2 * Definitions for packet disassembly structures and routines
4 * $Id: packet.h,v 1.10 1998/09/27 22:12:42 gerald Exp $
6 * Ethereal - Network traffic analyzer
7 * By Gerald Combs <gerald@zing.org>
8 * Copyright 1998 Gerald Combs
11 * This program is free software; you can redistribute it and/or
12 * modify it under the terms of the GNU General Public License
13 * as published by the Free Software Foundation; either version 2
14 * of the License, or (at your option) any later version.
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
19 * GNU General Public License for more details.
21 * You should have received a copy of the GNU General Public License
22 * along with this program; if not, write to the Free Software
23 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
30 /* Pointer versions of ntohs and ntohl. Given a pointer to a member of a
31 * byte array, returns the value of the two or four bytes at the pointer.
35 #if BYTE_ORDER == LITTLE_ENDIAN
36 #define pntohs(p) ((guint16) \
37 ((guint16)*((guint8 *)p+0)<<8| \
38 (guint16)*((guint8 *)p+1)<<0))
40 #define pntohl(p) ((guint32)*((guint8 *)p+0)<<24| \
41 (guint32)*((guint8 *)p+1)<<16| \
42 (guint32)*((guint8 *)p+2)<<8| \
43 (guint32)*((guint8 *)p+3)<<0)
44 #else /* BIG_ENDIAN */
45 #define pntohs(p) ((guint16) \
46 ((guint16)*((guint8 *)p+1)<<8| \
47 (guint16)*((guint8 *)p+0)<<0))
49 #define pntohl(p) ((guint32)*((guint8 *)p+3)<<24| \
50 (guint32)*((guint8 *)p+2)<<16| \
51 (guint32)*((guint8 *)p+1)<<8| \
52 (guint32)*((guint8 *)p+0)<<0)
53 #endif /* LITTLE_ENDIAN */
55 /* Useful when highlighting regions inside a dissect_*() function. With this
56 * macro, you can highlight from the start of the packet to the end of the
57 * frame. See dissect_data() for an example.
59 #define END_OF_FRAME (fd->cap_len - offset)
61 #define IEEE_802_3_MAX_LEN 1500
62 #define BYTE_VIEW_WIDTH 16
64 typedef struct _frame_data {
65 guint32 pkt_len; /* Packet length */
66 guint32 cap_len; /* Amount actually captured */
67 guint32 secs; /* Seconds */
68 guint32 usecs; /* Microseconds */
69 long file_off; /* File offset */
70 gchar *win_info[NUM_COLS]; /* Text for packet summary list fields */
73 typedef struct _packet_info {
84 /* Many of the structs and definitions below were taken from include files
85 * in the Linux distribution. */
87 /* ARP / RARP structs and definitions */
89 typedef struct _e_ether_arp {
101 #ifndef ARPOP_REQUEST
102 #define ARPOP_REQUEST 1 /* ARP request. */
105 #define ARPOP_REPLY 2 /* ARP reply. */
107 /* Some OSes have different names, or don't define these at all */
108 #ifndef ARPOP_RREQUEST
109 #define ARPOP_RREQUEST 3 /* RARP request. */
112 #define ARPOP_RREPLY 4 /* RARP reply. */
115 /* ICMP structs and definitions */
117 typedef struct _e_icmp {
122 struct { /* Address mask request/reply */
127 struct { /* Timestap request/reply */
134 guint32 zero; /* Unreachable */
138 #define ICMP_ECHOREPLY 0
139 #define ICMP_UNREACH 3
140 #define ICMP_SOURCEQUENCH 4
141 #define ICMP_REDIRECT 5
143 #define ICMP_TIMXCEED 11
144 #define ICMP_PARAMPROB 12
145 #define ICMP_TSTAMP 13
146 #define ICMP_TSTAMPREPLY 14
148 #define ICMP_IREQREPLY 16
149 #define ICMP_MASKREQ 17
150 #define ICMP_MASKREPLY 18
152 /* IGMP structs and definitions */
154 typedef struct _e_igmp {
155 #if BYTE_ORDER == BIG_ENDIAN
158 #else /* Little endian */
167 #define IGMP_M_QRY 0x01
168 #define IGMP_V1_M_RPT 0x02
169 #define IGMP_V2_LV_GRP 0x07
170 #define IGMP_DVMRP 0x03
171 #define IGMP_PIM 0x04
172 #define IGMP_V2_M_RPT 0x06
173 #define IGMP_MTRC_RESP 0x1e
174 #define IGMP_MTRC 0x1f
176 /* IP structs and definitions */
178 typedef struct _e_ip {
179 #if BYTE_ORDER == BIG_ENDIAN
182 #else /* Little endian */
197 #define IPTOS_TOS_MASK 0x1E
198 #define IPTOS_TOS(tos) ((tos) & IPTOS_TOS_MASK)
199 #define IPTOS_NONE 0x00
200 #define IPTOS_LOWDELAY 0x10
201 #define IPTOS_THROUGHPUT 0x08
202 #define IPTOS_RELIABILITY 0x04
203 #define IPTOS_LOWCOST 0x02
205 #define IP_PROTO_ICMP 1
206 #define IP_PROTO_IGMP 2
207 #define IP_PROTO_TCP 6
208 #define IP_PROTO_UDP 17
209 #define IP_PROTO_OSPF 89
211 /* Null/loopback structs and definitions */
213 typedef struct _e_nullhdr {
219 /* PPP structs and definitions */
221 typedef struct _e_ppphdr {
227 /* TCP structs and definitions */
229 typedef struct _e_tcphdr {
234 #if BYTE_ORDER == LITTLE_ENDIAN
253 /* UDP structs and definitions */
255 typedef struct _e_udphdr {
262 /* UDP Ports -> should go in packet-udp.h */
264 #define UDP_PORT_DNS 53
265 #define UDP_PORT_BOOTPS 67
266 #define UDP_PORT_IPX 213
267 #define UDP_PORT_RIP 520
271 #define TCP_PORT_PRINTER 515
273 /* Tree types. Each dissect_* routine should have one for each
274 add_subtree() call. */
277 #define ETT_IEEE8023 1
280 #define ETT_TOKEN_RING 4
281 #define ETT_TR_IERR_CNT 5
282 #define ETT_TR_NERR_CNT 6
295 #define ETT_DNS_ANS 19
296 #define ETT_DNS_QRY 20
298 #define ETT_RIP_VEC 22
300 #define ETT_OSPF_HDR 24
301 #define ETT_OSPF_HELLO 25
302 #define ETT_OSPF_DESC 26
303 #define ETT_OSPF_LSR 27
304 #define ETT_OSPF_LSA_UPD 28
305 #define ETT_OSPF_LSA 29
309 #define ETT_BOOTP_OPTION 33
315 #define ETT_IPXRIP 39
316 #define ETT_IPXSAP 40
317 #define ETT_IPXSAP_SERVER 41
320 /* Should be the last item number plus one */
321 #define NUM_TREE_TYPES 43
323 /* The version of pcap.h that comes with some systems is missing these
331 #ifndef DLT_SLIP_BSDOS
332 #define DLT_SLIP_BSDOS 13
335 #ifndef DLT_PPP_BSDOS
336 #define DLT_PPP_BSDOS 14
339 /* Utility routines used by packet*.c */
340 gchar* ether_to_str(guint8 *);
341 gchar* ip_to_str(guint8 *);
342 void packet_hex_print(GtkText *, guint8 *, gint, gint, gint);
344 GtkWidget* add_item_to_tree(GtkWidget *, gint, gint, gchar *, ...)
345 __attribute__((format (printf, 4, 5)));
347 GtkWidget* add_item_to_tree(GtkWidget *, gint, gint, gchar *, ...);
349 void decode_start_len(GtkTreeItem *, gint*, gint*);
351 /* Routines in packet.c */
352 void dissect_packet(const u_char *, guint32 ts_secs, guint32 ts_usecs,
353 frame_data *, GtkTree *);
354 void add_subtree(GtkWidget *, GtkWidget*, gint);
355 void expand_tree(GtkWidget *, gpointer);
356 void collapse_tree(GtkWidget *, gpointer);
359 * Routines in packet-*.c
360 * Routines should take three args: packet data *, frame_data *, tree *
361 * They should never modify the packet data.
363 void dissect_eth(const u_char *, frame_data *, GtkTree *);
364 void dissect_null(const u_char *, frame_data *, GtkTree *);
365 void dissect_ppp(const u_char *, frame_data *, GtkTree *);
366 void dissect_raw(const u_char *, frame_data *, GtkTree *);
367 void dissect_tr(const u_char *, frame_data *, GtkTree *);
370 * Routines in packet-*.c
371 * Routines should take four args: packet data *, offset, frame_data *,
373 * They should never modify the packet data.
375 void dissect_arp(const u_char *, int, frame_data *, GtkTree *);
376 void dissect_bootp(const u_char *, int, frame_data *, GtkTree *);
377 void dissect_data(const u_char *, int, frame_data *, GtkTree *);
378 void dissect_dns(const u_char *, int, frame_data *, GtkTree *);
379 void dissect_icmp(const u_char *, int, frame_data *, GtkTree *);
380 void dissect_igmp(const u_char *, int, frame_data *, GtkTree *);
381 void dissect_ip(const u_char *, int, frame_data *, GtkTree *);
382 void dissect_ipv6(const u_char *, int, frame_data *, GtkTree *);
383 void dissect_ipx(const u_char *, int, frame_data *, GtkTree *);
384 void dissect_llc(const u_char *, int, frame_data *, GtkTree *);
385 void dissect_lpd(const u_char *, int, frame_data *, GtkTree *);
386 void dissect_ncp(const u_char *, int, frame_data *, GtkTree *);
387 void dissect_osi(const u_char *, int, frame_data *, GtkTree *);
388 void dissect_ospf(const u_char *, int, frame_data *, GtkTree *);
389 void dissect_ospf_hello(const u_char *, int, frame_data *, GtkTree *);
390 void dissect_rip(const u_char *, int, frame_data *, GtkTree *);
391 void dissect_tcp(const u_char *, int, frame_data *, GtkTree *);
392 void dissect_trmac(const u_char *, int, frame_data *, GtkTree *);
393 void dissect_udp(const u_char *, int, frame_data *, GtkTree *);
394 void dissect_vines(const u_char *, int, frame_data *, GtkTree *);
395 void dissect_vspp(const u_char *, int, frame_data *, GtkTree *);
397 /* This function is in ethertype.c */
398 void ethertype(guint16 etype, int offset,
399 const u_char *pd, frame_data *fd, GtkTree *tree,
402 #endif /* packet.h */