2 * Routines for BPDU (Spanning Tree Protocol) disassembly
4 * $Id: packet-bpdu.c,v 1.26 2001/06/18 02:17:45 guy Exp $
6 * Copyright 1999 Christophe Tronche <ch.tronche@computer.org>
8 * Ethereal - Network traffic analyzer
9 * By Gerald Combs <gerald@ethereal.com>
10 * Copyright 1998 Gerald Combs
13 * This program is free software; you can redistribute it and/or
14 * modify it under the terms of the GNU General Public License
15 * as published by the Free Software Foundation; either version 2
16 * of the License, or (at your option) any later version.
18 * This program is distributed in the hope that it will be useful,
19 * but WITHOUT ANY WARRANTY; without even the implied warranty of
20 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21 * GNU General Public License for more details.
23 * You should have received a copy of the GNU General Public License
24 * along with this program; if not, write to the Free Software
25 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
32 #ifdef HAVE_SYS_TYPES_H
33 # include <sys/types.h>
36 #ifdef HAVE_NETINET_IN_H
37 # include <netinet/in.h>
48 /* Offsets of fields within a BPDU */
50 #define BPDU_IDENTIFIER 0
51 #define BPDU_VERSION_IDENTIFIER 2
54 #define BPDU_ROOT_IDENTIFIER 5
55 #define BPDU_ROOT_PATH_COST 13
56 #define BPDU_BRIDGE_IDENTIFIER 17
57 #define BPDU_PORT_IDENTIFIER 25
58 #define BPDU_MESSAGE_AGE 27
59 #define BPDU_MAX_AGE 29
60 #define BPDU_HELLO_TIME 31
61 #define BPDU_FORWARD_DELAY 33
63 static int proto_bpdu = -1;
64 static int hf_bpdu_proto_id = -1;
65 static int hf_bpdu_version_id = -1;
66 static int hf_bpdu_type = -1;
67 static int hf_bpdu_flags = -1;
68 static int hf_bpdu_root_mac = -1;
69 static int hf_bpdu_root_cost = -1;
70 static int hf_bpdu_bridge_mac = -1;
71 static int hf_bpdu_port_id = -1;
72 static int hf_bpdu_msg_age = -1;
73 static int hf_bpdu_max_age = -1;
74 static int hf_bpdu_hello_time = -1;
75 static int hf_bpdu_forward_delay = -1;
77 static gint ett_bpdu = -1;
79 static dissector_handle_t gvrp_handle;
82 dissect_bpdu(tvbuff_t *tvb, packet_info *pinfo, proto_tree *tree) {
83 guint16 protocol_identifier;
84 guint8 protocol_version_identifier;
87 guint16 root_identifier_bridge_priority;
88 const guint8 *root_identifier_mac;
89 gchar *root_identifier_mac_str;
90 guint32 root_path_cost;
91 guint16 bridge_identifier_bridge_priority;
92 const guint8 *bridge_identifier_mac;
93 gchar *bridge_identifier_mac_str;
94 guint16 port_identifier;
100 proto_tree *bpdu_tree;
103 /* GARP application frames require special interpretation of the
104 destination address field; otherwise, they will be mistaken as
106 Fortunately, they can be recognized by checking the first 6 octets
107 of the destination address, which are in the range from
108 01-80-C2-00-00-20 to 01-80-C2-00-00-2F.
110 Yes - we *do* need to check the destination address type;
111 on Linux cooked captures, there *is* no destination address,
113 if (pinfo->dl_dst.type == AT_ETHER &&
114 pinfo->dl_dst.data[0] == 0x01 && pinfo->dl_dst.data[1] == 0x80 &&
115 pinfo->dl_dst.data[2] == 0xC2 && pinfo->dl_dst.data[3] == 0x00 &&
116 pinfo->dl_dst.data[4] == 0x00 && ((pinfo->dl_dst.data[5] & 0x20) == 0x20)) {
118 protocol_identifier = tvb_get_ntohs(tvb, BPDU_IDENTIFIER);
120 switch (pinfo->dl_dst.data[5]) {
123 /* Future expansion for GMRP */
128 call_dissector(gvrp_handle, tvb, pinfo, tree);
132 pinfo->current_proto = "GARP";
134 if (check_col(pinfo->fd, COL_PROTOCOL)) {
135 col_set_str(pinfo->fd, COL_PROTOCOL, "GARP");
136 /* Generic Attribute Registration Protocol */
139 if (check_col(pinfo->fd, COL_INFO)) {
140 col_add_fstr(pinfo->fd, COL_INFO,
141 "Unknown GARP application (0x%02X)",
142 pinfo->dl_dst.data[5]);
148 if (check_col(pinfo->fd, COL_PROTOCOL)) {
149 col_set_str(pinfo->fd, COL_PROTOCOL, "STP"); /* Spanning Tree Protocol */
151 if (check_col(pinfo->fd, COL_INFO)) {
152 col_clear(pinfo->fd, COL_INFO);
155 bpdu_type = tvb_get_guint8(tvb, BPDU_TYPE);
156 if (bpdu_type == 0) {
157 flags = tvb_get_guint8(tvb, BPDU_FLAGS);
158 root_identifier_bridge_priority = tvb_get_ntohs(tvb,
159 BPDU_ROOT_IDENTIFIER);
160 root_identifier_mac = tvb_get_ptr(tvb, BPDU_ROOT_IDENTIFIER + 2, 6);
161 root_identifier_mac_str = ether_to_str(root_identifier_mac);
162 root_path_cost = tvb_get_ntohl(tvb, BPDU_ROOT_PATH_COST);
163 port_identifier = tvb_get_ntohs(tvb, BPDU_PORT_IDENTIFIER);
165 /* Squelch GCC complaints. */
167 root_identifier_bridge_priority = 0;
168 root_identifier_mac = NULL;
169 root_identifier_mac_str = NULL;
174 if (check_col(pinfo->fd, COL_INFO)) {
176 col_add_fstr(pinfo->fd, COL_INFO, "Conf. %sRoot = %d/%s Cost = %d Port = 0x%04x",
177 flags & 0x1 ? "TC + " : "",
178 root_identifier_bridge_priority, root_identifier_mac_str, root_path_cost,
180 else if (bpdu_type == 0x80)
181 col_add_fstr(pinfo->fd, COL_INFO, "Topology Change Notification");
185 ti = proto_tree_add_protocol_format(tree, proto_bpdu, tvb, 0, 35,
186 "Spanning Tree Protocol");
187 bpdu_tree = proto_item_add_subtree(ti, ett_bpdu);
189 protocol_identifier = tvb_get_ntohs(tvb, BPDU_IDENTIFIER);
190 proto_tree_add_uint_format(bpdu_tree, hf_bpdu_proto_id, tvb,
193 "Protocol Identifier: 0x%04x (%s)",
195 protocol_identifier == 0 ?
196 "Spanning Tree" : "Unknown Protocol");
198 protocol_version_identifier = tvb_get_guint8(tvb, BPDU_VERSION_IDENTIFIER);
199 proto_tree_add_uint(bpdu_tree, hf_bpdu_version_id, tvb,
200 BPDU_VERSION_IDENTIFIER, 1,
201 protocol_version_identifier);
202 if (protocol_version_identifier != 0)
203 proto_tree_add_text(bpdu_tree, tvb, BPDU_VERSION_IDENTIFIER, 1,
204 " (Warning: this version of Ethereal only knows about version = 0)");
205 proto_tree_add_uint_format(bpdu_tree, hf_bpdu_type, tvb,
208 "BPDU Type: 0x%02x (%s)",
210 bpdu_type == 0 ? "Configuration" :
211 bpdu_type == 0x80 ? "Topology Change Notification" : "Unknown");
213 if (bpdu_type != 0) {
214 dissect_data(tvb, BPDU_TYPE + 1, pinfo, tree);
218 bridge_identifier_bridge_priority = tvb_get_ntohs(tvb, BPDU_BRIDGE_IDENTIFIER);
219 bridge_identifier_mac = tvb_get_ptr(tvb, BPDU_BRIDGE_IDENTIFIER + 2, 6);
220 bridge_identifier_mac_str = ether_to_str(bridge_identifier_mac);
221 message_age = tvb_get_ntohs(tvb, BPDU_MESSAGE_AGE) / 256.0;
222 max_age = tvb_get_ntohs(tvb, BPDU_MAX_AGE) / 256.0;
223 hello_time = tvb_get_ntohs(tvb, BPDU_HELLO_TIME) / 256.0;
224 forward_delay = tvb_get_ntohs(tvb, BPDU_FORWARD_DELAY) / 256.0;
226 proto_tree_add_uint(bpdu_tree, hf_bpdu_flags, tvb,
227 BPDU_FLAGS, 1, flags);
229 proto_tree_add_text(bpdu_tree, tvb, BPDU_FLAGS, 1, " 1... .... Topology Change Acknowledgment");
231 proto_tree_add_text(bpdu_tree, tvb, BPDU_FLAGS, 1, " .... ...1 Topology Change");
233 proto_tree_add_ether_hidden(bpdu_tree, hf_bpdu_root_mac, tvb,
234 BPDU_ROOT_IDENTIFIER + 2, 6,
235 root_identifier_mac);
236 proto_tree_add_text(bpdu_tree, tvb,
237 BPDU_ROOT_IDENTIFIER, 8,
238 "Root Identifier: %d / %s",
239 root_identifier_bridge_priority,
240 root_identifier_mac_str);
241 proto_tree_add_uint(bpdu_tree, hf_bpdu_root_cost, tvb,
242 BPDU_ROOT_PATH_COST, 4,
244 proto_tree_add_text(bpdu_tree, tvb,
245 BPDU_BRIDGE_IDENTIFIER, 8,
246 "Bridge Identifier: %d / %s",
247 bridge_identifier_bridge_priority,
248 bridge_identifier_mac_str);
249 proto_tree_add_ether_hidden(bpdu_tree, hf_bpdu_bridge_mac, tvb,
250 BPDU_BRIDGE_IDENTIFIER + 2, 6,
251 bridge_identifier_mac);
252 proto_tree_add_uint(bpdu_tree, hf_bpdu_port_id, tvb,
253 BPDU_PORT_IDENTIFIER, 2,
255 proto_tree_add_double(bpdu_tree, hf_bpdu_msg_age, tvb,
258 proto_tree_add_double(bpdu_tree, hf_bpdu_max_age, tvb,
261 proto_tree_add_double(bpdu_tree, hf_bpdu_hello_time, tvb,
264 proto_tree_add_double(bpdu_tree, hf_bpdu_forward_delay, tvb,
265 BPDU_FORWARD_DELAY, 2,
271 proto_register_bpdu(void)
274 static hf_register_info hf[] = {
276 { "Protocol Identifier", "stp.protocol",
277 FT_UINT16, BASE_HEX, NULL, 0x0,
279 { &hf_bpdu_version_id,
280 { "Protocol Version Identifier", "stp.version",
281 FT_UINT8, BASE_DEC, NULL, 0x0,
284 { "BPDU type", "stp.type",
285 FT_UINT8, BASE_HEX, NULL, 0x0,
288 { "BPDU flags", "stp.flags",
289 FT_UINT8, BASE_HEX, NULL, 0x0,
292 { "Root Identifier", "stp.root.hw",
293 FT_ETHER, BASE_NONE, NULL, 0x0,
295 { &hf_bpdu_root_cost,
296 { "Root Path Cost", "stp.root.cost",
297 FT_UINT32, BASE_DEC, NULL, 0x0,
299 { &hf_bpdu_bridge_mac,
300 { "Bridge Identifier", "stp.bridge.hw",
301 FT_ETHER, BASE_NONE, NULL, 0x0,
304 { "Port identifier", "stp.port",
305 FT_UINT16, BASE_HEX, NULL, 0x0,
308 { "Message Age", "stp.msg_age",
309 FT_DOUBLE, BASE_NONE, NULL, 0x0,
312 { "Max Age", "stp.max_age",
313 FT_DOUBLE, BASE_NONE, NULL, 0x0,
315 { &hf_bpdu_hello_time,
316 { "Hello Time", "stp.hello",
317 FT_DOUBLE, BASE_NONE, NULL, 0x0,
319 { &hf_bpdu_forward_delay,
320 { "Forward Delay", "stp.forward",
321 FT_DOUBLE, BASE_NONE, NULL, 0x0,
324 static gint *ett[] = {
328 proto_bpdu = proto_register_protocol("Spanning Tree Protocol", "STP", "stp");
329 proto_register_field_array(proto_bpdu, hf, array_length(hf));
330 proto_register_subtree_array(ett, array_length(ett));
332 register_dissector("bpdu", dissect_bpdu, proto_bpdu);
336 proto_reg_handoff_bpdu(void)
339 * Get handle for the GVRP dissector.
341 gvrp_handle = find_dissector("gvrp");
343 dissector_add("llc.dsap", SAP_BPDU, dissect_bpdu, proto_bpdu);
344 dissector_add("ppp.protocol", PPP_BPDU, dissect_bpdu, proto_bpdu);