2 * Copyright (c) 1998-2007 The TCPDUMP project
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that: (1) source code
6 * distributions retain the above copyright notice and this paragraph
7 * in its entirety, and (2) distributions including binary code include
8 * the above copyright notice and this paragraph in its entirety in
9 * the documentation or other materials provided with the distribution.
10 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND
11 * WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT
12 * LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
13 * FOR A PARTICULAR PURPOSE.
15 * Support for the Light Weight Access Point Protocol as per RFC 5412
17 * Original code by Carles Kishimoto <carles.kishimoto@gmail.com>
24 #include <tcpdump-stdinc.h>
26 #include "interface.h"
28 #include "addrtoname.h"
31 * LWAPP transport (common) header
33 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
34 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
35 * |VER| RID |C|F|L| Frag ID | Length |
36 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
37 * | Status/WLANs | Payload... |
38 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
42 struct lwapp_transport_header
{
50 * LWAPP control header
52 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
53 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
54 * | Message Type | Seq Num | Msg Element Length |
55 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
57 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
58 * | Msg Element [0..N] |
59 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
62 struct lwapp_control_header
{
66 uint8_t session_id
[4];
69 #define LWAPP_VERSION 0
70 #define LWAPP_EXTRACT_VERSION(x) (((x)&0xC0)>>6)
71 #define LWAPP_EXTRACT_RID(x) (((x)&0x38)>>3)
72 #define LWAPP_EXTRACT_CONTROL_BIT(x) (((x)&0x04)>>2)
74 static const struct tok lwapp_header_bits_values
[] = {
75 { 0x01, "Last Fragment Bit"},
76 { 0x02, "Fragment Bit"},
77 { 0x04, "Control Bit"},
81 #define LWAPP_MSGTYPE_DISCOVERY_REQUEST 1
82 #define LWAPP_MSGTYPE_DISCOVERY_RESPONSE 2
83 #define LWAPP_MSGTYPE_JOIN_REQUEST 3
84 #define LWAPP_MSGTYPE_JOIN_RESPONSE 4
85 #define LWAPP_MSGTYPE_JOIN_ACK 5
86 #define LWAPP_MSGTYPE_JOIN_CONFIRM 6
87 #define LWAPP_MSGTYPE_CONFIGURE_REQUEST 10
88 #define LWAPP_MSGTYPE_CONFIGURE_RESPONSE 11
89 #define LWAPP_MSGTYPE_CONF_UPDATE_REQUEST 12
90 #define LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE 13
91 #define LWAPP_MSGTYPE_WTP_EVENT_REQUEST 14
92 #define LWAPP_MSGTYPE_WTP_EVENT_RESPONSE 15
93 #define LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST 16
94 #define LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE 17
95 #define LWAPP_MSGTYPE_ECHO_REQUEST 22
96 #define LWAPP_MSGTYPE_ECHO_RESPONSE 23
97 #define LWAPP_MSGTYPE_IMAGE_DATA_REQUEST 24
98 #define LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE 25
99 #define LWAPP_MSGTYPE_RESET_REQUEST 26
100 #define LWAPP_MSGTYPE_RESET_RESPONSE 27
101 #define LWAPP_MSGTYPE_KEY_UPDATE_REQUEST 30
102 #define LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE 31
103 #define LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST 32
104 #define LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE 33
105 #define LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST 34
106 #define LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE 35
107 #define LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION 36
108 #define LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST 37
109 #define LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE 38
110 #define LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST 39
111 #define LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE 40
113 static const struct tok lwapp_msg_type_values
[] = {
114 { LWAPP_MSGTYPE_DISCOVERY_REQUEST
, "Discovery req"},
115 { LWAPP_MSGTYPE_DISCOVERY_RESPONSE
, "Discovery resp"},
116 { LWAPP_MSGTYPE_JOIN_REQUEST
, "Join req"},
117 { LWAPP_MSGTYPE_JOIN_RESPONSE
, "Join resp"},
118 { LWAPP_MSGTYPE_JOIN_ACK
, "Join ack"},
119 { LWAPP_MSGTYPE_JOIN_CONFIRM
, "Join confirm"},
120 { LWAPP_MSGTYPE_CONFIGURE_REQUEST
, "Configure req"},
121 { LWAPP_MSGTYPE_CONFIGURE_RESPONSE
, "Configure resp"},
122 { LWAPP_MSGTYPE_CONF_UPDATE_REQUEST
, "Update req"},
123 { LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE
, "Update resp"},
124 { LWAPP_MSGTYPE_WTP_EVENT_REQUEST
, "WTP event req"},
125 { LWAPP_MSGTYPE_WTP_EVENT_RESPONSE
, "WTP event resp"},
126 { LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST
, "Change state event req"},
127 { LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE
, "Change state event resp"},
128 { LWAPP_MSGTYPE_ECHO_REQUEST
, "Echo req"},
129 { LWAPP_MSGTYPE_ECHO_RESPONSE
, "Echo resp"},
130 { LWAPP_MSGTYPE_IMAGE_DATA_REQUEST
, "Image data req"},
131 { LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE
, "Image data resp"},
132 { LWAPP_MSGTYPE_RESET_REQUEST
, "Channel status req"},
133 { LWAPP_MSGTYPE_RESET_RESPONSE
, "Channel status resp"},
134 { LWAPP_MSGTYPE_KEY_UPDATE_REQUEST
, "Key update req"},
135 { LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE
, "Key update resp"},
136 { LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST
, "Primary discovery req"},
137 { LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE
, "Primary discovery resp"},
138 { LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST
, "Data transfer req"},
139 { LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE
, "Data transfer resp"},
140 { LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION
, "Clear config ind"},
141 { LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST
, "Wlan config req"},
142 { LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE
, "Wlan config resp"},
143 { LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST
, "Mobile config req"},
144 { LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE
, "Mobile config resp"},
149 * LWAPP message elements
152 * 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
153 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
154 * | Type | Length | Value ... |
155 * +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
157 struct lwapp_message_header
{
163 lwapp_control_print(netdissect_options
*ndo
,
164 const u_char
*pptr
, u_int len
, int has_ap_ident
)
166 const struct lwapp_transport_header
*lwapp_trans_header
;
167 const struct lwapp_control_header
*lwapp_control_header
;
175 /* check if enough bytes for AP identity */
176 ND_TCHECK2(*tptr
, 6);
177 lwapp_trans_header
= (const struct lwapp_transport_header
*)(pptr
+6);
179 lwapp_trans_header
= (const struct lwapp_transport_header
*)pptr
;
181 ND_TCHECK(*lwapp_trans_header
);
184 * Sanity checking of the header.
186 if (LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
) != LWAPP_VERSION
) {
187 ND_PRINT((ndo
, "LWAPP version %u packet not supported",
188 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
)));
193 if (ndo
->ndo_vflag
< 1) {
194 ND_PRINT((ndo
, "LWAPPv%u, %s frame, Flags [%s], length %u",
195 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
196 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
197 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
202 /* ok they seem to want to know everything - lets fully decode it */
203 tlen
=EXTRACT_16BITS(lwapp_trans_header
->length
);
205 ND_PRINT((ndo
, "LWAPPv%u, %s frame, Radio-id %u, Flags [%s], Frag-id %u, length %u",
206 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
207 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
208 LWAPP_EXTRACT_RID(lwapp_trans_header
->version
),
209 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
210 lwapp_trans_header
->frag_id
,
214 ND_PRINT((ndo
, "\n\tAP identity: %s", etheraddr_string(ndo
, tptr
)));
215 tptr
+=sizeof(const struct lwapp_transport_header
)+6;
217 tptr
+=sizeof(const struct lwapp_transport_header
);
222 /* did we capture enough for fully decoding the object header ? */
223 ND_TCHECK2(*tptr
, sizeof(struct lwapp_control_header
));
225 lwapp_control_header
= (const struct lwapp_control_header
*)tptr
;
226 msg_tlen
= EXTRACT_16BITS(lwapp_control_header
->len
);
228 /* print message header */
229 ND_PRINT((ndo
, "\n\t Msg type: %s (%u), Seqnum: %u, Msg len: %d, Session: 0x%08x",
230 tok2str(lwapp_msg_type_values
,"Unknown",lwapp_control_header
->msg_type
),
231 lwapp_control_header
->msg_type
,
232 lwapp_control_header
->seq_num
,
234 EXTRACT_32BITS(lwapp_control_header
->session_id
)));
236 /* did we capture enough for fully decoding the message */
237 ND_TCHECK2(*tptr
, msg_tlen
);
239 /* XXX - Decode sub messages for each message */
240 switch(lwapp_control_header
->msg_type
) {
241 case LWAPP_MSGTYPE_DISCOVERY_REQUEST
:
242 case LWAPP_MSGTYPE_DISCOVERY_RESPONSE
:
243 case LWAPP_MSGTYPE_JOIN_REQUEST
:
244 case LWAPP_MSGTYPE_JOIN_RESPONSE
:
245 case LWAPP_MSGTYPE_JOIN_ACK
:
246 case LWAPP_MSGTYPE_JOIN_CONFIRM
:
247 case LWAPP_MSGTYPE_CONFIGURE_REQUEST
:
248 case LWAPP_MSGTYPE_CONFIGURE_RESPONSE
:
249 case LWAPP_MSGTYPE_CONF_UPDATE_REQUEST
:
250 case LWAPP_MSGTYPE_CONF_UPDATE_RESPONSE
:
251 case LWAPP_MSGTYPE_WTP_EVENT_REQUEST
:
252 case LWAPP_MSGTYPE_WTP_EVENT_RESPONSE
:
253 case LWAPP_MSGTYPE_CHANGE_STATE_EVENT_REQUEST
:
254 case LWAPP_MSGTYPE_CHANGE_STATE_EVENT_RESPONSE
:
255 case LWAPP_MSGTYPE_ECHO_REQUEST
:
256 case LWAPP_MSGTYPE_ECHO_RESPONSE
:
257 case LWAPP_MSGTYPE_IMAGE_DATA_REQUEST
:
258 case LWAPP_MSGTYPE_IMAGE_DATA_RESPONSE
:
259 case LWAPP_MSGTYPE_RESET_REQUEST
:
260 case LWAPP_MSGTYPE_RESET_RESPONSE
:
261 case LWAPP_MSGTYPE_KEY_UPDATE_REQUEST
:
262 case LWAPP_MSGTYPE_KEY_UPDATE_RESPONSE
:
263 case LWAPP_MSGTYPE_PRIMARY_DISCOVERY_REQUEST
:
264 case LWAPP_MSGTYPE_PRIMARY_DISCOVERY_RESPONSE
:
265 case LWAPP_MSGTYPE_DATA_TRANSFER_REQUEST
:
266 case LWAPP_MSGTYPE_DATA_TRANSFER_RESPONSE
:
267 case LWAPP_MSGTYPE_CLEAR_CONFIG_INDICATION
:
268 case LWAPP_MSGTYPE_WLAN_CONFIG_REQUEST
:
269 case LWAPP_MSGTYPE_WLAN_CONFIG_RESPONSE
:
270 case LWAPP_MSGTYPE_MOBILE_CONFIG_REQUEST
:
271 case LWAPP_MSGTYPE_MOBILE_CONFIG_RESPONSE
:
276 tptr
+= sizeof(struct lwapp_control_header
) + msg_tlen
;
277 tlen
-= sizeof(struct lwapp_control_header
) + msg_tlen
;
282 ND_PRINT((ndo
, "\n\t\t packet exceeded snapshot"));
286 lwapp_data_print(netdissect_options
*ndo
,
287 const u_char
*pptr
, u_int len
)
289 const struct lwapp_transport_header
*lwapp_trans_header
;
295 /* check if enough bytes for AP identity */
296 ND_TCHECK2(*tptr
, 6);
297 lwapp_trans_header
= (const struct lwapp_transport_header
*)pptr
;
298 ND_TCHECK(*lwapp_trans_header
);
301 * Sanity checking of the header.
303 if (LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
) != LWAPP_VERSION
) {
304 ND_PRINT((ndo
, "LWAPP version %u packet not supported",
305 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
)));
310 if (ndo
->ndo_vflag
< 1) {
311 ND_PRINT((ndo
, "LWAPPv%u, %s frame, Flags [%s], length %u",
312 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
313 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
314 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
319 /* ok they seem to want to know everything - lets fully decode it */
320 tlen
=EXTRACT_16BITS(lwapp_trans_header
->length
);
322 ND_PRINT((ndo
, "LWAPPv%u, %s frame, Radio-id %u, Flags [%s], Frag-id %u, length %u",
323 LWAPP_EXTRACT_VERSION(lwapp_trans_header
->version
),
324 LWAPP_EXTRACT_CONTROL_BIT(lwapp_trans_header
->version
) ? "Control" : "Data",
325 LWAPP_EXTRACT_RID(lwapp_trans_header
->version
),
326 bittok2str(lwapp_header_bits_values
,"none",(lwapp_trans_header
->version
)&0x07),
327 lwapp_trans_header
->frag_id
,
330 tptr
+=sizeof(const struct lwapp_transport_header
);
331 tlen
-=sizeof(const struct lwapp_transport_header
);
333 /* FIX - An IEEE 802.11 frame follows - hexdump for now */
334 print_unknown_data(ndo
, tptr
, "\n\t", tlen
);
339 ND_PRINT((ndo
, "\n\t\t packet exceeded snapshot"));
344 * c-style: whitesmith