2 * protohierstat 2002 Ronnie Sahlberg
6 * Wireshark - Network traffic analyzer
7 * By Gerald Combs <gerald@wireshark.org>
8 * Copyright 1998 Gerald Combs
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version 2
13 * of the License, or (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
25 /* This module provides ProtocolHierarchyStatistics for tshark */
33 #ifdef HAVE_SYS_TYPES_H
34 # include <sys/types.h>
38 #include "epan/packet_info.h"
39 #include "epan/epan_dissect.h"
40 #include "epan/proto.h"
42 #include <epan/stat_cmd_args.h>
44 typedef struct _phs_t {
45 struct _phs_t *sibling;
47 struct _phs_t *parent;
50 const char *proto_name;
57 new_phs_t(phs_t *parent)
60 rs=g_malloc(sizeof(phs_t));
74 protohierstat_packet(void *prs, packet_info *pinfo, epan_dissect_t *edt, const void *dummy _U_)
87 if(!edt->tree->first_child){
91 for(node=edt->tree->first_child;node;node=node->next){
94 /* first time we saw a protocol at this leaf */
96 rs->protocol=fi->hfinfo->id;
97 rs->proto_name=fi->hfinfo->abbrev;
99 rs->bytes=pinfo->fd->pkt_len;
100 rs->child=new_phs_t(rs);
105 /* find this protocol in the list of siblings */
106 for(tmprs=rs;tmprs;tmprs=tmprs->sibling){
107 if(tmprs->protocol==fi->hfinfo->id){
112 /* not found, then we must add it to the end of the list */
114 for(tmprs=rs;tmprs->sibling;tmprs=tmprs->sibling)
116 tmprs->sibling=new_phs_t(rs->parent);
118 rs->protocol=fi->hfinfo->id;
119 rs->proto_name=fi->hfinfo->abbrev;
125 rs->bytes+=pinfo->fd->pkt_len;
128 rs->child=new_phs_t(rs);
136 phs_draw(phs_t *rs, int indentation)
139 #define MAXPHSLINE 80
140 char str[MAXPHSLINE];
141 for(;rs;rs=rs->sibling){
142 if(rs->protocol==-1){
147 for(i=0;i<indentation;i++){
149 stroff+=g_snprintf(str+stroff, MAXPHSLINE-stroff, "...");
152 stroff+=g_snprintf(str+stroff, MAXPHSLINE-stroff, " ");
154 g_snprintf(str+stroff, MAXPHSLINE-stroff, "%s", rs->proto_name);
155 printf("%-40s frames:%d bytes:%" G_GINT64_MODIFIER "d\n",str, rs->frames, rs->bytes);
156 phs_draw(rs->child, indentation+1);
161 protohierstat_draw(void *prs)
166 printf("===================================================================\n");
167 printf("Protocol Hierarchy Statistics\n");
168 printf("Filter: %s\n\n",rs->filter?rs->filter:"");
170 printf("===================================================================\n");
175 protohierstat_init(const char *optarg, void* userdata _U_)
179 const char *filter=NULL;
180 GString *error_string;
182 if(strcmp("io,phs",optarg)==0){
184 } else if(sscanf(optarg,"io,phs,%n",&pos)==0){
189 fprintf(stderr, "tshark: invalid \"-z io,phs[,<filter>]\" argument\n");
196 rs->filter=g_strdup(filter);
201 error_string=register_tap_listener("frame", rs, filter, TL_REQUIRES_PROTO_TREE, NULL, protohierstat_packet, protohierstat_draw);
203 /* error, we failed to attach to the tap. clean up */
207 fprintf(stderr, "tshark: Couldn't register io,phs tap: %s\n",
209 g_string_free(error_string, TRUE);
216 register_tap_listener_protohierstat(void)
218 register_stat_cmd_arg("io,phs", protohierstat_init, NULL);