2 * Routines for packet capture windows
4 * $Id: capture.c,v 1.7 1998/10/13 07:03:31 guy Exp $
6 * Ethereal - Network traffic analyzer
7 * By Gerald Combs <gerald@zing.org>
8 * Copyright 1998 Gerald Combs
11 * This program is free software; you can redistribute it and/or
12 * modify it under the terms of the GNU General Public License
13 * as published by the Free Software Foundation; either version 2
14 * of the License, or (at your option) any later version.
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
21 * You should have received a copy of the GNU General Public License
22 * along with this program; if not, write to the Free Software
23 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
31 #ifdef HAVE_SYS_TYPES_H
32 # include <sys/types.h>
40 #include <sys/socket.h>
41 #include <sys/ioctl.h>
44 #ifdef NEED_SNPRINTF_H
50 # include "snprintf.h"
53 #ifdef HAVE_SYS_SOCKIO_H
54 # include <sys/sockio.h>
65 extern capture_file cf;
66 extern GtkWidget *info_bar;
67 extern guint file_ctx;
69 /* File selection data keys */
70 #define E_CAP_PREP_FS_KEY "cap_prep_fs"
71 #define E_CAP_PREP_TE_KEY "cap_prep_te"
73 /* Capture callback data keys */
74 #define E_CAP_IFACE_KEY "cap_iface"
75 #define E_CAP_FILT_KEY "cap_filter"
76 #define E_CAP_FILE_KEY "cap_file"
77 #define E_CAP_COUNT_KEY "cap_count"
78 #define E_CAP_OPEN_KEY "cap_open"
79 #define E_CAP_SNAP_KEY "cap_snap"
81 /* Capture filter key */
82 #define E_CAP_FILT_TE_KEY "cap_filt_te"
85 get_interface_list() {
87 struct ifreq *ifr, *last;
89 int sock = socket(AF_INET, SOCK_DGRAM, 0);
93 simple_dialog(ESD_TYPE_WARN, NULL,
94 "Can't list interfaces: error opening socket.");
98 /* Since we have to grab the interface list all at once, we'll make
100 ifc.ifc_len = 1024 * sizeof(struct ifreq);
101 ifc.ifc_buf = malloc(ifc.ifc_len);
103 if (ioctl(sock, SIOCGIFCONF, &ifc) < 0 ||
104 ifc.ifc_len < sizeof(struct ifreq))
106 simple_dialog(ESD_TYPE_WARN, NULL,
107 "Can't list interfaces: ioctl error.");
111 ifr = (struct ifreq *) ifc.ifc_req;
112 last = (struct ifreq *) ((char *) ifr + ifc.ifc_len);
117 * - Interfaces that are up, and not loopback
118 * - IP interfaces (do we really need this?)
119 * - Anything that doesn't begin with "lo" (loopback again) or "dummy"
120 * - Anything that doesn't include a ":" (Solaris virtuals)
122 if (! (ifr->ifr_flags & (IFF_UP | IFF_LOOPBACK)) &&
123 (ifr->ifr_addr.sa_family == AF_INET) &&
124 strncmp(ifr->ifr_name, "lo", 2) &&
125 strncmp(ifr->ifr_name, "dummy", 5) &&
126 ! strchr(ifr->ifr_name, ':')) {
127 il = g_list_append(il, g_strdup(ifr->ifr_name));
129 #ifdef HAVE_SOCKADDR_SA_LEN
130 ifr = (struct ifreq *) ((char *) ifr + ifr->ifr_addr.sa_len + IFNAMSIZ);
132 ifr = (struct ifreq *) ((char *) ifr + sizeof(struct ifreq));
141 capture_prep_cb(GtkWidget *w, gpointer d) {
142 GtkWidget *cap_open_w, *if_cb, *if_lb, *file_te, *file_bt,
143 *count_lb, *count_cb, *main_vb, *if_hb, *count_hb,
144 *filter_hb, *filter_bt, *filter_te, *file_hb, *caplen_hb,
145 *bbox, *ok_bt, *cancel_bt, *capfile_ck, *snap_lb,
148 GList *if_list, *count_list = NULL;
149 gchar *count_item1 = "0 (Infinite)", count_item2[16];
151 cap_open_w = gtk_window_new(GTK_WINDOW_TOPLEVEL);
152 gtk_window_set_title(GTK_WINDOW(cap_open_w), "Ethereal: Capture Preferences");
154 /* Container for each row of widgets */
155 main_vb = gtk_vbox_new(FALSE, 3);
156 gtk_container_border_width(GTK_CONTAINER(main_vb), 5);
157 gtk_container_add(GTK_CONTAINER(cap_open_w), main_vb);
158 gtk_widget_show(main_vb);
161 if_hb = gtk_hbox_new(FALSE, 3);
162 gtk_container_add(GTK_CONTAINER(main_vb), if_hb);
163 gtk_widget_show(if_hb);
165 if_lb = gtk_label_new("Interface:");
166 gtk_box_pack_start(GTK_BOX(if_hb), if_lb, FALSE, FALSE, 0);
167 gtk_widget_show(if_lb);
169 if_list = get_interface_list();
171 if_cb = gtk_combo_new();
172 gtk_combo_set_popdown_strings(GTK_COMBO(if_cb), if_list);
174 gtk_entry_set_text(GTK_ENTRY(GTK_COMBO(if_cb)->entry), cf.iface);
176 gtk_entry_set_text(GTK_ENTRY(GTK_COMBO(if_cb)->entry), if_list->data);
177 gtk_box_pack_start(GTK_BOX(if_hb), if_cb, FALSE, FALSE, 0);
178 gtk_widget_show(if_cb);
181 g_free(if_list->data);
182 if_list = g_list_remove_link(if_list, if_list);
186 count_hb = gtk_hbox_new(FALSE, 3);
187 gtk_container_add(GTK_CONTAINER(main_vb), count_hb);
188 gtk_widget_show(count_hb);
190 count_lb = gtk_label_new("Count:");
191 gtk_box_pack_start(GTK_BOX(count_hb), count_lb, FALSE, FALSE, 0);
192 gtk_widget_show(count_lb);
195 snprintf(count_item2, 15, "%d", cf.count);
196 count_list = g_list_append(count_list, count_item2);
198 count_list = g_list_append(count_list, count_item1);
200 count_cb = gtk_combo_new();
201 gtk_combo_set_popdown_strings(GTK_COMBO(count_cb), count_list);
202 gtk_box_pack_start(GTK_BOX(count_hb), count_cb, FALSE, FALSE, 0);
203 gtk_widget_show(count_cb);
206 count_list = g_list_remove_link(count_list, count_list);
209 filter_hb = gtk_hbox_new(FALSE, 3);
210 gtk_container_add(GTK_CONTAINER(main_vb), filter_hb);
211 gtk_widget_show(filter_hb);
213 filter_bt = gtk_button_new_with_label("Filter:");
214 gtk_signal_connect(GTK_OBJECT(filter_bt), "clicked",
215 GTK_SIGNAL_FUNC(prefs_cb), (gpointer) E_PR_PG_FILTER);
216 gtk_box_pack_start(GTK_BOX(filter_hb), filter_bt, FALSE, TRUE, 0);
217 gtk_widget_show(filter_bt);
219 filter_te = gtk_entry_new();
220 if (cf.cfilter) gtk_entry_set_text(GTK_ENTRY(filter_te), cf.cfilter);
221 gtk_object_set_data(GTK_OBJECT(filter_bt), E_FILT_TE_PTR_KEY, filter_te);
222 gtk_box_pack_start(GTK_BOX(filter_hb), filter_te, TRUE, TRUE, 0);
223 gtk_widget_show(filter_te);
225 /* File row: File: button and text entry */
226 file_hb = gtk_hbox_new(FALSE, 3);
227 gtk_container_add(GTK_CONTAINER(main_vb), file_hb);
228 gtk_widget_show(file_hb);
230 file_bt = gtk_button_new_with_label("File:");
231 gtk_box_pack_start(GTK_BOX(file_hb), file_bt, FALSE, FALSE, 0);
232 gtk_widget_show(file_bt);
234 file_te = gtk_entry_new();
236 gtk_entry_set_text(GTK_ENTRY(file_te), cf.save_file);
237 gtk_box_pack_start(GTK_BOX(file_hb), file_te, TRUE, TRUE, 0);
238 gtk_widget_show(file_te);
240 gtk_signal_connect_object(GTK_OBJECT(file_bt), "clicked",
241 GTK_SIGNAL_FUNC(capture_prep_file_cb), GTK_OBJECT(file_te));
243 /* Misc row: Capture file checkbox and snap spinbutton */
244 caplen_hb = gtk_hbox_new(FALSE, 3);
245 gtk_container_add(GTK_CONTAINER(main_vb), caplen_hb);
246 gtk_widget_show(caplen_hb);
248 capfile_ck = gtk_check_button_new_with_label("Open file after capture");
249 gtk_toggle_button_set_state(GTK_TOGGLE_BUTTON(capfile_ck), TRUE);
250 gtk_box_pack_start(GTK_BOX(caplen_hb), capfile_ck, FALSE, FALSE, 3);
251 gtk_widget_show(capfile_ck);
253 snap_lb = gtk_label_new("Capture length");
254 gtk_misc_set_alignment(GTK_MISC(snap_lb), 0, 0.5);
255 gtk_box_pack_start(GTK_BOX(caplen_hb), snap_lb, FALSE, FALSE, 6);
256 gtk_widget_show(snap_lb);
258 adj = (GtkAdjustment *) gtk_adjustment_new((float) cf.snap, 1.0, 4096.0,
260 snap_sb = gtk_spin_button_new (adj, 0, 0);
261 gtk_spin_button_set_wrap (GTK_SPIN_BUTTON (snap_sb), TRUE);
262 gtk_widget_set_usize (snap_sb, 80, 0);
263 gtk_box_pack_start (GTK_BOX(caplen_hb), snap_sb, FALSE, FALSE, 3);
264 gtk_widget_show(snap_sb);
266 /* Button row: OK and cancel buttons */
267 bbox = gtk_hbutton_box_new();
268 gtk_button_box_set_layout (GTK_BUTTON_BOX (bbox), GTK_BUTTONBOX_END);
269 gtk_button_box_set_spacing(GTK_BUTTON_BOX(bbox), 5);
270 gtk_container_add(GTK_CONTAINER(main_vb), bbox);
271 gtk_widget_show(bbox);
273 ok_bt = gtk_button_new_with_label ("OK");
274 gtk_signal_connect_object(GTK_OBJECT(ok_bt), "clicked",
275 GTK_SIGNAL_FUNC(capture_prep_ok_cb), GTK_OBJECT(cap_open_w));
276 GTK_WIDGET_SET_FLAGS(ok_bt, GTK_CAN_DEFAULT);
277 gtk_box_pack_start (GTK_BOX (bbox), ok_bt, TRUE, TRUE, 0);
278 gtk_widget_grab_default(ok_bt);
279 gtk_widget_show(ok_bt);
281 cancel_bt = gtk_button_new_with_label ("Cancel");
282 gtk_signal_connect_object(GTK_OBJECT(cancel_bt), "clicked",
283 GTK_SIGNAL_FUNC(capture_prep_close_cb), GTK_OBJECT(cap_open_w));
284 GTK_WIDGET_SET_FLAGS(ok_bt, GTK_CAN_DEFAULT);
285 gtk_box_pack_start (GTK_BOX (bbox), cancel_bt, TRUE, TRUE, 0);
286 gtk_widget_show(cancel_bt);
288 /* Attach pointers to needed widges to the capture prefs window/object */
289 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_IFACE_KEY, if_cb);
290 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_FILT_KEY, filter_te);
291 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_FILE_KEY, file_te);
292 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_COUNT_KEY, count_cb);
293 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_OPEN_KEY, capfile_ck);
294 gtk_object_set_data(GTK_OBJECT(cap_open_w), E_CAP_SNAP_KEY, snap_sb);
296 gtk_widget_show(cap_open_w);
300 capture_prep_file_cb(GtkWidget *w, gpointer te) {
303 fs = gtk_file_selection_new ("Ethereal: Open Save File");
305 gtk_object_set_data(GTK_OBJECT(w), E_CAP_PREP_FS_KEY, fs);
306 gtk_object_set_data(GTK_OBJECT(w), E_CAP_PREP_TE_KEY, (GtkWidget *) te);
308 gtk_signal_connect (GTK_OBJECT (GTK_FILE_SELECTION(fs)->ok_button),
309 "clicked", (GtkSignalFunc) cap_prep_fs_ok_cb, w);
311 /* Connect the cancel_button to destroy the widget */
312 gtk_signal_connect (GTK_OBJECT (GTK_FILE_SELECTION(fs)->cancel_button),
313 "clicked", (GtkSignalFunc) cap_prep_fs_cancel_cb, w);
319 cap_prep_fs_ok_cb(GtkWidget *w, gpointer data) {
322 fs = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_PREP_FS_KEY);
323 te = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_PREP_TE_KEY);
325 gtk_entry_set_text(GTK_ENTRY(te),
326 gtk_file_selection_get_filename (GTK_FILE_SELECTION(fs)));
327 cap_prep_fs_cancel_cb(w, data);
331 cap_prep_fs_cancel_cb(GtkWidget *w, gpointer data) {
334 fs = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_PREP_FS_KEY);
336 gtk_widget_destroy(fs);
340 capture_prep_ok_cb(GtkWidget *w, gpointer data) {
341 GtkWidget *if_cb, *filter_te, *file_te, *count_cb, *open_ck, *snap_sb;
344 if_cb = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_IFACE_KEY);
345 filter_te = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_FILT_KEY);
346 file_te = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_FILE_KEY);
347 count_cb = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_COUNT_KEY);
348 open_ck = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_OPEN_KEY);
349 snap_sb = (GtkWidget *) gtk_object_get_data(GTK_OBJECT(data), E_CAP_SNAP_KEY);
351 if (cf.iface) g_free(cf.iface);
353 g_strdup(gtk_entry_get_text(GTK_ENTRY(GTK_COMBO(if_cb)->entry)));
354 if (cf.cfilter) g_free(cf.cfilter);
355 cf.cfilter = g_strdup(gtk_entry_get_text(GTK_ENTRY(filter_te)));
356 if (cf.save_file) g_free(cf.save_file);
357 cf.save_file = g_strdup(gtk_entry_get_text(GTK_ENTRY(file_te)));
359 atoi(g_strdup(gtk_entry_get_text(GTK_ENTRY(GTK_COMBO(count_cb)->entry))));
360 open = GTK_TOGGLE_BUTTON(open_ck)->active;
361 cf.snap = gtk_spin_button_get_value_as_int(GTK_SPIN_BUTTON(snap_sb));
364 else if (cf.snap < 68)
367 gtk_widget_destroy(GTK_WIDGET(data));
373 capture_prep_close_cb(GtkWidget *w, gpointer win) {
375 gtk_grab_remove(GTK_WIDGET(win));
376 gtk_widget_destroy(GTK_WIDGET(win));
381 GtkWidget *cap_w, *main_vb, *count_lb, *tcp_lb, *udp_lb,
382 *ospf_lb, *other_lb, *stop_bt;
384 gchar err_str[PCAP_ERRBUF_SIZE], label_str[32];
386 bpf_u_int32 netnum, netmask;
387 time_t upd_time, cur_time;
398 close_cap_file(&cf, info_bar, file_ctx);
400 pch = pcap_open_live(cf.iface, cf.snap, 1, 250, err_str);
403 if (cf.save_file[0]) {
404 ld.pdh = pcap_dump_open(pch, cf.save_file);
405 if (ld.pdh == NULL) { /* We have an error */
406 snprintf(err_str, PCAP_ERRBUF_SIZE, "Error trying to open dump "
407 "file:\n%s", pcap_geterr(pch));
408 simple_dialog(ESD_TYPE_WARN, NULL, err_str);
409 g_free(cf.save_file);
417 if (pcap_lookupnet (cf.iface, &netnum, &netmask, err_str) < 0) {
418 simple_dialog(ESD_TYPE_WARN, NULL,
419 "Can't use filter: Couldn't obtain netmask info.");
421 } else if (pcap_compile(pch, &cf.fcode, cf.cfilter, 1, netmask) < 0) {
422 simple_dialog(ESD_TYPE_WARN, NULL, "Unable to parse filter string.");
424 } else if (pcap_setfilter(pch, &cf.fcode) < 0) {
425 simple_dialog(ESD_TYPE_WARN, NULL, "Can't install filter.");
430 cap_w = gtk_window_new(GTK_WINDOW_TOPLEVEL);
431 gtk_window_set_title(GTK_WINDOW(cap_w), "Ethereal: Capture / Playback");
433 /* Container for capture display widgets */
434 main_vb = gtk_vbox_new(FALSE, 1);
435 gtk_container_border_width(GTK_CONTAINER(main_vb), 5);
436 gtk_container_add(GTK_CONTAINER(cap_w), main_vb);
437 gtk_widget_show(main_vb);
439 count_lb = gtk_label_new("Count: 0");
440 gtk_box_pack_start(GTK_BOX(main_vb), count_lb, FALSE, FALSE, 3);
441 gtk_widget_show(count_lb);
443 tcp_lb = gtk_label_new("TCP: 0 (0.0%)");
444 gtk_box_pack_start(GTK_BOX(main_vb), tcp_lb, FALSE, FALSE, 3);
445 gtk_widget_show(tcp_lb);
447 udp_lb = gtk_label_new("UDP: 0 (0.0%)");
448 gtk_box_pack_start(GTK_BOX(main_vb), udp_lb, FALSE, FALSE, 3);
449 gtk_widget_show(udp_lb);
451 ospf_lb = gtk_label_new("OSPF: 0 (0.0%)");
452 gtk_box_pack_start(GTK_BOX(main_vb), ospf_lb, FALSE, FALSE, 3);
453 gtk_widget_show(ospf_lb);
455 other_lb = gtk_label_new("Other: 0 (0.0%)");
456 gtk_box_pack_start(GTK_BOX(main_vb), other_lb, FALSE, FALSE, 3);
457 gtk_widget_show(other_lb);
459 stop_bt = gtk_button_new_with_label ("Stop");
460 gtk_signal_connect(GTK_OBJECT(stop_bt), "clicked",
461 GTK_SIGNAL_FUNC(capture_stop_cb), (gpointer) &ld);
462 gtk_box_pack_end(GTK_BOX(main_vb), stop_bt, FALSE, FALSE, 3);
463 GTK_WIDGET_SET_FLAGS(stop_bt, GTK_CAN_DEFAULT);
464 gtk_widget_grab_default(stop_bt);
465 GTK_WIDGET_SET_FLAGS(stop_bt, GTK_CAN_DEFAULT);
466 gtk_widget_grab_default(stop_bt);
467 gtk_widget_show(stop_bt);
469 gtk_widget_show(cap_w);
472 upd_time = time(NULL);
474 while (gtk_events_pending()) gtk_main_iteration();
475 pcap_dispatch(pch, 1, capture_pcap_cb, (u_char *) &ld);
477 /* Only update once a second so as not to overload slow displays */
478 cur_time = time(NULL);
479 if (cur_time > upd_time) {
483 sprintf(label_str, "Count: %d", ld.count);
484 gtk_label_set(GTK_LABEL(count_lb), label_str);
486 sprintf(label_str, "TCP: %d (%.1f%%)", ld.tcp, pct(ld.tcp, ld.count));
487 gtk_label_set(GTK_LABEL(tcp_lb), label_str);
489 sprintf(label_str, "UDP: %d (%.1f%%)", ld.udp, pct(ld.udp, ld.count));
490 gtk_label_set(GTK_LABEL(udp_lb), label_str);
492 sprintf(label_str, "OSPF: %d (%.1f%%)", ld.ospf, pct(ld.ospf, ld.count));
493 gtk_label_set(GTK_LABEL(ospf_lb), label_str);
495 sprintf(label_str, "Other: %d (%.1f%%)", ld.other,
496 pct(ld.other, ld.count));
497 gtk_label_set(GTK_LABEL(other_lb), label_str);
501 if (ld.pdh) pcap_dump_close(ld.pdh);
504 gtk_grab_remove(GTK_WIDGET(cap_w));
505 gtk_widget_destroy(GTK_WIDGET(cap_w));
507 while (gtk_events_pending()) gtk_main_iteration();
508 simple_dialog(ESD_TYPE_WARN, NULL,
509 "The capture session could not be initiated. Please\n"
510 "check to make sure you have sufficient permissions, and\n"
511 "that you have the proper interface specified.");
512 g_free(cf.save_file);
516 if (cf.save_file && open) load_cap_file(cf.save_file, &cf);
520 pct(gint num, gint denom) {
522 return (float) num * 100.0 / (float) denom;
529 capture_stop_cb(GtkWidget *w, gpointer data) {
530 loop_data *ld = (loop_data *) data;
536 capture_pcap_cb(u_char *user, const struct pcap_pkthdr *phdr,
543 loop_data *ld = (loop_data *) user;
545 if ((++ld->count >= ld->max) && (ld->max > 0))
549 /* Currently, pcap_dumper_t is a FILE *. Let's hope that doesn't change. */
550 if (ld->pdh) pcap_dump((u_char *) ld->pdh, phdr, pd);
552 etype = etype = (pd[12] << 8) | pd[13];
553 if (etype <= IEEE_802_3_MAX_LEN) {
554 etype = (pd[20] << 8) | pd[21];
560 iptype = pd[offset + 9];
577 case ETHERTYPE_ATALK:
578 case ETHERTYPE_VINES: