2 * Copyright (c) 2008 CACE Technologies, Davis (California)
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
14 * 3. Neither the name of CACE Technologies nor the names of its
15 * contributors may be used to endorse or promote products derived from
16 * this software without specific prior written permission.
18 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
19 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
20 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
21 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
22 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
23 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
24 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
28 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
50 typedef TC_STATUS (TC_CALLCONV
*TcFcnQueryPortList
) (PTC_PORT
*ppPorts
, PULONG pLength
);
51 typedef TC_STATUS (TC_CALLCONV
*TcFcnFreePortList
) (TC_PORT
*pPorts
);
53 typedef PCHAR (TC_CALLCONV
*TcFcnStatusGetString
) (TC_STATUS status
);
55 typedef PCHAR (TC_CALLCONV
*TcFcnPortGetName
) (TC_PORT port
);
56 typedef PCHAR (TC_CALLCONV
*TcFcnPortGetDescription
) (TC_PORT port
);
58 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceOpenByName
) (PCHAR name
, PTC_INSTANCE pInstance
);
59 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceClose
) (TC_INSTANCE instance
);
60 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceSetFeature
) (TC_INSTANCE instance
, ULONG feature
, ULONG value
);
61 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceQueryFeature
) (TC_INSTANCE instance
, ULONG feature
, PULONG pValue
);
62 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceReceivePackets
) (TC_INSTANCE instance
, PTC_PACKETS_BUFFER pBuffer
);
63 typedef HANDLE (TC_CALLCONV
*TcFcnInstanceGetReceiveWaitHandle
) (TC_INSTANCE instance
);
64 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceTransmitPackets
) (TC_INSTANCE instance
, TC_PACKETS_BUFFER pBuffer
);
65 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceQueryStatistics
) (TC_INSTANCE instance
, PTC_STATISTICS pStatistics
);
67 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferCreate
) (ULONG size
, PTC_PACKETS_BUFFER pBuffer
);
68 typedef VOID (TC_CALLCONV
*TcFcnPacketsBufferDestroy
) (TC_PACKETS_BUFFER buffer
);
69 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferQueryNextPacket
)(TC_PACKETS_BUFFER buffer
, PTC_PACKET_HEADER pHeader
, PVOID
*ppData
);
70 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferCommitNextPacket
)(TC_PACKETS_BUFFER buffer
, PTC_PACKET_HEADER pHeader
, PVOID pData
);
72 typedef VOID (TC_CALLCONV
*TcFcnStatisticsDestroy
) (TC_STATISTICS statistics
);
73 typedef TC_STATUS (TC_CALLCONV
*TcFcnStatisticsUpdate
) (TC_STATISTICS statistics
);
74 typedef TC_STATUS (TC_CALLCONV
*TcFcnStatisticsQueryValue
) (TC_STATISTICS statistics
, ULONG counterId
, PULONGLONG pValue
);
86 typedef struct _TC_FUNCTIONS
88 TC_API_LOAD_STATUS LoadStatus
;
90 HMODULE hTcApiDllHandle
;
92 TcFcnQueryPortList QueryPortList
;
93 TcFcnFreePortList FreePortList
;
94 TcFcnStatusGetString StatusGetString
;
96 TcFcnPortGetName PortGetName
;
97 TcFcnPortGetDescription PortGetDescription
;
99 TcFcnInstanceOpenByName InstanceOpenByName
;
100 TcFcnInstanceClose InstanceClose
;
101 TcFcnInstanceSetFeature InstanceSetFeature
;
102 TcFcnInstanceQueryFeature InstanceQueryFeature
;
103 TcFcnInstanceReceivePackets InstanceReceivePackets
;
105 TcFcnInstanceGetReceiveWaitHandle InstanceGetReceiveWaitHandle
;
107 TcFcnInstanceTransmitPackets InstanceTransmitPackets
;
108 TcFcnInstanceQueryStatistics InstanceQueryStatistics
;
110 TcFcnPacketsBufferCreate PacketsBufferCreate
;
111 TcFcnPacketsBufferDestroy PacketsBufferDestroy
;
112 TcFcnPacketsBufferQueryNextPacket PacketsBufferQueryNextPacket
;
113 TcFcnPacketsBufferCommitNextPacket PacketsBufferCommitNextPacket
;
115 TcFcnStatisticsDestroy StatisticsDestroy
;
116 TcFcnStatisticsUpdate StatisticsUpdate
;
117 TcFcnStatisticsQueryValue StatisticsQueryValue
;
121 static pcap_if_t
* TcCreatePcapIfFromPort(TC_PORT port
);
122 static int TcSetDatalink(pcap_t
*p
, int dlt
);
123 static int TcGetNonBlock(pcap_t
*p
);
124 static int TcSetNonBlock(pcap_t
*p
, int nonblock
);
125 static void TcCleanup(pcap_t
*p
);
126 static int TcInject(pcap_t
*p
, const void *buf
, int size
);
127 static int TcRead(pcap_t
*p
, int cnt
, pcap_handler callback
, u_char
*user
);
128 static int TcStats(pcap_t
*p
, struct pcap_stat
*ps
);
130 static struct pcap_stat
*TcStatsEx(pcap_t
*p
, int *pcap_stat_size
);
131 static int TcSetBuff(pcap_t
*p
, int dim
);
132 static int TcSetMode(pcap_t
*p
, int mode
);
133 static int TcSetMinToCopy(pcap_t
*p
, int size
);
134 static HANDLE
TcGetReceiveWaitHandle(pcap_t
*p
);
135 static int TcOidGetRequest(pcap_t
*p
, bpf_u_int32 oid
, void *data
, size_t *lenp
);
136 static int TcOidSetRequest(pcap_t
*p
, bpf_u_int32 oid
, const void *data
, size_t *lenp
);
137 static u_int
TcSendqueueTransmit(pcap_t
*p
, pcap_send_queue
*queue
, int sync
);
138 static int TcSetUserBuffer(pcap_t
*p
, int size
);
139 static int TcLiveDump(pcap_t
*p
, char *filename
, int maxsize
, int maxpacks
);
140 static int TcLiveDumpEnded(pcap_t
*p
, int sync
);
141 static PAirpcapHandle
TcGetAirPcapHandle(pcap_t
*p
);
145 TC_FUNCTIONS g_TcFunctions
=
147 TC_API_UNLOADED
, /* LoadStatus */
148 NULL
, /* hTcApiDllHandle */
149 NULL
, /* QueryPortList */
150 NULL
, /* FreePortList */
151 NULL
, /* StatusGetString */
152 NULL
, /* PortGetName */
153 NULL
, /* PortGetDescription */
154 NULL
, /* InstanceOpenByName */
155 NULL
, /* InstanceClose */
156 NULL
, /* InstanceSetFeature */
157 NULL
, /* InstanceQueryFeature */
158 NULL
, /* InstanceReceivePackets */
159 NULL
, /* InstanceGetReceiveWaitHandle */
160 NULL
, /* InstanceTransmitPackets */
161 NULL
, /* InstanceQueryStatistics */
162 NULL
, /* PacketsBufferCreate */
163 NULL
, /* PacketsBufferDestroy */
164 NULL
, /* PacketsBufferQueryNextPacket */
165 NULL
, /* PacketsBufferCommitNextPacket */
166 NULL
, /* StatisticsDestroy */
167 NULL
, /* StatisticsUpdate */
168 NULL
/* StatisticsQueryValue */
171 TC_FUNCTIONS g_TcFunctions
=
173 TC_API_LOADED
, /* LoadStatus */
178 TcPortGetDescription
,
179 TcInstanceOpenByName
,
181 TcInstanceSetFeature
,
182 TcInstanceQueryFeature
,
183 TcInstanceReceivePackets
,
185 TcInstanceGetReceiveWaitHandle
,
187 TcInstanceTransmitPackets
,
188 TcInstanceQueryStatistics
,
189 TcPacketsBufferCreate
,
190 TcPacketsBufferDestroy
,
191 TcPacketsBufferQueryNextPacket
,
192 TcPacketsBufferCommitNextPacket
,
195 TcStatisticsQueryValue
,
199 #define MAX_TC_PACKET_SIZE 9500
201 #pragma pack(push, 1)
203 #define PPH_PH_FLAG_PADDING ((UCHAR)0x01)
204 #define PPH_PH_VERSION ((UCHAR)0x00)
206 typedef struct _PPI_PACKET_HEADER
213 PPI_PACKET_HEADER
, *PPPI_PACKET_HEADER
;
215 typedef struct _PPI_FIELD_HEADER
220 PPI_FIELD_HEADER
, *PPPI_FIELD_HEADER
;
223 #define PPI_FIELD_TYPE_AGGREGATION_EXTENSION ((UCHAR)0x08)
225 typedef struct _PPI_FIELD_AGGREGATION_EXTENSION
229 PPI_FIELD_AGGREGATION_EXTENSION
, *PPPI_FIELD_AGGREGATION_EXTENSION
;
232 #define PPI_FIELD_TYPE_802_3_EXTENSION ((UCHAR)0x09)
234 #define PPI_FLD_802_3_EXT_FLAG_FCS_PRESENT ((ULONG)0x00000001)
236 typedef struct _PPI_FIELD_802_3_EXTENSION
241 PPI_FIELD_802_3_EXTENSION
, *PPPI_FIELD_802_3_EXTENSION
;
243 typedef struct _PPI_HEADER
245 PPI_PACKET_HEADER PacketHeader
;
246 PPI_FIELD_HEADER AggregationFieldHeader
;
247 PPI_FIELD_AGGREGATION_EXTENSION AggregationField
;
248 PPI_FIELD_HEADER Dot3FieldHeader
;
249 PPI_FIELD_802_3_EXTENSION Dot3Field
;
251 PPI_HEADER
, *PPPI_HEADER
;
256 // This wrapper around loadlibrary appends the system folder (usually c:\windows\system32)
257 // to the relative path of the DLL, so that the DLL is always loaded from an absolute path
258 // (It's no longer possible to load airpcap.dll from the application folder).
259 // This solves the DLL Hijacking issue discovered in August 2010
260 // http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html
262 HMODULE
LoadLibrarySafe(LPCTSTR lpFileName
)
264 TCHAR path
[MAX_PATH
];
265 TCHAR fullFileName
[MAX_PATH
];
267 HMODULE hModule
= NULL
;
270 res
= GetSystemDirectory(path
, MAX_PATH
);
275 // some bad failure occurred;
283 // the buffer was not big enough
285 SetLastError(ERROR_INSUFFICIENT_BUFFER
);
289 if (res
+ 1 + _tcslen(lpFileName
) + 1 < MAX_PATH
)
291 memcpy(fullFileName
, path
, res
* sizeof(TCHAR
));
292 fullFileName
[res
] = _T('\\');
293 memcpy(&fullFileName
[res
+ 1], lpFileName
, (_tcslen(lpFileName
) + 1) * sizeof(TCHAR
));
295 hModule
= LoadLibrary(fullFileName
);
299 SetLastError(ERROR_INSUFFICIENT_BUFFER
);
308 * NOTE: this function should be called by the pcap functions that can theoretically
309 * deal with the Tc library for the first time, namely listing the adapters and
310 * opening one. All the other ones (close, read, write, set parameters) work
311 * on an open instance of TC, so we do not care to call this function
313 TC_API_LOAD_STATUS
LoadTcFunctions(void)
315 TC_API_LOAD_STATUS currentStatus
;
319 currentStatus
= InterlockedCompareExchange((LONG
*)&g_TcFunctions
.LoadStatus
, TC_API_LOADING
, TC_API_UNLOADED
);
321 while(currentStatus
== TC_API_LOADING
)
323 currentStatus
= InterlockedCompareExchange((LONG
*)&g_TcFunctions
.LoadStatus
, TC_API_LOADING
, TC_API_LOADING
);
328 * at this point we are either in the LOADED state, unloaded state (i.e. we are the ones loading everything)
331 if(currentStatus
== TC_API_LOADED
)
333 return TC_API_LOADED
;
336 if (currentStatus
== TC_API_CANNOT_LOAD
)
338 return TC_API_CANNOT_LOAD
;
341 currentStatus
= TC_API_CANNOT_LOAD
;
343 g_TcFunctions
.hTcApiDllHandle
= LoadLibrarySafe("TcApi.dll");
344 if (g_TcFunctions
.hTcApiDllHandle
== NULL
) break;
346 g_TcFunctions
.QueryPortList
= (TcFcnQueryPortList
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcQueryPortList");
347 g_TcFunctions
.FreePortList
= (TcFcnFreePortList
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcFreePortList");
349 g_TcFunctions
.StatusGetString
= (TcFcnStatusGetString
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatusGetString");
351 g_TcFunctions
.PortGetName
= (TcFcnPortGetName
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPortGetName");
352 g_TcFunctions
.PortGetDescription
= (TcFcnPortGetDescription
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPortGetDescription");
354 g_TcFunctions
.InstanceOpenByName
= (TcFcnInstanceOpenByName
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceOpenByName");
355 g_TcFunctions
.InstanceClose
= (TcFcnInstanceClose
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceClose");
356 g_TcFunctions
.InstanceSetFeature
= (TcFcnInstanceSetFeature
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceSetFeature");
357 g_TcFunctions
.InstanceQueryFeature
= (TcFcnInstanceQueryFeature
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceQueryFeature");
358 g_TcFunctions
.InstanceReceivePackets
= (TcFcnInstanceReceivePackets
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceReceivePackets");
359 g_TcFunctions
.InstanceGetReceiveWaitHandle
= (TcFcnInstanceGetReceiveWaitHandle
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceGetReceiveWaitHandle");
360 g_TcFunctions
.InstanceTransmitPackets
= (TcFcnInstanceTransmitPackets
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceTransmitPackets");
361 g_TcFunctions
.InstanceQueryStatistics
= (TcFcnInstanceQueryStatistics
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceQueryStatistics");
363 g_TcFunctions
.PacketsBufferCreate
= (TcFcnPacketsBufferCreate
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferCreate");
364 g_TcFunctions
.PacketsBufferDestroy
= (TcFcnPacketsBufferDestroy
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferDestroy");
365 g_TcFunctions
.PacketsBufferQueryNextPacket
= (TcFcnPacketsBufferQueryNextPacket
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferQueryNextPacket");
366 g_TcFunctions
.PacketsBufferCommitNextPacket
= (TcFcnPacketsBufferCommitNextPacket
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferCommitNextPacket");
368 g_TcFunctions
.StatisticsDestroy
= (TcFcnStatisticsDestroy
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsDestroy");
369 g_TcFunctions
.StatisticsUpdate
= (TcFcnStatisticsUpdate
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsUpdate");
370 g_TcFunctions
.StatisticsQueryValue
= (TcFcnStatisticsQueryValue
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsQueryValue");
372 if ( g_TcFunctions
.QueryPortList
== NULL
373 || g_TcFunctions
.FreePortList
== NULL
374 || g_TcFunctions
.StatusGetString
== NULL
375 || g_TcFunctions
.PortGetName
== NULL
376 || g_TcFunctions
.PortGetDescription
== NULL
377 || g_TcFunctions
.InstanceOpenByName
== NULL
378 || g_TcFunctions
.InstanceClose
== NULL
379 || g_TcFunctions
.InstanceSetFeature
== NULL
380 || g_TcFunctions
.InstanceQueryFeature
== NULL
381 || g_TcFunctions
.InstanceReceivePackets
== NULL
382 || g_TcFunctions
.InstanceGetReceiveWaitHandle
== NULL
383 || g_TcFunctions
.InstanceTransmitPackets
== NULL
384 || g_TcFunctions
.InstanceQueryStatistics
== NULL
385 || g_TcFunctions
.PacketsBufferCreate
== NULL
386 || g_TcFunctions
.PacketsBufferDestroy
== NULL
387 || g_TcFunctions
.PacketsBufferQueryNextPacket
== NULL
388 || g_TcFunctions
.PacketsBufferCommitNextPacket
== NULL
389 || g_TcFunctions
.StatisticsDestroy
== NULL
390 || g_TcFunctions
.StatisticsUpdate
== NULL
391 || g_TcFunctions
.StatisticsQueryValue
== NULL
398 * everything got loaded, yay!!
400 currentStatus
= TC_API_LOADED
;
403 if (currentStatus
!= TC_API_LOADED
)
405 if (g_TcFunctions
.hTcApiDllHandle
!= NULL
)
407 FreeLibrary(g_TcFunctions
.hTcApiDllHandle
);
408 g_TcFunctions
.hTcApiDllHandle
= NULL
;
412 InterlockedExchange((LONG
*)&g_TcFunctions
.LoadStatus
, currentStatus
);
414 return currentStatus
;
418 TC_API_LOAD_STATUS
LoadTcFunctions(void)
420 return TC_API_LOADED
;
425 * Private data for capturing on TurboCap devices.
428 TC_INSTANCE TcInstance
;
429 TC_PACKETS_BUFFER TcPacketsBuffer
;
430 ULONG TcAcceptedCount
;
435 TcFindAllDevs(pcap_if_list_t
*devlist
, char *errbuf
)
437 TC_API_LOAD_STATUS loadStatus
;
439 PTC_PORT pPorts
= NULL
;
447 loadStatus
= LoadTcFunctions();
449 if (loadStatus
!= TC_API_LOADED
)
456 * enumerate the ports, and add them to the list
458 status
= g_TcFunctions
.QueryPortList(&pPorts
, &numPorts
);
460 if (status
!= TC_SUCCESS
)
466 for (i
= 0; i
< numPorts
; i
++)
469 * transform the port into an entry in the list
471 dev
= TcCreatePcapIfFromPort(pPorts
[i
]);
474 add_dev(devlist
, dev
->name
, dev
->flags
, dev
->description
, errbuf
);
480 * ignore the result here
482 status
= g_TcFunctions
.FreePortList(pPorts
);
490 static pcap_if_t
* TcCreatePcapIfFromPort(TC_PORT port
)
494 pcap_if_t
*newIf
= NULL
;
496 newIf
= (pcap_if_t
*)malloc(sizeof(*newIf
));
502 memset(newIf
, 0, sizeof(*newIf
));
504 name
= g_TcFunctions
.PortGetName(port
);
505 description
= g_TcFunctions
.PortGetDescription(port
);
507 newIf
->name
= (char*)malloc(strlen(name
) + 1);
508 if (newIf
->name
== NULL
)
514 newIf
->description
= (char*)malloc(strlen(description
) + 1);
515 if (newIf
->description
== NULL
)
522 strcpy(newIf
->name
, name
);
523 strcpy(newIf
->description
, description
);
525 newIf
->addresses
= NULL
;
534 TcActivate(pcap_t
*p
)
536 struct pcap_tc
*pt
= p
->priv
;
539 PPPI_HEADER pPpiHeader
;
544 * No monitor mode on Tc cards; they're Ethernet
547 return PCAP_ERROR_RFMON_NOTSUP
;
550 pt
->PpiPacket
= malloc(sizeof(PPI_HEADER
) + MAX_TC_PACKET_SIZE
);
552 if (pt
->PpiPacket
== NULL
)
554 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Error allocating memory");
559 * Turn a negative snapshot value (invalid), a snapshot value of
560 * 0 (unspecified), or a value bigger than the normal maximum
561 * value, into the maximum allowed value.
563 * If some application really *needs* a bigger snapshot
564 * length, we should just increase MAXIMUM_SNAPLEN.
566 if (p
->snapshot
<= 0 || p
->snapshot
> MAXIMUM_SNAPLEN
)
567 p
->snapshot
= MAXIMUM_SNAPLEN
;
570 * Initialize the PPI fixed fields
572 pPpiHeader
= (PPPI_HEADER
)pt
->PpiPacket
;
573 pPpiHeader
->PacketHeader
.PphDlt
= DLT_EN10MB
;
574 pPpiHeader
->PacketHeader
.PphLength
= sizeof(PPI_HEADER
);
575 pPpiHeader
->PacketHeader
.PphFlags
= 0;
576 pPpiHeader
->PacketHeader
.PphVersion
= 0;
578 pPpiHeader
->AggregationFieldHeader
.PfhLength
= sizeof(PPI_FIELD_AGGREGATION_EXTENSION
);
579 pPpiHeader
->AggregationFieldHeader
.PfhType
= PPI_FIELD_TYPE_AGGREGATION_EXTENSION
;
581 pPpiHeader
->Dot3FieldHeader
.PfhLength
= sizeof(PPI_FIELD_802_3_EXTENSION
);
582 pPpiHeader
->Dot3FieldHeader
.PfhType
= PPI_FIELD_TYPE_802_3_EXTENSION
;
584 status
= g_TcFunctions
.InstanceOpenByName(p
->opt
.device
, &pt
->TcInstance
);
586 if (status
!= TC_SUCCESS
)
588 /* Adapter detected but we are not able to open it. Return failure. */
589 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Error opening TurboCap adapter: %s", g_TcFunctions
.StatusGetString(status
));
593 p
->linktype
= DLT_EN10MB
;
594 p
->dlt_list
= (u_int
*) malloc(sizeof(u_int
) * 2);
596 * If that fails, just leave the list empty.
598 if (p
->dlt_list
!= NULL
) {
599 p
->dlt_list
[0] = DLT_EN10MB
;
600 p
->dlt_list
[1] = DLT_PPI
;
605 * ignore promiscuous mode
611 * ignore all the buffer sizes
617 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_RX_STATUS
, 1);
619 if (status
!= TC_SUCCESS
)
621 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,"Error enabling reception on a TurboCap instance: %s", g_TcFunctions
.StatusGetString(status
));
626 * enable transmission
628 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_TX_STATUS
, 1);
630 * Ignore the error here.
633 p
->inject_op
= TcInject
;
635 * if the timeout is -1, it means immediate return, no timeout
636 * if the timeout is 0, it means INFINITE
639 if (p
->opt
.timeout
== 0)
641 timeout
= 0xFFFFFFFF;
644 if (p
->opt
.timeout
< 0)
647 * we insert a minimal timeout here
653 timeout
= p
->opt
.timeout
;
656 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_READ_TIMEOUT
, timeout
);
658 if (status
!= TC_SUCCESS
)
660 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,"Error setting the read timeout a TurboCap instance: %s", g_TcFunctions
.StatusGetString(status
));
665 p
->setfilter_op
= install_bpf_program
;
666 p
->setdirection_op
= NULL
; /* Not implemented. */
667 p
->set_datalink_op
= TcSetDatalink
;
668 p
->getnonblock_op
= TcGetNonBlock
;
669 p
->setnonblock_op
= TcSetNonBlock
;
670 p
->stats_op
= TcStats
;
672 p
->stats_ex_op
= TcStatsEx
;
673 p
->setbuff_op
= TcSetBuff
;
674 p
->setmode_op
= TcSetMode
;
675 p
->setmintocopy_op
= TcSetMinToCopy
;
676 p
->getevent_op
= TcGetReceiveWaitHandle
;
677 p
->oid_get_request_op
= TcOidGetRequest
;
678 p
->oid_set_request_op
= TcOidSetRequest
;
679 p
->sendqueue_transmit_op
= TcSendqueueTransmit
;
680 p
->setuserbuffer_op
= TcSetUserBuffer
;
681 p
->live_dump_op
= TcLiveDump
;
682 p
->live_dump_ended_op
= TcLiveDumpEnded
;
683 p
->get_airpcap_handle_op
= TcGetAirPcapHandle
;
685 p
->selectable_fd
= -1;
688 p
->cleanup_op
= TcCleanup
;
697 TcCreate(const char *device
, char *ebuf
, int *is_ours
)
700 PTC_PORT pPorts
= NULL
;
706 if (LoadTcFunctions() != TC_API_LOADED
)
709 * XXX - report this as an error rather than as
710 * "not a TurboCap device"?
717 * enumerate the ports, and add them to the list
719 status
= g_TcFunctions
.QueryPortList(&pPorts
, &numPorts
);
721 if (status
!= TC_SUCCESS
)
724 * XXX - report this as an error rather than as
725 * "not a TurboCap device"?
732 for (i
= 0; i
< numPorts
; i
++)
734 if (strcmp(g_TcFunctions
.PortGetName(pPorts
[i
]), device
) == 0)
744 * ignore the result here
746 (void)g_TcFunctions
.FreePortList(pPorts
);
755 /* OK, it's probably ours. */
758 p
= pcap_create_common(ebuf
, sizeof (struct pcap_tc
));
762 p
->activate_op
= TcActivate
;
764 * Set these up front, so that, even if our client tries
765 * to set non-blocking mode before we're activated, or
766 * query the state of non-blocking mode, they get an error,
767 * rather than having the non-blocking mode option set
770 p
->getnonblock_op
= TcGetNonBlock
;
771 p
->setnonblock_op
= TcSetNonBlock
;
775 static int TcSetDatalink(pcap_t
*p
, int dlt
)
778 * We don't have to do any work here; pcap_set_datalink() checks
779 * whether the value is in the list of DLT_ values we
780 * supplied, so we don't have to, and, if it is valid, sets
781 * p->linktype to the new value; we don't have to do anything
782 * in hardware, we just use what's in p->linktype.
784 * We do have to have a routine, however, so that pcap_set_datalink()
785 * doesn't think we don't support setting the link-layer header
791 static int TcGetNonBlock(pcap_t
*p
)
793 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
794 "Non-blocking mode isn't supported for TurboCap ports");
798 static int TcSetNonBlock(pcap_t
*p
, int nonblock
)
800 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
801 "Non-blocking mode isn't supported for TurboCap ports");
805 static void TcCleanup(pcap_t
*p
)
807 struct pcap_tc
*pt
= p
->priv
;
809 if (pt
->TcPacketsBuffer
!= NULL
)
811 g_TcFunctions
.PacketsBufferDestroy(pt
->TcPacketsBuffer
);
812 pt
->TcPacketsBuffer
= NULL
;
814 if (pt
->TcInstance
!= NULL
)
817 * here we do not check for the error values
819 g_TcFunctions
.InstanceClose(pt
->TcInstance
);
820 pt
->TcInstance
= NULL
;
823 if (pt
->PpiPacket
!= NULL
)
826 pt
->PpiPacket
= NULL
;
829 pcap_cleanup_live_common(p
);
832 /* Send a packet to the network */
833 static int TcInject(pcap_t
*p
, const void *buf
, int size
)
835 struct pcap_tc
*pt
= p
->priv
;
837 TC_PACKETS_BUFFER buffer
;
838 TC_PACKET_HEADER header
;
842 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: the TurboCap API does not support packets larger than 64k");
846 status
= g_TcFunctions
.PacketsBufferCreate(sizeof(TC_PACKET_HEADER
) + TC_ALIGN_USHORT_TO_64BIT((USHORT
)size
), &buffer
);
848 if (status
!= TC_SUCCESS
)
850 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcPacketsBufferCreate failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
855 * we assume that the packet is without the checksum, as common with WinPcap
857 memset(&header
, 0, sizeof(header
));
859 header
.Length
= (USHORT
)size
;
860 header
.CapturedLength
= header
.Length
;
862 status
= g_TcFunctions
.PacketsBufferCommitNextPacket(buffer
, &header
, (PVOID
)buf
);
864 if (status
== TC_SUCCESS
)
866 status
= g_TcFunctions
.InstanceTransmitPackets(pt
->TcInstance
, buffer
);
868 if (status
!= TC_SUCCESS
)
870 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcInstanceTransmitPackets failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
875 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcPacketsBufferCommitNextPacket failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
878 g_TcFunctions
.PacketsBufferDestroy(buffer
);
880 if (status
!= TC_SUCCESS
)
890 static int TcRead(pcap_t
*p
, int cnt
, pcap_handler callback
, u_char
*user
)
892 struct pcap_tc
*pt
= p
->priv
;
897 * Has "pcap_breakloop()" been called?
902 * Yes - clear the flag that indicates that it
903 * has, and return -2 to indicate that we were
904 * told to break out of the loop.
910 if (pt
->TcPacketsBuffer
== NULL
)
912 status
= g_TcFunctions
.InstanceReceivePackets(pt
->TcInstance
, &pt
->TcPacketsBuffer
);
913 if (status
!= TC_SUCCESS
)
915 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "read error, TcInstanceReceivePackets failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
922 struct pcap_pkthdr hdr
;
923 TC_PACKET_HEADER tcHeader
;
928 * Has "pcap_breakloop()" been called?
929 * If so, return immediately - if we haven't read any
930 * packets, clear the flag and return -2 to indicate
931 * that we were told to break out of the loop, otherwise
932 * leave the flag set, so that the *next* call will break
933 * out of the loop without having read any packets, and
934 * return the number of packets we've processed so far.
949 if (pt
->TcPacketsBuffer
== NULL
)
954 status
= g_TcFunctions
.PacketsBufferQueryNextPacket(pt
->TcPacketsBuffer
, &tcHeader
, &data
);
956 if (status
== TC_ERROR_END_OF_BUFFER
)
958 g_TcFunctions
.PacketsBufferDestroy(pt
->TcPacketsBuffer
);
959 pt
->TcPacketsBuffer
= NULL
;
963 if (status
!= TC_SUCCESS
)
965 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "read error, TcPacketsBufferQueryNextPacket failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
969 /* No underlaying filtering system. We need to filter on our own */
970 if (p
->fcode
.bf_insns
)
972 filterResult
= pcap_filter(p
->fcode
.bf_insns
, data
, tcHeader
.Length
, tcHeader
.CapturedLength
);
974 if (filterResult
== 0)
979 if (filterResult
> tcHeader
.CapturedLength
)
981 filterResult
= tcHeader
.CapturedLength
;
986 filterResult
= tcHeader
.CapturedLength
;
989 pt
->TcAcceptedCount
++;
991 hdr
.ts
.tv_sec
= (bpf_u_int32
)(tcHeader
.Timestamp
/ (ULONGLONG
)(1000 * 1000 * 1000));
992 hdr
.ts
.tv_usec
= (bpf_u_int32
)((tcHeader
.Timestamp
% (ULONGLONG
)(1000 * 1000 * 1000)) / 1000);
994 if (p
->linktype
== DLT_EN10MB
)
996 hdr
.caplen
= filterResult
;
997 hdr
.len
= tcHeader
.Length
;
998 (*callback
)(user
, &hdr
, data
);
1002 PPPI_HEADER pPpiHeader
= (PPPI_HEADER
)pt
->PpiPacket
;
1003 PVOID data2
= pPpiHeader
+ 1;
1005 pPpiHeader
->AggregationField
.InterfaceId
= TC_PH_FLAGS_RX_PORT_ID(tcHeader
.Flags
);
1006 pPpiHeader
->Dot3Field
.Errors
= tcHeader
.Errors
;
1007 if (tcHeader
.Flags
& TC_PH_FLAGS_CHECKSUM
)
1009 pPpiHeader
->Dot3Field
.Flags
= PPI_FLD_802_3_EXT_FLAG_FCS_PRESENT
;
1013 pPpiHeader
->Dot3Field
.Flags
= 0;
1016 if (filterResult
<= MAX_TC_PACKET_SIZE
)
1018 memcpy(data2
, data
, filterResult
);
1019 hdr
.caplen
= sizeof(PPI_HEADER
) + filterResult
;
1020 hdr
.len
= sizeof(PPI_HEADER
) + tcHeader
.Length
;
1024 memcpy(data2
, data
, MAX_TC_PACKET_SIZE
);
1025 hdr
.caplen
= sizeof(PPI_HEADER
) + MAX_TC_PACKET_SIZE
;
1026 hdr
.len
= sizeof(PPI_HEADER
) + tcHeader
.Length
;
1029 (*callback
)(user
, &hdr
, pt
->PpiPacket
);
1033 if (++n
>= cnt
&& cnt
> 0)
1043 TcStats(pcap_t
*p
, struct pcap_stat
*ps
)
1045 struct pcap_tc
*pt
= p
->priv
;
1046 TC_STATISTICS statistics
;
1051 status
= g_TcFunctions
.InstanceQueryStatistics(pt
->TcInstance
, &statistics
);
1053 if (status
!= TC_SUCCESS
)
1055 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcInstanceQueryStatistics: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1059 memset(&s
, 0, sizeof(s
));
1061 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_TOTAL_RX_PACKETS
, &counter
);
1062 if (status
!= TC_SUCCESS
)
1064 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1067 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1069 s
.ps_recv
= (ULONG
)counter
;
1073 s
.ps_recv
= 0xFFFFFFFF;
1076 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_RX_DROPPED_PACKETS
, &counter
);
1077 if (status
!= TC_SUCCESS
)
1079 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1082 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1084 s
.ps_ifdrop
= (ULONG
)counter
;
1085 s
.ps_drop
= (ULONG
)counter
;
1089 s
.ps_ifdrop
= 0xFFFFFFFF;
1090 s
.ps_drop
= 0xFFFFFFFF;
1093 #if defined(_WIN32) && defined(ENABLE_REMOTE)
1094 s
.ps_capt
= pt
->TcAcceptedCount
;
1103 static struct pcap_stat
*
1104 TcStatsEx(pcap_t
*p
, int *pcap_stat_size
)
1106 struct pcap_tc
*pt
= p
->priv
;
1107 TC_STATISTICS statistics
;
1111 *pcap_stat_size
= sizeof (p
->stat
);
1113 status
= g_TcFunctions
.InstanceQueryStatistics(pt
->TcInstance
, &statistics
);
1115 if (status
!= TC_SUCCESS
)
1117 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcInstanceQueryStatistics: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1121 memset(&p
->stat
, 0, sizeof(p
->stat
));
1123 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_TOTAL_RX_PACKETS
, &counter
);
1124 if (status
!= TC_SUCCESS
)
1126 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1129 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1131 p
->stat
.ps_recv
= (ULONG
)counter
;
1135 p
->stat
.ps_recv
= 0xFFFFFFFF;
1138 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_RX_DROPPED_PACKETS
, &counter
);
1139 if (status
!= TC_SUCCESS
)
1141 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1144 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1146 p
->stat
.ps_ifdrop
= (ULONG
)counter
;
1147 p
->stat
.ps_drop
= (ULONG
)counter
;
1151 p
->stat
.ps_ifdrop
= 0xFFFFFFFF;
1152 p
->stat
.ps_drop
= 0xFFFFFFFF;
1155 #if defined(_WIN32) && defined(ENABLE_REMOTE)
1156 p
->stat
.ps_capt
= pt
->TcAcceptedCount
;
1162 /* Set the dimension of the kernel-level capture buffer */
1164 TcSetBuff(pcap_t
*p
, int dim
)
1167 * XXX turbocap has an internal way of managing buffers.
1168 * And at the moment it's not configurable, so we just
1169 * silently ignore the request to set the buffer.
1175 TcSetMode(pcap_t
*p
, int mode
)
1177 if (mode
!= MODE_CAPT
)
1179 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Mode %u not supported by TurboCap devices. TurboCap only supports capture.", mode
);
1187 TcSetMinToCopy(pcap_t
*p
, int size
)
1189 struct pcap_tc
*pt
= p
->priv
;
1194 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Mintocopy cannot be less than 0.");
1198 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_MINTOCOPY
, (ULONG
)size
);
1200 if (status
!= TC_SUCCESS
)
1202 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error setting the mintocopy: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1209 TcGetReceiveWaitHandle(pcap_t
*p
)
1211 struct pcap_tc
*pt
= p
->priv
;
1213 return g_TcFunctions
.InstanceGetReceiveWaitHandle(pt
->TcInstance
);
1217 TcOidGetRequest(pcap_t
*p
, bpf_u_int32 oid _U_
, void *data _U_
, size_t *lenp _U_
)
1219 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1220 "An OID get request cannot be performed on a TurboCap device");
1225 TcOidSetRequest(pcap_t
*p
, bpf_u_int32 oid _U_
, const void *data _U_
,
1228 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1229 "An OID set request cannot be performed on a TurboCap device");
1234 TcSendqueueTransmit(pcap_t
*p
, pcap_send_queue
*queue _U_
, int sync _U_
)
1236 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1237 "Packets cannot be bulk transmitted on a TurboCap device");
1242 TcSetUserBuffer(pcap_t
*p
, int size _U_
)
1244 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1245 "The user buffer cannot be set on a TurboCap device");
1250 TcLiveDump(pcap_t
*p
, char *filename _U_
, int maxsize _U_
, int maxpacks _U_
)
1252 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1253 "Live packet dumping cannot be performed on a TurboCap device");
1258 TcLiveDumpEnded(pcap_t
*p
, int sync _U_
)
1260 pcap_snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1261 "Live packet dumping cannot be performed on a TurboCap device");
1265 static PAirpcapHandle
1266 TcGetAirPcapHandle(pcap_t
*p _U_
)