1 /* Reorder the frames from an input dump file, and write to output dump file.
2 * Martin Mathieson and Jakub Jawadzki
4 * Wireshark - Network traffic analyzer
5 * By Gerald Combs <gerald@wireshark.org>
6 * Copyright 1998 Gerald Combs
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License along
19 * with this program; if not, write to the Free Software Foundation, Inc.,
20 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
36 #include <zlib.h> /* to get the libz version number */
39 #include <wiretap/wtap.h>
41 #ifndef HAVE_GETOPT_LONG
42 #include "wsutil/wsgetopt.h"
45 #include <wsutil/crash_info.h>
46 #include <wsutil/filesystem.h>
47 #include <wsutil/file_util.h>
48 #include <wsutil/privileges.h>
49 #include <wsutil/ws_diag_control.h>
50 #include <wsutil/ws_version_info.h>
51 #include <wiretap/wtap_opttypes.h>
54 #include <wsutil/plugins.h>
57 #include <wsutil/report_err.h>
59 /* Show command-line usage */
61 print_usage(FILE *output)
63 fprintf(output, "\n");
64 fprintf(output, "Usage: reordercap [options] <infile> <outfile>\n");
65 fprintf(output, "\n");
66 fprintf(output, "Options:\n");
67 fprintf(output, " -n don't write to output file if the input file is ordered.\n");
68 fprintf(output, " -h display this help and exit.\n");
71 /* Remember where this frame was in the file */
72 typedef struct FrameRecord_t {
80 /**************************************************/
83 /* Enable this symbol to see debug output */
84 /* #define REORDER_DEBUG */
87 #define DEBUG_PRINT printf
89 #define DEBUG_PRINT(...)
91 /**************************************************/
95 frame_write(FrameRecord_t *frame, wtap *wth, wtap_dumper *pdh,
96 struct wtap_pkthdr *phdr, Buffer *buf, const char *infile)
101 DEBUG_PRINT("\nDumping frame (offset=%" G_GINT64_MODIFIER "u)\n",
105 /* Re-read the frame from the stored location */
106 if (!wtap_seek_read(wth, frame->offset, phdr, buf, &err, &err_info)) {
108 /* Print a message noting that the read failed somewhere along the line. */
110 "reordercap: An error occurred while re-reading \"%s\": %s.\n",
111 infile, wtap_strerror(err));
112 if (err_info != NULL) {
113 fprintf(stderr, "(%s)\n", err_info);
120 /* Copy, and set length and timestamp from item. */
121 /* TODO: remove when wtap_seek_read() fills in phdr,
122 including time stamps, for all file types */
123 phdr->ts = frame->frame_time;
125 /* Dump frame to outfile */
126 if (!wtap_dump(pdh, phdr, ws_buffer_start_ptr(buf), &err, &err_info)) {
127 fprintf(stderr, "reordercap: Error (%s) writing frame to outfile\n",
129 if (err_info != NULL) {
130 fprintf(stderr, "(%s)\n", err_info);
137 /* Comparing timestamps between 2 frames.
138 negative if (t1 < t2)
140 positive if (t1 > t2)
143 frames_compare(gconstpointer a, gconstpointer b)
145 const FrameRecord_t *frame1 = *(const FrameRecord_t *const *) a;
146 const FrameRecord_t *frame2 = *(const FrameRecord_t *const *) b;
148 const nstime_t *time1 = &frame1->frame_time;
149 const nstime_t *time2 = &frame2->frame_time;
151 return nstime_cmp(time1, time2);
155 get_reordercap_compiled_info(GString *str)
158 g_string_append(str, ", ");
160 g_string_append(str, "with libz ");
162 g_string_append(str, ZLIB_VERSION);
163 #else /* ZLIB_VERSION */
164 g_string_append(str, "(version unknown)");
165 #endif /* ZLIB_VERSION */
166 #else /* HAVE_LIBZ */
167 g_string_append(str, "without libz");
168 #endif /* HAVE_LIBZ */
172 get_reordercap_runtime_info(
173 #if defined(HAVE_LIBZ) && !defined(_WIN32)
180 #if defined(HAVE_LIBZ) && !defined(_WIN32)
181 g_string_append_printf(str, ", with libz %s", zlibVersion());
187 * Don't report failures to load plugins because most (non-wiretap) plugins
188 * *should* fail to load (because we're not linked against libwireshark and
189 * dissector plugins need libwireshark).
192 failure_message(const char *msg_format _U_, va_list ap _U_)
198 /********************************************************************/
200 /********************************************************************/
202 main(int argc, char *argv[])
204 GString *comp_info_str;
205 GString *runtime_info_str;
207 wtap_dumper *pdh = NULL;
208 struct wtap_pkthdr dump_phdr;
213 const struct wtap_pkthdr *phdr;
214 guint wrong_order_count = 0;
215 gboolean write_output_regardless = TRUE;
217 wtap_optionblock_t shb_hdr = NULL;
218 wtapng_iface_descriptions_t *idb_inf = NULL;
219 wtap_optionblock_t nrb_hdr = NULL;
222 FrameRecord_t *prevFrame = NULL;
225 static const struct option long_options[] = {
226 {"help", no_argument, NULL, 'h'},
227 {"version", no_argument, NULL, 'v'},
235 char *init_progfile_dir_error;
238 /* Get the compile-time version information string */
239 comp_info_str = get_compiled_version_info(NULL, get_reordercap_compiled_info);
241 /* Get the run-time version information string */
242 runtime_info_str = get_runtime_version_info(get_reordercap_runtime_info);
244 /* Add it to the information to be reported on a crash. */
245 ws_add_crash_info("Reordercap (Wireshark) %s\n"
250 get_ws_vcs_version_info(), comp_info_str->str, runtime_info_str->str);
253 * Get credential information for later use.
255 init_process_policies();
256 init_open_routines();
259 /* Register wiretap plugins */
260 if ((init_progfile_dir_error = init_progfile_dir(argv[0], main))) {
261 g_warning("reordercap: init_progfile_dir(): %s", init_progfile_dir_error);
262 g_free(init_progfile_dir_error);
264 /* Register all the plugin types we have. */
265 wtap_register_plugin_types(); /* Types known to libwiretap */
267 init_report_err(failure_message,NULL,NULL,NULL);
269 /* Scan for plugins. This does *not* call their registration routines;
270 that's done later. */
273 /* Register all libwiretap plugin modules. */
274 register_all_wiretap_modules();
278 /* Process the options first */
279 while ((opt = getopt_long(argc, argv, "hnv", long_options, NULL)) != -1) {
282 write_output_regardless = FALSE;
285 printf("Reordercap (Wireshark) %s\n"
286 "Reorder timestamps of input file frames into output file.\n"
287 "See https://www.wireshark.org for more information.\n",
288 get_ws_vcs_version_info());
292 show_version("Reordercap (Wireshark)", comp_info_str, runtime_info_str);
293 g_string_free(comp_info_str, TRUE);
294 g_string_free(runtime_info_str, TRUE);
302 /* Remaining args are file names */
303 file_count = argc - optind;
304 if (file_count == 2) {
305 infile = argv[optind];
306 outfile = argv[optind+1];
314 /* TODO: if reordercap is ever changed to give the user a choice of which
315 open_routine reader to use, then the following needs to change. */
316 wth = wtap_open_offline(infile, WTAP_TYPE_AUTO, &err, &err_info, TRUE);
318 fprintf(stderr, "reordercap: Can't open %s: %s\n", infile,
320 if (err_info != NULL) {
321 fprintf(stderr, "(%s)\n", err_info);
326 DEBUG_PRINT("file_type_subtype is %d\n", wtap_file_type_subtype(wth));
328 shb_hdr = wtap_file_get_shb_for_new_file(wth);
329 idb_inf = wtap_file_get_idb_info(wth);
330 nrb_hdr = wtap_file_get_nrb_for_new_file(wth);
332 /* Open outfile (same filetype/encap as input file) */
333 if (strcmp(outfile, "-") == 0) {
334 pdh = wtap_dump_open_stdout_ng(wtap_file_type_subtype(wth), wtap_file_encap(wth),
335 65535, FALSE, shb_hdr, idb_inf, nrb_hdr, &err);
336 outfile = "standard output";
338 pdh = wtap_dump_open_ng(outfile, wtap_file_type_subtype(wth), wtap_file_encap(wth),
339 65535, FALSE, shb_hdr, idb_inf, nrb_hdr, &err);
345 fprintf(stderr, "reordercap: Failed to open output file: (%s) - error %s\n",
346 outfile, wtap_strerror(err));
347 wtap_optionblock_free(shb_hdr);
348 wtap_optionblock_free(nrb_hdr);
352 /* Allocate the array of frame pointers. */
353 frames = g_ptr_array_new();
355 /* Read each frame from infile */
356 while (wtap_read(wth, &err, &err_info, &data_offset)) {
357 FrameRecord_t *newFrameRecord;
359 phdr = wtap_phdr(wth);
361 newFrameRecord = g_slice_new(FrameRecord_t);
362 newFrameRecord->num = frames->len + 1;
363 newFrameRecord->offset = data_offset;
364 if (phdr->presence_flags & WTAP_HAS_TS) {
365 newFrameRecord->frame_time = phdr->ts;
367 nstime_set_unset(&newFrameRecord->frame_time);
370 if (prevFrame && frames_compare(&newFrameRecord, &prevFrame) < 0) {
374 g_ptr_array_add(frames, newFrameRecord);
375 prevFrame = newFrameRecord;
378 /* Print a message noting that the read failed somewhere along the line. */
380 "reordercap: An error occurred while reading \"%s\": %s.\n",
381 infile, wtap_strerror(err));
382 if (err_info != NULL) {
383 fprintf(stderr, "(%s)\n", err_info);
388 printf("%u frames, %u out of order\n", frames->len, wrong_order_count);
390 /* Sort the frames */
391 if (wrong_order_count > 0) {
392 g_ptr_array_sort(frames, frames_compare);
395 /* Write out each sorted frame in turn */
396 wtap_phdr_init(&dump_phdr);
397 ws_buffer_init(&buf, 1500);
398 for (i = 0; i < frames->len; i++) {
399 FrameRecord_t *frame = (FrameRecord_t *)frames->pdata[i];
401 /* Avoid writing if already sorted and configured to */
402 if (write_output_regardless || (wrong_order_count > 0)) {
403 frame_write(frame, wth, pdh, &dump_phdr, &buf, infile);
405 g_slice_free(FrameRecord_t, frame);
407 wtap_phdr_cleanup(&dump_phdr);
408 ws_buffer_free(&buf);
410 if (!write_output_regardless && (wrong_order_count == 0)) {
411 printf("Not writing output file because input file is already in order!\n");
414 /* Free the whole array */
415 g_ptr_array_free(frames, TRUE);
418 if (!wtap_dump_close(pdh, &err)) {
419 fprintf(stderr, "reordercap: Error closing %s: %s\n", outfile,
421 wtap_optionblock_free(shb_hdr);
422 wtap_optionblock_free(nrb_hdr);
425 wtap_optionblock_free(shb_hdr);
426 wtap_optionblock_free(nrb_hdr);
428 /* Finally, close infile */
435 * Editor modelines - http://www.wireshark.org/tools/modelines.html
440 * indent-tabs-mode: nil
443 * vi: set shiftwidth=4 tabstop=8 expandtab:
444 * :indentSize=4:tabSize=8:noTabs=true: