2 * protohierstat 2002 Ronnie Sahlberg
6 * Wireshark - Network traffic analyzer
7 * By Gerald Combs <gerald@wireshark.org>
8 * Copyright 1998 Gerald Combs
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version 2
13 * of the License, or (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
25 /* This module provides ProtocolHierarchyStatistics for tshark */
33 #ifdef HAVE_SYS_TYPES_H
34 # include <sys/types.h>
38 #include "epan/packet_info.h"
39 #include "epan/epan_dissect.h"
40 #include "epan/proto.h"
42 #include <epan/stat_cmd_args.h>
45 typedef struct _phs_t {
46 struct _phs_t *sibling;
48 struct _phs_t *parent;
51 const char *proto_name;
58 new_phs_t(phs_t *parent)
61 rs=g_malloc(sizeof(phs_t));
75 protohierstat_packet(void *prs, packet_info *pinfo, epan_dissect_t *edt, const void *dummy _U_)
88 if(!edt->tree->first_child){
92 for(tree=edt->tree->first_child;tree;tree=tree->next){
95 /* first time we saw a protocol at this leaf */
97 rs->protocol=fi->hfinfo->id;
98 rs->proto_name=fi->hfinfo->abbrev;
100 rs->bytes=pinfo->fd->pkt_len;
101 rs->child=new_phs_t(rs);
106 /* find this protocol in the list of siblings */
107 for(tmprs=rs;tmprs;tmprs=tmprs->sibling){
108 if(tmprs->protocol==fi->hfinfo->id){
113 /* not found, then we must add it to the end of the list */
115 for(tmprs=rs;tmprs->sibling;tmprs=tmprs->sibling)
117 tmprs->sibling=new_phs_t(rs->parent);
119 rs->protocol=fi->hfinfo->id;
120 rs->proto_name=fi->hfinfo->abbrev;
126 rs->bytes+=pinfo->fd->pkt_len;
129 rs->child=new_phs_t(rs);
137 phs_draw(phs_t *rs, int indentation)
140 #define MAXPHSLINE 80
141 char str[MAXPHSLINE];
142 for(;rs;rs=rs->sibling){
143 if(rs->protocol==-1){
148 for(i=0;i<indentation;i++){
150 stroff+=g_snprintf(str+stroff, MAXPHSLINE-stroff, "...");
153 stroff+=g_snprintf(str+stroff, MAXPHSLINE-stroff, " ");
155 stroff+=g_snprintf(str+stroff, MAXPHSLINE-stroff, rs->proto_name);
156 printf("%-40s frames:%d bytes:%" G_GINT64_MODIFIER "d\n",str, rs->frames, rs->bytes);
157 phs_draw(rs->child, indentation+1);
162 protohierstat_draw(void *prs)
167 printf("===================================================================\n");
168 printf("Protocol Hierarchy Statistics\n");
169 printf("Filter: %s\n\n",rs->filter?rs->filter:"");
171 printf("===================================================================\n");
176 protohierstat_init(const char *optarg, void* userdata _U_)
180 const char *filter=NULL;
181 GString *error_string;
183 if(!strcmp("io,phs",optarg)){
185 } else if(sscanf(optarg,"io,phs,%n",&pos)==0){
189 /* We must use a filter to guarantee that edt->tree
190 will be populated. "frame" matches everything so
191 that one is used instead of no filter.
196 fprintf(stderr, "tshark: invalid \"-z io,phs[,<filter>]\" argument\n");
203 rs->filter=g_strdup(filter);
208 error_string=register_tap_listener("frame", rs, filter, NULL, protohierstat_packet, protohierstat_draw);
210 /* error, we failed to attach to the tap. clean up */
214 fprintf(stderr, "tshark: Couldn't register io,phs tap: %s\n",
216 g_string_free(error_string, TRUE);
223 register_tap_listener_protohierstat(void)
225 register_stat_cmd_arg("io,phs", protohierstat_init, NULL);