2 * Copyright (c) 2008 CACE Technologies, Davis (California)
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 * notice, this list of conditions and the following disclaimer in the
13 * documentation and/or other materials provided with the distribution.
14 * 3. Neither the name of CACE Technologies nor the names of its
15 * contributors may be used to endorse or promote products derived from
16 * this software without specific prior written permission.
18 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
19 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
20 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
21 * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
22 * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
23 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
24 * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
25 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
26 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
27 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
28 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
50 typedef TC_STATUS (TC_CALLCONV
*TcFcnQueryPortList
) (PTC_PORT
*ppPorts
, PULONG pLength
);
51 typedef TC_STATUS (TC_CALLCONV
*TcFcnFreePortList
) (TC_PORT
*pPorts
);
53 typedef PCHAR (TC_CALLCONV
*TcFcnStatusGetString
) (TC_STATUS status
);
55 typedef PCHAR (TC_CALLCONV
*TcFcnPortGetName
) (TC_PORT port
);
56 typedef PCHAR (TC_CALLCONV
*TcFcnPortGetDescription
) (TC_PORT port
);
58 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceOpenByName
) (PCHAR name
, PTC_INSTANCE pInstance
);
59 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceClose
) (TC_INSTANCE instance
);
60 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceSetFeature
) (TC_INSTANCE instance
, ULONG feature
, ULONG value
);
61 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceQueryFeature
) (TC_INSTANCE instance
, ULONG feature
, PULONG pValue
);
62 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceReceivePackets
) (TC_INSTANCE instance
, PTC_PACKETS_BUFFER pBuffer
);
63 typedef HANDLE (TC_CALLCONV
*TcFcnInstanceGetReceiveWaitHandle
) (TC_INSTANCE instance
);
64 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceTransmitPackets
) (TC_INSTANCE instance
, TC_PACKETS_BUFFER pBuffer
);
65 typedef TC_STATUS (TC_CALLCONV
*TcFcnInstanceQueryStatistics
) (TC_INSTANCE instance
, PTC_STATISTICS pStatistics
);
67 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferCreate
) (ULONG size
, PTC_PACKETS_BUFFER pBuffer
);
68 typedef VOID (TC_CALLCONV
*TcFcnPacketsBufferDestroy
) (TC_PACKETS_BUFFER buffer
);
69 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferQueryNextPacket
)(TC_PACKETS_BUFFER buffer
, PTC_PACKET_HEADER pHeader
, PVOID
*ppData
);
70 typedef TC_STATUS (TC_CALLCONV
*TcFcnPacketsBufferCommitNextPacket
)(TC_PACKETS_BUFFER buffer
, PTC_PACKET_HEADER pHeader
, PVOID pData
);
72 typedef VOID (TC_CALLCONV
*TcFcnStatisticsDestroy
) (TC_STATISTICS statistics
);
73 typedef TC_STATUS (TC_CALLCONV
*TcFcnStatisticsUpdate
) (TC_STATISTICS statistics
);
74 typedef TC_STATUS (TC_CALLCONV
*TcFcnStatisticsQueryValue
) (TC_STATISTICS statistics
, ULONG counterId
, PULONGLONG pValue
);
86 typedef struct _TC_FUNCTIONS
88 TC_API_LOAD_STATUS LoadStatus
;
90 HMODULE hTcApiDllHandle
;
92 TcFcnQueryPortList QueryPortList
;
93 TcFcnFreePortList FreePortList
;
94 TcFcnStatusGetString StatusGetString
;
96 TcFcnPortGetName PortGetName
;
97 TcFcnPortGetDescription PortGetDescription
;
99 TcFcnInstanceOpenByName InstanceOpenByName
;
100 TcFcnInstanceClose InstanceClose
;
101 TcFcnInstanceSetFeature InstanceSetFeature
;
102 TcFcnInstanceQueryFeature InstanceQueryFeature
;
103 TcFcnInstanceReceivePackets InstanceReceivePackets
;
105 TcFcnInstanceGetReceiveWaitHandle InstanceGetReceiveWaitHandle
;
107 TcFcnInstanceTransmitPackets InstanceTransmitPackets
;
108 TcFcnInstanceQueryStatistics InstanceQueryStatistics
;
110 TcFcnPacketsBufferCreate PacketsBufferCreate
;
111 TcFcnPacketsBufferDestroy PacketsBufferDestroy
;
112 TcFcnPacketsBufferQueryNextPacket PacketsBufferQueryNextPacket
;
113 TcFcnPacketsBufferCommitNextPacket PacketsBufferCommitNextPacket
;
115 TcFcnStatisticsDestroy StatisticsDestroy
;
116 TcFcnStatisticsUpdate StatisticsUpdate
;
117 TcFcnStatisticsQueryValue StatisticsQueryValue
;
121 static pcap_if_t
* TcCreatePcapIfFromPort(TC_PORT port
);
122 static int TcSetDatalink(pcap_t
*p
, int dlt
);
123 static int TcGetNonBlock(pcap_t
*p
, char *errbuf
);
124 static int TcSetNonBlock(pcap_t
*p
, int nonblock
, char *errbuf
);
125 static void TcCleanup(pcap_t
*p
);
126 static int TcInject(pcap_t
*p
, const void *buf
, size_t size
);
127 static int TcRead(pcap_t
*p
, int cnt
, pcap_handler callback
, u_char
*user
);
128 static int TcStats(pcap_t
*p
, struct pcap_stat
*ps
);
129 static int TcSetFilter(pcap_t
*p
, struct bpf_program
*fp
);
131 static struct pcap_stat
*TcStatsEx(pcap_t
*p
, int *pcap_stat_size
);
132 static int TcSetBuff(pcap_t
*p
, int dim
);
133 static int TcSetMode(pcap_t
*p
, int mode
);
134 static int TcSetMinToCopy(pcap_t
*p
, int size
);
135 static int TcOidGetRequest(pcap_t
*p
, pcap_oid_data_t
*data
);
136 static int TcOidSetRequest(pcap_t
*p
, pcap_oid_data_t
*data
);
137 static u_int
TcOidSendqueueTransmit(pcap_t
*p
, pcap_send_queue
*queue
, int sync
);
138 //static int TcSetUserBuffer(pcap_t *p, int size);
139 static int TcLiveDump(pcap_t
*p
, char *filename
, int maxsize
, int maxpacks
);
140 static int TcLiveDumpEnded(pcap_t
*p
, int sync
);
141 static PAirpcapHandle
TcGetAirPcapHandle(pcap_t
*p
);
145 TC_FUNCTIONS g_TcFunctions
=
147 TC_API_UNLOADED
, /* LoadStatus */
148 NULL
, /* hTcApiDllHandle */
149 NULL
, /* QueryPortList */
150 NULL
, /* FreePortList */
151 NULL
, /* StatusGetString */
152 NULL
, /* PortGetName */
153 NULL
, /* PortGetDescription */
154 NULL
, /* InstanceOpenByName */
155 NULL
, /* InstanceClose */
156 NULL
, /* InstanceSetFeature */
157 NULL
, /* InstanceQueryFeature */
158 NULL
, /* InstanceReceivePackets */
159 NULL
, /* InstanceGetReceiveWaitHandle */
160 NULL
, /* InstanceTransmitPackets */
161 NULL
, /* InstanceQueryStatistics */
162 NULL
, /* PacketsBufferCreate */
163 NULL
, /* PacketsBufferDestroy */
164 NULL
, /* PacketsBufferQueryNextPacket */
165 NULL
, /* PacketsBufferCommitNextPacket */
166 NULL
, /* StatisticsDestroy */
167 NULL
, /* StatisticsUpdate */
168 NULL
/* StatisticsQueryValue */
171 TC_FUNCTIONS g_TcFunctions
=
173 TC_API_LOADED
, /* LoadStatus */
178 TcPortGetDescription
,
179 TcInstanceOpenByName
,
181 TcInstanceSetFeature
,
182 TcInstanceQueryFeature
,
183 TcInstanceReceivePackets
,
185 TcInstanceGetReceiveWaitHandle
,
187 TcInstanceTransmitPackets
,
188 TcInstanceQueryStatistics
,
189 TcPacketsBufferCreate
,
190 TcPacketsBufferDestroy
,
191 TcPacketsBufferQueryNextPacket
,
192 TcPacketsBufferCommitNextPacket
,
195 TcStatisticsQueryValue
,
199 #define MAX_TC_PACKET_SIZE 9500
201 #pragma pack(push, 1)
203 #define PPH_PH_FLAG_PADDING ((UCHAR)0x01)
204 #define PPH_PH_VERSION ((UCHAR)0x00)
206 typedef struct _PPI_PACKET_HEADER
213 PPI_PACKET_HEADER
, *PPPI_PACKET_HEADER
;
215 typedef struct _PPI_FIELD_HEADER
220 PPI_FIELD_HEADER
, *PPPI_FIELD_HEADER
;
223 #define PPI_FIELD_TYPE_AGGREGATION_EXTENSION ((UCHAR)0x08)
225 typedef struct _PPI_FIELD_AGGREGATION_EXTENSION
229 PPI_FIELD_AGGREGATION_EXTENSION
, *PPPI_FIELD_AGGREGATION_EXTENSION
;
232 #define PPI_FIELD_TYPE_802_3_EXTENSION ((UCHAR)0x09)
234 #define PPI_FLD_802_3_EXT_FLAG_FCS_PRESENT ((ULONG)0x00000001)
236 typedef struct _PPI_FIELD_802_3_EXTENSION
241 PPI_FIELD_802_3_EXTENSION
, *PPPI_FIELD_802_3_EXTENSION
;
243 typedef struct _PPI_HEADER
245 PPI_PACKET_HEADER PacketHeader
;
246 PPI_FIELD_HEADER AggregationFieldHeader
;
247 PPI_FIELD_AGGREGATION_EXTENSION AggregationField
;
248 PPI_FIELD_HEADER Dot3FieldHeader
;
249 PPI_FIELD_802_3_EXTENSION Dot3Field
;
251 PPI_HEADER
, *PPPI_HEADER
;
256 // This wrapper around loadlibrary appends the system folder (usually c:\windows\system32)
257 // to the relative path of the DLL, so that the DLL is always loaded from an absolute path
258 // (It's no longer possible to load airpcap.dll from the application folder).
259 // This solves the DLL Hijacking issue discovered in August 2010
260 // http://blog.metasploit.com/2010/08/exploiting-dll-hijacking-flaws.html
262 HMODULE
LoadLibrarySafe(LPCTSTR lpFileName
)
264 TCHAR path
[MAX_PATH
];
265 TCHAR fullFileName
[MAX_PATH
];
267 HMODULE hModule
= NULL
;
270 res
= GetSystemDirectory(path
, MAX_PATH
);
275 // some bad failure occurred;
283 // the buffer was not big enough
285 SetLastError(ERROR_INSUFFICIENT_BUFFER
);
289 if (res
+ 1 + _tcslen(lpFileName
) + 1 < MAX_PATH
)
291 memcpy(fullFileName
, path
, res
* sizeof(TCHAR
));
292 fullFileName
[res
] = _T('\\');
293 memcpy(&fullFileName
[res
+ 1], lpFileName
, (_tcslen(lpFileName
) + 1) * sizeof(TCHAR
));
295 hModule
= LoadLibrary(fullFileName
);
299 SetLastError(ERROR_INSUFFICIENT_BUFFER
);
308 * NOTE: this function should be called by the pcap functions that can theoretically
309 * deal with the Tc library for the first time, namely listing the adapters and
310 * opening one. All the other ones (close, read, write, set parameters) work
311 * on an open instance of TC, so we do not care to call this function
313 TC_API_LOAD_STATUS
LoadTcFunctions(void)
315 TC_API_LOAD_STATUS currentStatus
;
319 currentStatus
= InterlockedCompareExchange((LONG
*)&g_TcFunctions
.LoadStatus
, TC_API_LOADING
, TC_API_UNLOADED
);
321 while(currentStatus
== TC_API_LOADING
)
323 currentStatus
= InterlockedCompareExchange((LONG
*)&g_TcFunctions
.LoadStatus
, TC_API_LOADING
, TC_API_LOADING
);
328 * at this point we are either in the LOADED state, unloaded state (i.e. we are the ones loading everything)
331 if(currentStatus
== TC_API_LOADED
)
333 return TC_API_LOADED
;
336 if (currentStatus
== TC_API_CANNOT_LOAD
)
338 return TC_API_CANNOT_LOAD
;
341 currentStatus
= TC_API_CANNOT_LOAD
;
343 g_TcFunctions
.hTcApiDllHandle
= LoadLibrarySafe("TcApi.dll");
344 if (g_TcFunctions
.hTcApiDllHandle
== NULL
) break;
346 g_TcFunctions
.QueryPortList
= (TcFcnQueryPortList
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcQueryPortList");
347 g_TcFunctions
.FreePortList
= (TcFcnFreePortList
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcFreePortList");
349 g_TcFunctions
.StatusGetString
= (TcFcnStatusGetString
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatusGetString");
351 g_TcFunctions
.PortGetName
= (TcFcnPortGetName
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPortGetName");
352 g_TcFunctions
.PortGetDescription
= (TcFcnPortGetDescription
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPortGetDescription");
354 g_TcFunctions
.InstanceOpenByName
= (TcFcnInstanceOpenByName
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceOpenByName");
355 g_TcFunctions
.InstanceClose
= (TcFcnInstanceClose
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceClose");
356 g_TcFunctions
.InstanceSetFeature
= (TcFcnInstanceSetFeature
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceSetFeature");
357 g_TcFunctions
.InstanceQueryFeature
= (TcFcnInstanceQueryFeature
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceQueryFeature");
358 g_TcFunctions
.InstanceReceivePackets
= (TcFcnInstanceReceivePackets
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceReceivePackets");
359 g_TcFunctions
.InstanceGetReceiveWaitHandle
= (TcFcnInstanceGetReceiveWaitHandle
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceGetReceiveWaitHandle");
360 g_TcFunctions
.InstanceTransmitPackets
= (TcFcnInstanceTransmitPackets
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceTransmitPackets");
361 g_TcFunctions
.InstanceQueryStatistics
= (TcFcnInstanceQueryStatistics
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcInstanceQueryStatistics");
363 g_TcFunctions
.PacketsBufferCreate
= (TcFcnPacketsBufferCreate
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferCreate");
364 g_TcFunctions
.PacketsBufferDestroy
= (TcFcnPacketsBufferDestroy
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferDestroy");
365 g_TcFunctions
.PacketsBufferQueryNextPacket
= (TcFcnPacketsBufferQueryNextPacket
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferQueryNextPacket");
366 g_TcFunctions
.PacketsBufferCommitNextPacket
= (TcFcnPacketsBufferCommitNextPacket
)GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcPacketsBufferCommitNextPacket");
368 g_TcFunctions
.StatisticsDestroy
= (TcFcnStatisticsDestroy
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsDestroy");
369 g_TcFunctions
.StatisticsUpdate
= (TcFcnStatisticsUpdate
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsUpdate");
370 g_TcFunctions
.StatisticsQueryValue
= (TcFcnStatisticsQueryValue
) GetProcAddress(g_TcFunctions
.hTcApiDllHandle
, "TcStatisticsQueryValue");
372 if ( g_TcFunctions
.QueryPortList
== NULL
373 || g_TcFunctions
.FreePortList
== NULL
374 || g_TcFunctions
.StatusGetString
== NULL
375 || g_TcFunctions
.PortGetName
== NULL
376 || g_TcFunctions
.PortGetDescription
== NULL
377 || g_TcFunctions
.InstanceOpenByName
== NULL
378 || g_TcFunctions
.InstanceClose
== NULL
379 || g_TcFunctions
.InstanceSetFeature
== NULL
380 || g_TcFunctions
.InstanceQueryFeature
== NULL
381 || g_TcFunctions
.InstanceReceivePackets
== NULL
382 || g_TcFunctions
.InstanceGetReceiveWaitHandle
== NULL
383 || g_TcFunctions
.InstanceTransmitPackets
== NULL
384 || g_TcFunctions
.InstanceQueryStatistics
== NULL
385 || g_TcFunctions
.PacketsBufferCreate
== NULL
386 || g_TcFunctions
.PacketsBufferDestroy
== NULL
387 || g_TcFunctions
.PacketsBufferQueryNextPacket
== NULL
388 || g_TcFunctions
.PacketsBufferCommitNextPacket
== NULL
389 || g_TcFunctions
.StatisticsDestroy
== NULL
390 || g_TcFunctions
.StatisticsUpdate
== NULL
391 || g_TcFunctions
.StatisticsQueryValue
== NULL
398 * everything got loaded, yay!!
400 currentStatus
= TC_API_LOADED
;
403 if (currentStatus
!= TC_API_LOADED
)
405 if (g_TcFunctions
.hTcApiDllHandle
!= NULL
)
407 FreeLibrary(g_TcFunctions
.hTcApiDllHandle
);
408 g_TcFunctions
.hTcApiDllHandle
= NULL
;
412 InterlockedExchange((LONG
*)&g_TcFunctions
.LoadStatus
, currentStatus
);
414 return currentStatus
;
418 TC_API_LOAD_STATUS
LoadTcFunctions(void)
420 return TC_API_LOADED
;
425 * Private data for capturing on TurboCap devices.
428 TC_INSTANCE TcInstance
;
429 TC_PACKETS_BUFFER TcPacketsBuffer
;
430 ULONG TcAcceptedCount
;
435 TcFindAllDevs(pcap_if_t
**alldevsp
, char *errbuf
)
437 TC_API_LOAD_STATUS loadStatus
;
439 PTC_PORT pPorts
= NULL
;
442 pcap_if_t
*dev
, *cursor
;
447 loadStatus
= LoadTcFunctions();
449 if (loadStatus
!= TC_API_LOADED
)
456 * enumerate the ports, and add them to the list
458 status
= g_TcFunctions
.QueryPortList(&pPorts
, &numPorts
);
460 if (status
!= TC_SUCCESS
)
466 for (i
= 0; i
< numPorts
; i
++)
469 * transform the port into an entry in the list
471 dev
= TcCreatePcapIfFromPort(pPorts
[i
]);
476 * append it at the end
478 if (*alldevsp
== NULL
)
484 for(cursor
= *alldevsp
; cursor
->next
!= NULL
; cursor
= cursor
->next
);
493 * ignore the result here
495 status
= g_TcFunctions
.FreePortList(pPorts
);
503 static pcap_if_t
* TcCreatePcapIfFromPort(TC_PORT port
)
507 pcap_if_t
*newIf
= NULL
;
509 newIf
= (pcap_if_t
*)malloc(sizeof(*newIf
));
515 memset(newIf
, 0, sizeof(*newIf
));
517 name
= g_TcFunctions
.PortGetName(port
);
518 description
= g_TcFunctions
.PortGetDescription(port
);
520 newIf
->name
= (char*)malloc(strlen(name
) + 1);
521 if (newIf
->name
== NULL
)
527 newIf
->description
= (char*)malloc(strlen(description
) + 1);
528 if (newIf
->description
== NULL
)
535 strcpy(newIf
->name
, name
);
536 strcpy(newIf
->description
, description
);
538 newIf
->addresses
= NULL
;
547 TcActivate(pcap_t
*p
)
549 struct pcap_tc
*pt
= p
->priv
;
552 PPPI_HEADER pPpiHeader
;
557 * No monitor mode on Tc cards; they're Ethernet
560 return (PCAP_ERROR_RFMON_NOTSUP
);
563 pt
->PpiPacket
= (PCHAR
)malloc(sizeof(PPI_HEADER
) + MAX_TC_PACKET_SIZE
);
565 if (pt
->PpiPacket
== NULL
)
567 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Error allocating memory");
572 * Initialize the PPI fixed fields
574 pPpiHeader
= (PPPI_HEADER
)pt
->PpiPacket
;
575 pPpiHeader
->PacketHeader
.PphDlt
= DLT_EN10MB
;
576 pPpiHeader
->PacketHeader
.PphLength
= sizeof(PPI_HEADER
);
577 pPpiHeader
->PacketHeader
.PphFlags
= 0;
578 pPpiHeader
->PacketHeader
.PphVersion
= 0;
580 pPpiHeader
->AggregationFieldHeader
.PfhLength
= sizeof(PPI_FIELD_AGGREGATION_EXTENSION
);
581 pPpiHeader
->AggregationFieldHeader
.PfhType
= PPI_FIELD_TYPE_AGGREGATION_EXTENSION
;
583 pPpiHeader
->Dot3FieldHeader
.PfhLength
= sizeof(PPI_FIELD_802_3_EXTENSION
);
584 pPpiHeader
->Dot3FieldHeader
.PfhType
= PPI_FIELD_TYPE_802_3_EXTENSION
;
586 status
= g_TcFunctions
.InstanceOpenByName(p
->opt
.source
, &pt
->TcInstance
);
588 if (status
!= TC_SUCCESS
)
590 /* Adapter detected but we are not able to open it. Return failure. */
591 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Error opening TurboCap adapter: %s", g_TcFunctions
.StatusGetString(status
));
595 p
->linktype
= DLT_EN10MB
;
596 p
->dlt_list
= (u_int
*) malloc(sizeof(u_int
) * 2);
598 * If that fails, just leave the list empty.
600 if (p
->dlt_list
!= NULL
) {
601 p
->dlt_list
[0] = DLT_EN10MB
;
602 p
->dlt_list
[1] = DLT_PPI
;
607 * ignore promiscuous mode
613 * ignore all the buffer sizes
619 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_RX_STATUS
, 1);
621 if (status
!= TC_SUCCESS
)
623 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,"Error enabling reception on a TurboCap instance: %s", g_TcFunctions
.StatusGetString(status
));
628 * enable transmission
630 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_TX_STATUS
, 1);
632 * Ignore the error here.
635 p
->inject_op
= TcInject
;
637 * if the timeout is -1, it means immediate return, no timeout
638 * if the timeout is 0, it means INFINITE
641 if (p
->opt
.timeout
== 0)
643 timeout
= 0xFFFFFFFF;
646 if (p
->opt
.timeout
< 0)
649 * we insert a minimal timeout here
655 timeout
= p
->opt
.timeout
;
658 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_READ_TIMEOUT
, timeout
);
660 if (status
!= TC_SUCCESS
)
662 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,"Error setting the read timeout a TurboCap instance: %s", g_TcFunctions
.StatusGetString(status
));
667 p
->setfilter_op
= TcSetFilter
;
668 p
->setdirection_op
= NULL
; /* Not implemented. */
669 p
->set_datalink_op
= TcSetDatalink
;
670 p
->getnonblock_op
= TcGetNonBlock
;
671 p
->setnonblock_op
= TcSetNonBlock
;
672 p
->stats_op
= TcStats
;
674 p
->stats_ex_op
= TcStatsEx
;
675 p
->setbuff_op
= TcSetBuff
;
676 p
->setmode_op
= TcSetMode
;
677 p
->setmintocopy_op
= TcSetMinToCopy
;
678 p
->getevent_op
= TcGetReceiveWaitHandle
;
679 p
->oid_get_request_op
= TcOidGetRequest
;
680 p
->oid_set_request_op
= TcOidSetRequest
;
681 p
->sendqueue_transmit_op
= TcOidSendqueueTransmit
;
682 p
->setuserbuffer_op
= TcSetUserBuffer
;
683 p
->live_dump_op
= TcLiveDump
;
684 p
->live_dump_ended_op
= TcLiveDumpEnded
;
685 p
->get_airpcap_handle_op
= TcGetAirPcapHandle
;
687 p
->selectable_fd
= -1;
690 p
->cleanup_op
= TcCleanup
;
699 TcCreate(const char *device
, char *ebuf
, int *is_ours
)
702 PTC_PORT pPorts
= NULL
;
708 if (LoadTcFunctions() != TC_API_LOADED
)
711 * XXX - report this as an error rather than as
712 * "not a TurboCap device"?
719 * enumerate the ports, and add them to the list
721 status
= g_TcFunctions
.QueryPortList(&pPorts
, &numPorts
);
723 if (status
!= TC_SUCCESS
)
726 * XXX - report this as an error rather than as
727 * "not a TurboCap device"?
734 for (i
= 0; i
< numPorts
; i
++)
736 if (strcmp(g_TcFunctions
.PortGetName(pPorts
[i
]), device
) == 0)
746 * ignore the result here
748 (void)g_TcFunctions
.FreePortList(pPorts
);
757 /* OK, it's probably ours. */
760 p
= pcap_create_common(device
, ebuf
, sizeof (struct pcap_tc
));
764 p
->activate_op
= TcActivate
;
768 static int TcSetDatalink(pcap_t
*p
, int dlt
)
771 * always return 0, as the check is done by pcap_set_datalink
776 static int TcGetNonBlock(pcap_t
*p
, char *errbuf
)
778 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
779 "Getting the non blocking status is not available for TurboCap ports");
780 snprintf(errbuf
, PCAP_ERRBUF_SIZE
,
781 "Getting the non blocking status is not available for TurboCap ports");
785 static int TcSetNonBlock(pcap_t
*p
, int nonblock
, char *errbuf
)
787 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
788 "Setting the non blocking status is not available for TurboCap ports");
789 snprintf(errbuf
, PCAP_ERRBUF_SIZE
,
790 "Setting the non blocking status is not available for TurboCap ports");
795 static void TcCleanup(pcap_t
*p
)
797 struct pcap_tc
*pt
= p
->priv
;
799 if (pt
->TcPacketsBuffer
!= NULL
)
801 g_TcFunctions
.PacketsBufferDestroy(pt
->TcPacketsBuffer
);
802 pt
->TcPacketsBuffer
= NULL
;
804 if (pt
->TcInstance
!= NULL
)
807 * here we do not check for the error values
809 g_TcFunctions
.InstanceClose(pt
->TcInstance
);
810 pt
->TcInstance
= NULL
;
813 if (pt
->PpiPacket
!= NULL
)
816 pt
->PpiPacket
= NULL
;
819 pcap_cleanup_live_common(p
);
822 /* Send a packet to the network */
823 static int TcInject(pcap_t
*p
, const void *buf
, size_t size
)
825 struct pcap_tc
*pt
= p
->priv
;
827 TC_PACKETS_BUFFER buffer
;
828 TC_PACKET_HEADER header
;
832 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: the TurboCap API does not support packets larger than 64k");
836 status
= g_TcFunctions
.PacketsBufferCreate(sizeof(TC_PACKET_HEADER
) + TC_ALIGN_USHORT_TO_64BIT((USHORT
)size
), &buffer
);
838 if (status
!= TC_SUCCESS
)
840 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcPacketsBufferCreate failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
845 * we assume that the packet is without the checksum, as common with WinPcap
847 memset(&header
, 0, sizeof(header
));
849 header
.Length
= (USHORT
)size
;
850 header
.CapturedLength
= header
.Length
;
852 status
= g_TcFunctions
.PacketsBufferCommitNextPacket(buffer
, &header
, (PVOID
)buf
);
854 if (status
== TC_SUCCESS
)
856 status
= g_TcFunctions
.InstanceTransmitPackets(pt
->TcInstance
, buffer
);
858 if (status
!= TC_SUCCESS
)
860 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcInstanceTransmitPackets failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
865 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "send error: TcPacketsBufferCommitNextPacket failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
868 g_TcFunctions
.PacketsBufferDestroy(buffer
);
870 if (status
!= TC_SUCCESS
)
880 static int TcRead(pcap_t
*p
, int cnt
, pcap_handler callback
, u_char
*user
)
882 struct pcap_tc
*pt
= p
->priv
;
887 * Has "pcap_breakloop()" been called?
892 * Yes - clear the flag that indicates that it
893 * has, and return -2 to indicate that we were
894 * told to break out of the loop.
900 if (pt
->TcPacketsBuffer
== NULL
)
902 status
= g_TcFunctions
.InstanceReceivePackets(pt
->TcInstance
, &pt
->TcPacketsBuffer
);
903 if (status
!= TC_SUCCESS
)
905 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "read error, TcInstanceReceivePackets failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
912 struct pcap_pkthdr hdr
;
913 TC_PACKET_HEADER tcHeader
;
918 * Has "pcap_breakloop()" been called?
919 * If so, return immediately - if we haven't read any
920 * packets, clear the flag and return -2 to indicate
921 * that we were told to break out of the loop, otherwise
922 * leave the flag set, so that the *next* call will break
923 * out of the loop without having read any packets, and
924 * return the number of packets we've processed so far.
939 if (pt
->TcPacketsBuffer
== NULL
)
944 status
= g_TcFunctions
.PacketsBufferQueryNextPacket(pt
->TcPacketsBuffer
, &tcHeader
, &data
);
946 if (status
== TC_ERROR_END_OF_BUFFER
)
948 g_TcFunctions
.PacketsBufferDestroy(pt
->TcPacketsBuffer
);
949 pt
->TcPacketsBuffer
= NULL
;
953 if (status
!= TC_SUCCESS
)
955 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "read error, TcPacketsBufferQueryNextPacket failure: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
959 /* No underlaying filtering system. We need to filter on our own */
960 if (p
->fcode
.bf_insns
)
962 filterResult
= bpf_filter(p
->fcode
.bf_insns
, data
, tcHeader
.Length
, tcHeader
.CapturedLength
);
964 if (filterResult
== 0)
969 if (filterResult
> tcHeader
.CapturedLength
)
971 filterResult
= tcHeader
.CapturedLength
;
976 filterResult
= tcHeader
.CapturedLength
;
979 pt
->TcAcceptedCount
++;
981 hdr
.ts
.tv_sec
= (bpf_u_int32
)(tcHeader
.Timestamp
/ (ULONGLONG
)(1000 * 1000 * 1000));
982 hdr
.ts
.tv_usec
= (bpf_u_int32
)((tcHeader
.Timestamp
% (ULONGLONG
)(1000 * 1000 * 1000)) / 1000);
984 if (p
->linktype
== DLT_EN10MB
)
986 hdr
.caplen
= filterResult
;
987 hdr
.len
= tcHeader
.Length
;
988 (*callback
)(user
, &hdr
, data
);
992 PPPI_HEADER pPpiHeader
= (PPPI_HEADER
)pt
->PpiPacket
;
993 PVOID data2
= pPpiHeader
+ 1;
995 pPpiHeader
->AggregationField
.InterfaceId
= TC_PH_FLAGS_RX_PORT_ID(tcHeader
.Flags
);
996 pPpiHeader
->Dot3Field
.Errors
= tcHeader
.Errors
;
997 if (tcHeader
.Flags
& TC_PH_FLAGS_CHECKSUM
)
999 pPpiHeader
->Dot3Field
.Flags
= PPI_FLD_802_3_EXT_FLAG_FCS_PRESENT
;
1003 pPpiHeader
->Dot3Field
.Flags
= 0;
1006 if (filterResult
<= MAX_TC_PACKET_SIZE
)
1008 memcpy(data2
, data
, filterResult
);
1009 hdr
.caplen
= sizeof(PPI_HEADER
) + filterResult
;
1010 hdr
.len
= sizeof(PPI_HEADER
) + tcHeader
.Length
;
1014 memcpy(data2
, data
, MAX_TC_PACKET_SIZE
);
1015 hdr
.caplen
= sizeof(PPI_HEADER
) + MAX_TC_PACKET_SIZE
;
1016 hdr
.len
= sizeof(PPI_HEADER
) + tcHeader
.Length
;
1019 (*callback
)(user
, &hdr
, pt
->PpiPacket
);
1023 if (++n
>= cnt
&& cnt
> 0)
1033 TcStats(pcap_t
*p
, struct pcap_stat
*ps
)
1035 struct pcap_tc
*pt
= p
->priv
;
1036 TC_STATISTICS statistics
;
1041 status
= g_TcFunctions
.InstanceQueryStatistics(pt
->TcInstance
, &statistics
);
1043 if (status
!= TC_SUCCESS
)
1045 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcInstanceQueryStatistics: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1049 memset(&s
, 0, sizeof(s
));
1051 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_TOTAL_RX_PACKETS
, &counter
);
1052 if (status
!= TC_SUCCESS
)
1054 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1057 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1059 s
.ps_recv
= (ULONG
)counter
;
1063 s
.ps_recv
= 0xFFFFFFFF;
1066 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_RX_DROPPED_PACKETS
, &counter
);
1067 if (status
!= TC_SUCCESS
)
1069 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1072 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1074 s
.ps_ifdrop
= (ULONG
)counter
;
1075 s
.ps_drop
= (ULONG
)counter
;
1079 s
.ps_ifdrop
= 0xFFFFFFFF;
1080 s
.ps_drop
= 0xFFFFFFFF;
1083 #if defined(_WIN32) && defined(HAVE_REMOTE)
1084 s
.ps_capt
= pt
->TcAcceptedCount
;
1093 * We filter at user level, since the kernel driver does't process the packets
1096 TcSetFilter(pcap_t
*p
, struct bpf_program
*fp
)
1100 strncpy(p
->errbuf
, "setfilter: No filter specified", sizeof(p
->errbuf
));
1104 /* Install a user level filter */
1105 if (install_bpf_program(p
, fp
) < 0)
1107 snprintf(p
->errbuf
, sizeof(p
->errbuf
),
1108 "setfilter, unable to install the filter: %s", pcap_strerror(errno
));
1116 static struct pcap_stat
*
1117 TcStatsEx(pcap_t
*p
, int *pcap_stat_size
)
1119 struct pcap_tc
*pt
= p
->priv
;
1120 TC_STATISTICS statistics
;
1124 *pcap_stat_size
= sizeof (p
->stat
);
1126 status
= g_TcFunctions
.InstanceQueryStatistics(pt
->TcInstance
, &statistics
);
1128 if (status
!= TC_SUCCESS
)
1130 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcInstanceQueryStatistics: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1134 memset(&p
->stat
, 0, sizeof(p
->stat
));
1136 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_TOTAL_RX_PACKETS
, &counter
);
1137 if (status
!= TC_SUCCESS
)
1139 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1142 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1144 p
->stat
.ps_recv
= (ULONG
)counter
;
1148 p
->stat
.ps_recv
= 0xFFFFFFFF;
1151 status
= g_TcFunctions
.StatisticsQueryValue(statistics
, TC_COUNTER_INSTANCE_RX_DROPPED_PACKETS
, &counter
);
1152 if (status
!= TC_SUCCESS
)
1154 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error in TcStatisticsQueryValue: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1157 if (counter
<= (ULONGLONG
)0xFFFFFFFF)
1159 p
->stat
.ps_ifdrop
= (ULONG
)counter
;
1160 p
->stat
.ps_drop
= (ULONG
)counter
;
1164 p
->stat
.ps_ifdrop
= 0xFFFFFFFF;
1165 p
->stat
.ps_drop
= 0xFFFFFFFF;
1169 p
->stat
.ps_capt
= pt
->TcAcceptedCount
;
1175 /* Set the dimension of the kernel-level capture buffer */
1177 TcSetBuff(pcap_t
*p
, int dim
)
1180 * XXX turbocap has an internal way of managing buffers.
1181 * And at the moment it's not configurable, so we just
1182 * silently ignore the request to set the buffer.
1188 TcSetMode(pcap_t
*p
, int mode
)
1190 if (mode
!= MODE_CAPT
)
1192 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Mode %u not supported by TurboCap devices. TurboCap only supports capture.", mode
);
1200 TcSetMinToCopy(pcap_t
*p
, int size
)
1202 struct pcap_tc
*pt
= p
->priv
;
1207 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "Mintocopy cannot be less than 0.");
1211 status
= g_TcFunctions
.InstanceSetFeature(pt
->TcInstance
, TC_INST_FT_MINTOCOPY
, (ULONG
)size
);
1213 if (status
!= TC_SUCCESS
)
1215 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
, "TurboCap error setting the mintocopy: %s (%08x)", g_TcFunctions
.StatusGetString(status
), status
);
1222 TcGetReceiveWaitHandle(pcap_t
*p
)
1224 struct pcap_tc
*pt
= p
->priv
;
1226 return g_TcFunctions
.InstanceGetReceiveWaitHandle(pt
->TcInstance
);
1230 TcOidGetRequest(pcap_t
*p
, pcap_oid_data_t
*data _U_
)
1232 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1233 "An OID get request cannot be performed on a TurboCap device");
1234 return (PCAP_ERROR
);
1238 TcOidSetRequest(pcap_t
*p
, pcap_oid_data_t
*data _U_
)
1240 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1241 "An OID set request cannot be performed on a TurboCap device");
1242 return (PCAP_ERROR
);
1246 TcOidSendqueueTransmit(pcap_t
*p
, pcap_send_queue
*queue _U_
, int sync _U_
)
1248 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1249 "Packets cannot be bulk transmitted on a TurboCap device");
1254 TcSetUserBuffer(pcap_t
*p
, int size _U_
)
1256 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1257 "The user buffer cannot be set on a TurboCap device");
1262 TcLiveDump(pcap_t
*p
, char *filename _U_
, int maxsize _U_
, int maxpacks _U_
)
1264 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1265 "Live packet dumping cannot be performed on a TurboCap device");
1270 TcLiveDumpEnded(pcap_t
*p
, int sync _U_
)
1272 snprintf(p
->errbuf
, PCAP_ERRBUF_SIZE
,
1273 "Live packet dumping cannot be performed on a TurboCap device");
1277 static PAirpcapHandle
1278 TcGetAirPcapHandle(pcap_t
*p _U_
)