Fix files that had Gilbert's old e-mail address or that didn't have my
[obnox/wireshark/wip.git] / wiretap / lanalyzer.c
1 /* lanalyzer.c
2  *
3  * $Id: lanalyzer.c,v 1.20 2000/01/22 06:22:38 guy Exp $
4  *
5  * Wiretap Library
6  * Copyright (c) 1998 by Gilbert Ramirez <gram@xiexie.org>
7  * 
8  * This program is free software; you can redistribute it and/or
9  * modify it under the terms of the GNU General Public License
10  * as published by the Free Software Foundation; either version 2
11  * of the License, or (at your option) any later version.
12  * 
13  * This program is distributed in the hope that it will be useful,
14  * but WITHOUT ANY WARRANTY; without even the implied warranty of
15  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16  * GNU General Public License for more details.
17  * 
18  * You should have received a copy of the GNU General Public License
19  * along with this program; if not, write to the Free Software
20  * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.
21  *
22  */
23 #ifdef HAVE_CONFIG_H
24 #include "config.h"
25 #endif
26 #include <stdlib.h>
27 #include <errno.h>
28 #include <time.h>
29 #include "wtap.h"
30 #include "file_wrappers.h"
31 #include "buffer.h"
32 #include "lanalyzer.h"
33
34 /* The LANalyzer format is documented (at least in part) in Novell document
35    TID022037, which can be found at, among other places:
36
37         http://www.hackzone.ru/nsp/info/nw/lan/trace.txt
38  */
39
40 /* Record types. */
41 #define REC_TRACE_HEADER        0x1001
42 #define REC_CYCLIC_TRACE_HEADER 0x1007
43 #define REC_TRACE_SUMMARY       0x1002
44 #define REC_TRACE_PACKET_DATA   0x1005
45
46 /* LANalyzer board types (which indicate the type of network on which
47    the capture was done). */
48 #define BOARD_325               226     /* LANalyzer 325 (Ethernet) */
49 #define BOARD_325TR             227     /* LANalyzer 325TR (Token-ring) */
50
51 static int lanalyzer_read(wtap *wth, int *err);
52
53 int lanalyzer_open(wtap *wth, int *err)
54 {
55         int bytes_read;
56         char LE_record_type[2];
57         char LE_record_length[2];
58         char summary[210];
59         guint16 board_type, mxslc;
60         guint16 record_type, record_length;
61         guint8 cr_day, cr_month, cr_year;
62         struct tm tm;
63
64         file_seek(wth->fh, 0, SEEK_SET);
65         wth->data_offset = 0;
66         errno = WTAP_ERR_CANT_READ;
67         bytes_read = file_read(LE_record_type, 1, 2, wth->fh);
68         bytes_read += file_read(LE_record_length, 1, 2, wth->fh);
69         if (bytes_read != 4) {
70                 *err = file_error(wth->fh);
71                 if (*err != 0)
72                         return -1;
73                 return 0;
74         }
75         wth->data_offset += 4;
76         record_type = pletohs(LE_record_type);
77         record_length = pletohs(LE_record_length); /* make sure to do this for while() loop */
78
79         if (record_type != REC_TRACE_HEADER && record_type != REC_CYCLIC_TRACE_HEADER) {  
80                 return 0;
81         }
82
83         /* If we made it this far, then the file is a LANAlyzer file.
84          * Let's get some info from it. Note that we get wth->snapshot_length
85          * from a record later in the file. */
86         wth->file_type = WTAP_FILE_LANALYZER;
87         wth->capture.lanalyzer = g_malloc(sizeof(lanalyzer_t));
88         wth->subtype_read = lanalyzer_read;
89         wth->snapshot_length = 0;
90
91         /* Read records until we find the start of packets */
92         while (1) {
93                 file_seek(wth->fh, record_length, SEEK_CUR);
94                 wth->data_offset += record_length;
95                 errno = WTAP_ERR_CANT_READ;
96                 bytes_read = file_read(LE_record_type, 1, 2, wth->fh);
97                 bytes_read += file_read(LE_record_length, 1, 2, wth->fh);
98                 if (bytes_read != 4) {
99                         *err = file_error(wth->fh);
100                         if (*err != 0) {
101                                 g_free(wth->capture.lanalyzer);
102                                 return -1;
103                         }
104                         g_free(wth->capture.lanalyzer);
105                         return 0;
106                 }
107                 wth->data_offset += 4;
108
109                 record_type = pletohs(LE_record_type);
110                 record_length = pletohs(LE_record_length);
111
112                 /*g_message("Record 0x%04X Length %d", record_type, record_length);*/
113                 switch (record_type) {
114                         /* Trace Summary Record */
115                         case REC_TRACE_SUMMARY:
116                                 errno = WTAP_ERR_CANT_READ;
117                                 bytes_read = file_read(summary, 1, sizeof summary,
118                                     wth->fh);
119                                 if (bytes_read != sizeof summary) {
120                                         *err = file_error(wth->fh);
121                                         if (*err != 0) {
122                                                 g_free(wth->capture.lanalyzer);
123                                                 return -1;
124                                         }
125                                         g_free(wth->capture.lanalyzer);
126                                         return 0;
127                                 }
128                                 wth->data_offset += sizeof summary;
129
130                                 /* Assume that the date of the creation of the trace file
131                                  * is the same date of the trace. Lanalyzer doesn't
132                                  * store the creation date/time of the trace, but only of
133                                  * the file. Unless you traced at 11:55 PM and saved at 00:05
134                                  * AM, the assumption that trace.date == file.date is true.
135                                  */
136                                 cr_day = summary[0];
137                                 cr_month = summary[1];
138                                 cr_year = pletohs(&summary[2]);
139                                 /*g_message("Day %d Month %d Year %d (%04X)", cr_day, cr_month,
140                                                 cr_year, cr_year);*/
141
142                                 /* Get capture start time. I learned how to do
143                                  * this from Guy's code in ngsniffer.c
144                                  */
145                                 /* this strange year offset is not in the
146                                  * lanalyzer file format documentation, but it
147                                  * works. */
148                                 tm.tm_year = cr_year - (1900 - 1792);
149                                 tm.tm_mon = cr_month - 1;
150                                 tm.tm_mday = cr_day;
151                                 tm.tm_hour = 0;
152                                 tm.tm_min = 0;
153                                 tm.tm_sec = 0;
154                                 tm.tm_isdst = -1;
155                                 wth->capture.lanalyzer->start = mktime(&tm);
156                                 /*g_message("Day %d Month %d Year %d", tm.tm_mday,
157                                                 tm.tm_mon, tm.tm_year);*/
158                                 mxslc = pletohs(&summary[30]);
159                                 wth->snapshot_length = mxslc;
160
161                                 record_length = 0; /* to fake the next iteration of while() */
162                                 board_type = pletohs(&summary[188]);
163                                 switch (board_type) {
164                                         case BOARD_325:
165                                                 wth->file_encap = WTAP_ENCAP_ETHERNET;
166                                                 break;
167                                         case BOARD_325TR:
168                                                 wth->file_encap = WTAP_ENCAP_TR;
169                                                 break;
170                                         default:
171                                                 g_message("lanalyzer: board type %u unknown",
172                                                     board_type);
173                                                 g_free(wth->capture.lanalyzer);
174                                                 *err = WTAP_ERR_UNSUPPORTED;
175                                                 return -1;
176                                 }
177                                 break;
178
179                         /* Trace Packet Data Record */
180                         case REC_TRACE_PACKET_DATA:
181                                 /* Go back header number ob ytes so that lanalyzer_read
182                                  * can read this header */
183                                 file_seek(wth->fh, -bytes_read, SEEK_CUR);
184                                 wth->data_offset -= bytes_read;
185                                 return 1;
186
187                         default:
188                                 ; /* no action */
189                 }
190         } 
191
192         /* never gets here */
193         g_assert_not_reached();
194         return 0;
195 }
196
197 #define DESCRIPTOR_LEN  32
198
199 /* Read the next packet */
200 static int lanalyzer_read(wtap *wth, int *err)
201 {
202         int             packet_size = 0;
203         int             bytes_read;
204         char            LE_record_type[2];
205         char            LE_record_length[2];
206         guint16         record_type, record_length;
207         gchar           descriptor[DESCRIPTOR_LEN];
208         int             data_offset;
209         guint16         time_low, time_med, time_high, true_size;
210         double          t;
211
212         /* read the record type and length. */
213         errno = WTAP_ERR_CANT_READ;
214         bytes_read = file_read(LE_record_type, 1, 2, wth->fh);
215         if (bytes_read != 2) {
216                 *err = file_error(wth->fh);
217                 if (*err != 0)
218                         return -1;
219                 if (bytes_read != 0) {
220                         *err = WTAP_ERR_SHORT_READ;
221                         return -1;
222                 }
223                 return 0;
224         }
225         wth->data_offset += 2;
226         bytes_read = file_read(LE_record_length, 1, 2, wth->fh);
227         if (bytes_read != 2) {
228                 *err = file_error(wth->fh);
229                 if (*err == 0)
230                         *err = WTAP_ERR_SHORT_READ;
231                 return -1;
232         }
233         wth->data_offset += 2;
234
235         record_type = pletohs(LE_record_type);
236         record_length = pletohs(LE_record_length);
237
238         /* Only Trace Packet Data Records should occur now that we're in
239          * the middle of reading packets.  If any other record type exists
240          * after a Trace Packet Data Record, mark it as an error. */
241         if (record_type != REC_TRACE_PACKET_DATA) {
242                 g_message("lanalyzer: record type %u seen after trace summary record",
243                     record_type);
244                 *err = WTAP_ERR_BAD_RECORD;
245                 return -1;
246         }
247         else {
248                 packet_size = record_length - DESCRIPTOR_LEN;
249         }
250
251         /* Read the descriptor data */
252         errno = WTAP_ERR_CANT_READ;
253         bytes_read = file_read(descriptor, 1, DESCRIPTOR_LEN, wth->fh);
254         if (bytes_read != DESCRIPTOR_LEN) {
255                 *err = file_error(wth->fh);
256                 if (*err == 0)
257                         *err = WTAP_ERR_SHORT_READ;
258                 return -1;
259         }
260         wth->data_offset += DESCRIPTOR_LEN;
261
262         /* Read the packet data */
263         buffer_assure_space(wth->frame_buffer, packet_size);
264         data_offset = wth->data_offset;
265         errno = WTAP_ERR_CANT_READ;
266         bytes_read = file_read(buffer_start_ptr(wth->frame_buffer), 1,
267                 packet_size, wth->fh);
268
269         if (bytes_read != packet_size) {
270                 *err = file_error(wth->fh);
271                 if (*err == 0)
272                         *err = WTAP_ERR_SHORT_READ;
273                 return -1;
274         }
275         wth->data_offset += packet_size;
276
277         true_size = pletohs(&descriptor[4]);
278         time_low = pletohs(&descriptor[8]);
279         time_med = pletohs(&descriptor[10]);
280         time_high = pletohs(&descriptor[12]);
281
282         t = (double)time_low+(double)(time_med)*65536.0 +
283                 (double)time_high*4294967296.0;
284         t = t/1000000.0 * 0.5; /* t = # of secs */
285         t += wth->capture.lanalyzer->start;
286
287         wth->phdr.ts.tv_sec = (long)t;
288         wth->phdr.ts.tv_usec = (unsigned long)((t-(double)(wth->phdr.ts.tv_sec))
289                         *1.0e6);
290
291         wth->phdr.len = true_size - 4;
292         wth->phdr.caplen = packet_size;
293         wth->phdr.pkt_encap = wth->file_encap;
294
295         return data_offset;
296 }