140 frames_compare(gconstpointer a, gconstpointer b)
142 const FrameRecord_t *frame1 = *(const FrameRecord_t *const *) a;
143 const FrameRecord_t *frame2 = *(const FrameRecord_t *const *) b;
145 const nstime_t *time1 = &frame1->frame_time;
146 const nstime_t *time2 = &frame2->frame_time;
148 return nstime_cmp(time1, time2);
152 * General errors and warnings are reported with an console message
156 failure_warning_message(const char *msg_format, va_list ap)
158 fprintf(stderr, "reordercap: ");
159 vfprintf(stderr, msg_format, ap);
160 fprintf(stderr, "\n");
164 * Report additional information for an error in command-line arguments.
167 failure_message_cont(const char *msg_format, va_list ap)
169 vfprintf(stderr, msg_format, ap);
170 fprintf(stderr, "\n");
173 /********************************************************************/
175 /********************************************************************/
177 main(int argc, char *argv[])
179 GString *comp_info_str;
180 GString *runtime_info_str;
181 char *init_progfile_dir_error;
183 wtap_dumper *pdh = NULL;
184 struct wtap_pkthdr dump_phdr;
189 const struct wtap_pkthdr *phdr;
190 guint wrong_order_count = 0;
191 gboolean write_output_regardless = TRUE;
193 GArray *shb_hdrs = NULL;
194 wtapng_iface_descriptions_t *idb_inf = NULL;
195 GArray *nrb_hdrs = NULL;
196 int ret = EXIT_SUCCESS;
199 FrameRecord_t *prevFrame = NULL;
202 static const struct option long_options[] = {
203 {"help", no_argument, NULL, 'h'},
204 {"version", no_argument, NULL, 'v'},
211 cmdarg_err_init(failure_warning_message, failure_message_cont);
213 /* Get the compile-time version information string */
214 comp_info_str = get_compiled_version_info(NULL, NULL);
216 /* Get the run-time version information string */
217 runtime_info_str = get_runtime_version_info(NULL);
219 /* Add it to the information to be reported on a crash. */
220 ws_add_crash_info("Reordercap (Wireshark) %s\n"
225 get_ws_vcs_version_info(), comp_info_str->str, runtime_info_str->str);
226 g_string_free(comp_info_str, TRUE);
227 g_string_free(runtime_info_str, TRUE);
230 * Get credential information for later use.
232 init_process_policies();
235 * Attempt to get the pathname of the directory containing the
238 init_progfile_dir_error = init_progfile_dir(argv[0], main);
239 if (init_progfile_dir_error != NULL) {
241 "reordercap: Can't get pathname of directory containing the reordercap program: %s.\n",
242 init_progfile_dir_error);
243 g_free(init_progfile_dir_error);
249 /* Register wiretap plugins */
250 init_report_message(failure_warning_message, failure_warning_message,
253 /* Scan for plugins. This does *not* call their registration routines;
256 Don't report failures to load plugins because most (non-wiretap)
257 plugins *should* fail to load (because we're not linked against
258 libwireshark and dissector plugins need libwireshark). */
259 scan_plugins(DONT_REPORT_LOAD_FAILURE);
261 /* Register all libwiretap plugin modules. */
262 register_all_wiretap_modules();
265 /* Process the options first */
266 while ((opt = getopt_long(argc, argv, "hnv", long_options, NULL)) != -1) {
269 write_output_regardless = FALSE;
272 printf("Reordercap (Wireshark) %s\n"
273 "Reorder timestamps of input file frames into output file.\n"
274 "See https://www.wireshark.org for more information.\n",
275 get_ws_vcs_version_info());
279 comp_info_str = get_compiled_version_info(NULL, NULL);
280 runtime_info_str = get_runtime_version_info(NULL);
281 show_version("Reordercap (Wireshark)", comp_info_str, runtime_info_str);
282 g_string_free(comp_info_str, TRUE);
283 g_string_free(runtime_info_str, TRUE);
287 ret = INVALID_OPTION;
292 /* Remaining args are file names */
293 file_count = argc - optind;
294 if (file_count == 2) {
295 infile = argv[optind];
296 outfile = argv[optind+1];
300 ret = INVALID_OPTION;
305 /* TODO: if reordercap is ever changed to give the user a choice of which
306 open_routine reader to use, then the following needs to change. */
307 wth = wtap_open_offline(infile, WTAP_TYPE_AUTO, &err, &err_info, TRUE);
309 cfile_open_failure_message("reordercap", infile, err, err_info);
313 DEBUG_PRINT("file_type_subtype is %d\n", wtap_file_type_subtype(wth));
315 shb_hdrs = wtap_file_get_shb_for_new_file(wth);
316 idb_inf = wtap_file_get_idb_info(wth);
317 nrb_hdrs = wtap_file_get_nrb_for_new_file(wth);
319 /* Open outfile (same filetype/encap as input file) */
320 if (strcmp(outfile, "-") == 0) {
321 pdh = wtap_dump_open_stdout_ng(wtap_file_type_subtype(wth), wtap_file_encap(wth),
322 wtap_snapshot_length(wth), FALSE, shb_hdrs, idb_inf, nrb_hdrs, &err);
324 pdh = wtap_dump_open_ng(outfile, wtap_file_type_subtype(wth), wtap_file_encap(wth),
325 wtap_snapshot_length(wth), FALSE, shb_hdrs, idb_inf, nrb_hdrs, &err);
331 cfile_dump_open_failure_message("reordercap", outfile, err,
332 wtap_file_type_subtype(wth));
333 wtap_block_array_free(shb_hdrs);
334 wtap_block_array_free(nrb_hdrs);
335 ret = OUTPUT_FILE_ERROR;
339 /* Allocate the array of frame pointers. */
340 frames = g_ptr_array_new();
342 /* Read each frame from infile */
343 while (wtap_read(wth, &err, &err_info, &data_offset)) {
344 FrameRecord_t *newFrameRecord;
346 phdr = wtap_phdr(wth);
348 newFrameRecord = g_slice_new(FrameRecord_t);
349 newFrameRecord->num = frames->len + 1;
350 newFrameRecord->offset = data_offset;
351 if (phdr->presence_flags & WTAP_HAS_TS) {
352 newFrameRecord->frame_time = phdr->ts;
354 nstime_set_unset(&newFrameRecord->frame_time);
357 if (prevFrame && frames_compare(&newFrameRecord, &prevFrame) < 0) {
361 g_ptr_array_add(frames, newFrameRecord);
362 prevFrame = newFrameRecord;
365 /* Print a message noting that the read failed somewhere along the line. */
366 cfile_read_failure_message("reordercap", infile, err, err_info);
369 printf("%u frames, %u out of order\n", frames->len, wrong_order_count);
371 /* Sort the frames */
372 if (wrong_order_count > 0) {
373 g_ptr_array_sort(frames, frames_compare);
376 /* Write out each sorted frame in turn */
377 wtap_phdr_init(&dump_phdr);
378 ws_buffer_init(&buf, 1500);
379 for (i = 0; i < frames->len; i++) {
380 FrameRecord_t *frame = (FrameRecord_t *)frames->pdata[i];
382 /* Avoid writing if already sorted and configured to */
383 if (write_output_regardless || (wrong_order_count > 0)) {
384 frame_write(frame, wth, pdh, &dump_phdr, &buf, infile, outfile);
386 g_slice_free(FrameRecord_t, frame);
388 wtap_phdr_cleanup(&dump_phdr);
389 ws_buffer_free(&buf);
391 if (!write_output_regardless && (wrong_order_count == 0)) {
392 printf("Not writing output file because input file is already in order.\n");
395 /* Free the whole array */
396 g_ptr_array_free(frames, TRUE);
399 if (!wtap_dump_close(pdh, &err)) {
400 cfile_close_failure_message(outfile, err);
401 wtap_block_array_free(shb_hdrs);
402 wtap_block_array_free(nrb_hdrs);
403 ret = OUTPUT_FILE_ERROR;
406 wtap_block_array_free(shb_hdrs);
407 wtap_block_array_free(nrb_hdrs);
409 /* Finally, close infile and release resources. */
422 * Editor modelines - http://www.wireshark.org/tools/modelines.html
427 * indent-tabs-mode: nil
430 * vi: set shiftwidth=4 tabstop=8 expandtab:
431 * :indentSize=4:tabSize=8:noTabs=true: