2 * Copyright (c) 1990, 1991, 1993, 1994, 1995, 1996, 1997
3 * The Regents of the University of California. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that: (1) source code distributions
7 * retain the above copyright notice and this paragraph in its entirety, (2)
8 * distributions including binary code include the above copyright notice and
9 * this paragraph in its entirety in the documentation or other materials
10 * provided with the distribution, and (3) all advertising materials mentioning
11 * features or use of this software display the following acknowledgement:
12 * ``This product includes software developed by the University of California,
13 * Lawrence Berkeley Laboratory and its contributors.'' Neither the name of
14 * the University nor the names of its contributors may be used to endorse
15 * or promote products derived from this software without specific prior
17 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED
18 * WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
19 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
21 * Extensively modified by Motonori Shindo (mshindo@mshindo.net) for more
22 * complete PPP support.
25 /* \summary: Point to Point Protocol (PPP) printer */
29 * o resolve XXX as much as possible
38 #include "netdissect-stdinc.h"
41 #include <net/slcompress.h>
42 #include <net/if_ppp.h>
47 #include "netdissect.h"
49 #include "addrtoname.h"
52 #include "ethertype.h"
54 #include "netdissect-alloc.h"
57 * The following constants are defined by IANA. Please refer to
58 * https://www.isi.edu/in-notes/iana/assignments/ppp-numbers
59 * for the up-to-date information.
62 /* Protocol Codes defined in ppp.h */
64 static const struct tok ppptype2str
[] = {
68 { PPP_DECNET
, "DECNET" },
69 { PPP_APPLE
, "APPLE" },
71 { PPP_VJC
, "VJC IP" },
72 { PPP_VJNC
, "VJNC IP" },
73 { PPP_BRPDU
, "BRPDU" },
75 { PPP_VINES
, "VINES" },
76 { PPP_MPLS_UCAST
, "MPLS" },
77 { PPP_MPLS_MCAST
, "MPLS" },
78 { PPP_COMP
, "Compressed"},
82 { PPP_HELLO
, "HELLO" },
83 { PPP_LUXCOM
, "LUXCOM" },
86 { PPP_OSICP
, "OSICP" },
88 { PPP_DECNETCP
, "DECNETCP" },
89 { PPP_APPLECP
, "APPLECP" },
90 { PPP_IPXCP
, "IPXCP" },
91 { PPP_STIICP
, "STIICP" },
92 { PPP_VINESCP
, "VINESCP" },
93 { PPP_IPV6CP
, "IP6CP" },
94 { PPP_MPLSCP
, "MPLSCP" },
101 { PPP_SPAP
, "SPAP" },
102 { PPP_SPAP_OLD
, "Old-SPAP" },
103 { PPP_BACP
, "BACP" },
105 { PPP_MPCP
, "MLPPP-CP" },
110 /* Control Protocols (LCP/IPCP/CCP etc.) Codes defined in RFC 1661 */
112 #define CPCODES_VEXT 0 /* Vendor-Specific (RFC2153) */
113 #define CPCODES_CONF_REQ 1 /* Configure-Request */
114 #define CPCODES_CONF_ACK 2 /* Configure-Ack */
115 #define CPCODES_CONF_NAK 3 /* Configure-Nak */
116 #define CPCODES_CONF_REJ 4 /* Configure-Reject */
117 #define CPCODES_TERM_REQ 5 /* Terminate-Request */
118 #define CPCODES_TERM_ACK 6 /* Terminate-Ack */
119 #define CPCODES_CODE_REJ 7 /* Code-Reject */
120 #define CPCODES_PROT_REJ 8 /* Protocol-Reject (LCP only) */
121 #define CPCODES_ECHO_REQ 9 /* Echo-Request (LCP only) */
122 #define CPCODES_ECHO_RPL 10 /* Echo-Reply (LCP only) */
123 #define CPCODES_DISC_REQ 11 /* Discard-Request (LCP only) */
124 #define CPCODES_ID 12 /* Identification (LCP only) RFC1570 */
125 #define CPCODES_TIME_REM 13 /* Time-Remaining (LCP only) RFC1570 */
126 #define CPCODES_RESET_REQ 14 /* Reset-Request (CCP only) RFC1962 */
127 #define CPCODES_RESET_REP 15 /* Reset-Reply (CCP only) */
129 static const struct tok cpcodes
[] = {
130 {CPCODES_VEXT
, "Vendor-Extension"}, /* RFC2153 */
131 {CPCODES_CONF_REQ
, "Conf-Request"},
132 {CPCODES_CONF_ACK
, "Conf-Ack"},
133 {CPCODES_CONF_NAK
, "Conf-Nack"},
134 {CPCODES_CONF_REJ
, "Conf-Reject"},
135 {CPCODES_TERM_REQ
, "Term-Request"},
136 {CPCODES_TERM_ACK
, "Term-Ack"},
137 {CPCODES_CODE_REJ
, "Code-Reject"},
138 {CPCODES_PROT_REJ
, "Prot-Reject"},
139 {CPCODES_ECHO_REQ
, "Echo-Request"},
140 {CPCODES_ECHO_RPL
, "Echo-Reply"},
141 {CPCODES_DISC_REQ
, "Disc-Req"},
142 {CPCODES_ID
, "Ident"}, /* RFC1570 */
143 {CPCODES_TIME_REM
, "Time-Rem"}, /* RFC1570 */
144 {CPCODES_RESET_REQ
, "Reset-Req"}, /* RFC1962 */
145 {CPCODES_RESET_REP
, "Reset-Ack"}, /* RFC1962 */
149 /* LCP Config Options */
151 #define LCPOPT_VEXT 0
153 #define LCPOPT_ACCM 2
157 #define LCPOPT_DEP6 6
159 #define LCPOPT_ACFC 8
160 #define LCPOPT_FCSALT 9
161 #define LCPOPT_SDP 10
162 #define LCPOPT_NUMMODE 11
163 #define LCPOPT_DEP12 12
164 #define LCPOPT_CBACK 13
165 #define LCPOPT_DEP14 14
166 #define LCPOPT_DEP15 15
167 #define LCPOPT_DEP16 16
168 #define LCPOPT_MLMRRU 17
169 #define LCPOPT_MLSSNHF 18
170 #define LCPOPT_MLED 19
171 #define LCPOPT_PROP 20
172 #define LCPOPT_DCEID 21
173 #define LCPOPT_MPP 22
175 #define LCPOPT_LCPAOPT 24
176 #define LCPOPT_COBS 25
178 #define LCPOPT_MLHF 27
179 #define LCPOPT_I18N 28
180 #define LCPOPT_SDLOS 29
181 #define LCPOPT_PPPMUX 30
183 static const char *lcpconfopts
[] = {
184 "Vend-Ext", /* (0) */
187 "Auth-Prot", /* (3) */
188 "Qual-Prot", /* (4) */
189 "Magic-Num", /* (5) */
190 "deprecated(6)", /* used to be a Quality Protocol */
195 "Num-Mode", /* (11) */
196 "deprecated(12)", /* used to be a Multi-Link-Procedure*/
197 "Call-Back", /* (13) */
198 "deprecated(14)", /* used to be a Connect-Time */
199 "deprecated(15)", /* used to be a Compund-Frames */
200 "deprecated(16)", /* used to be a Nominal-Data-Encap */
202 "12-Bit seq #", /* (18) */
203 "End-Disc", /* (19) */
204 "Proprietary", /* (20) */
207 "Link-Disc", /* (23) */
208 "LCP-Auth-Opt", /* (24) */
210 "Prefix-elision", /* (26) */
211 "Multilink-header-Form",/* (27) */
213 "SDL-over-SONET/SDH", /* (29) */
214 "PPP-Muxing", /* (30) */
217 #define NUM_LCPOPTS (sizeof(lcpconfopts) / sizeof(lcpconfopts[0]))
219 /* ECP - to be supported */
221 /* CCP Config Options */
223 #define CCPOPT_OUI 0 /* RFC1962 */
224 #define CCPOPT_PRED1 1 /* RFC1962 */
225 #define CCPOPT_PRED2 2 /* RFC1962 */
226 #define CCPOPT_PJUMP 3 /* RFC1962 */
227 /* 4-15 unassigned */
228 #define CCPOPT_HPPPC 16 /* RFC1962 */
229 #define CCPOPT_STACLZS 17 /* RFC1974 */
230 #define CCPOPT_MPPC 18 /* RFC2118 */
231 #define CCPOPT_GFZA 19 /* RFC1962 */
232 #define CCPOPT_V42BIS 20 /* RFC1962 */
233 #define CCPOPT_BSDCOMP 21 /* RFC1977 */
235 #define CCPOPT_LZSDCP 23 /* RFC1967 */
236 #define CCPOPT_MVRCA 24 /* RFC1975 */
237 #define CCPOPT_DEC 25 /* RFC1976 */
238 #define CCPOPT_DEFLATE 26 /* RFC1979 */
239 /* 27-254 unassigned */
240 #define CCPOPT_RESV 255 /* RFC1962 */
242 static const struct tok ccpconfopts_values
[] = {
243 { CCPOPT_OUI
, "OUI" },
244 { CCPOPT_PRED1
, "Pred-1" },
245 { CCPOPT_PRED2
, "Pred-2" },
246 { CCPOPT_PJUMP
, "Puddle" },
247 { CCPOPT_HPPPC
, "HP-PPC" },
248 { CCPOPT_STACLZS
, "Stac-LZS" },
249 { CCPOPT_MPPC
, "MPPC" },
250 { CCPOPT_GFZA
, "Gand-FZA" },
251 { CCPOPT_V42BIS
, "V.42bis" },
252 { CCPOPT_BSDCOMP
, "BSD-Comp" },
253 { CCPOPT_LZSDCP
, "LZS-DCP" },
254 { CCPOPT_MVRCA
, "MVRCA" },
255 { CCPOPT_DEC
, "DEC" },
256 { CCPOPT_DEFLATE
, "Deflate" },
257 { CCPOPT_RESV
, "Reserved"},
261 /* BACP Config Options */
263 #define BACPOPT_FPEER 1 /* RFC2125 */
265 static const struct tok bacconfopts_values
[] = {
266 { BACPOPT_FPEER
, "Favored-Peer" },
271 /* SDCP - to be supported */
273 /* IPCP Config Options */
274 #define IPCPOPT_2ADDR 1 /* RFC1172, RFC1332 (deprecated) */
275 #define IPCPOPT_IPCOMP 2 /* RFC1332 */
276 #define IPCPOPT_ADDR 3 /* RFC1332 */
277 #define IPCPOPT_MOBILE4 4 /* RFC2290 */
278 #define IPCPOPT_PRIDNS 129 /* RFC1877 */
279 #define IPCPOPT_PRINBNS 130 /* RFC1877 */
280 #define IPCPOPT_SECDNS 131 /* RFC1877 */
281 #define IPCPOPT_SECNBNS 132 /* RFC1877 */
283 static const struct tok ipcpopt_values
[] = {
284 { IPCPOPT_2ADDR
, "IP-Addrs" },
285 { IPCPOPT_IPCOMP
, "IP-Comp" },
286 { IPCPOPT_ADDR
, "IP-Addr" },
287 { IPCPOPT_MOBILE4
, "Home-Addr" },
288 { IPCPOPT_PRIDNS
, "Pri-DNS" },
289 { IPCPOPT_PRINBNS
, "Pri-NBNS" },
290 { IPCPOPT_SECDNS
, "Sec-DNS" },
291 { IPCPOPT_SECNBNS
, "Sec-NBNS" },
295 #define IPCPOPT_IPCOMP_HDRCOMP 0x61 /* rfc3544 */
296 #define IPCPOPT_IPCOMP_MINLEN 14
298 static const struct tok ipcpopt_compproto_values
[] = {
299 { PPP_VJC
, "VJ-Comp" },
300 { IPCPOPT_IPCOMP_HDRCOMP
, "IP Header Compression" },
304 static const struct tok ipcpopt_compproto_subopt_values
[] = {
305 { 1, "RTP-Compression" },
306 { 2, "Enhanced RTP-Compression" },
310 /* IP6CP Config Options */
313 static const struct tok ip6cpopt_values
[] = {
314 { IP6CP_IFID
, "Interface-ID" },
318 /* ATCP - to be supported */
319 /* OSINLCP - to be supported */
320 /* BVCP - to be supported */
321 /* BCP - to be supported */
322 /* IPXCP - to be supported */
323 /* MPLSCP - to be supported */
325 /* Auth Algorithms */
327 /* 0-4 Reserved (RFC1994) */
328 #define AUTHALG_CHAPMD5 5 /* RFC1994 */
329 #define AUTHALG_MSCHAP1 128 /* RFC2433 */
330 #define AUTHALG_MSCHAP2 129 /* RFC2795 */
332 static const struct tok authalg_values
[] = {
333 { AUTHALG_CHAPMD5
, "MD5" },
334 { AUTHALG_MSCHAP1
, "MS-CHAPv1" },
335 { AUTHALG_MSCHAP2
, "MS-CHAPv2" },
339 /* FCS Alternatives - to be supported */
341 /* Multilink Endpoint Discriminator (RFC1717) */
342 #define MEDCLASS_NULL 0 /* Null Class */
343 #define MEDCLASS_LOCAL 1 /* Locally Assigned */
344 #define MEDCLASS_IPV4 2 /* Internet Protocol (IPv4) */
345 #define MEDCLASS_MAC 3 /* IEEE 802.1 global MAC address */
346 #define MEDCLASS_MNB 4 /* PPP Magic Number Block */
347 #define MEDCLASS_PSNDN 5 /* Public Switched Network Director Number */
349 /* PPP LCP Callback */
350 #define CALLBACK_AUTH 0 /* Location determined by user auth */
351 #define CALLBACK_DSTR 1 /* Dialing string */
352 #define CALLBACK_LID 2 /* Location identifier */
353 #define CALLBACK_E164 3 /* E.164 number */
354 #define CALLBACK_X500 4 /* X.500 distinguished name */
355 #define CALLBACK_CBCP 6 /* Location is determined during CBCP nego */
357 static const struct tok ppp_callback_values
[] = {
358 { CALLBACK_AUTH
, "UserAuth" },
359 { CALLBACK_DSTR
, "DialString" },
360 { CALLBACK_LID
, "LocalID" },
361 { CALLBACK_E164
, "E.164" },
362 { CALLBACK_X500
, "X.500" },
363 { CALLBACK_CBCP
, "CBCP" },
374 static const struct tok chapcode_values
[] = {
375 { CHAP_CHAL
, "Challenge" },
376 { CHAP_RESP
, "Response" },
377 { CHAP_SUCC
, "Success" },
378 { CHAP_FAIL
, "Fail" },
388 static const struct tok papcode_values
[] = {
389 { PAP_AREQ
, "Auth-Req" },
390 { PAP_AACK
, "Auth-ACK" },
391 { PAP_ANAK
, "Auth-NACK" },
396 #define BAP_CALLREQ 1
397 #define BAP_CALLRES 2
405 static u_int
print_lcp_config_options(netdissect_options
*, const u_char
*p
, u_int
);
406 static u_int
print_ipcp_config_options(netdissect_options
*, const u_char
*p
, u_int
);
407 static u_int
print_ip6cp_config_options(netdissect_options
*, const u_char
*p
, u_int
);
408 static u_int
print_ccp_config_options(netdissect_options
*, const u_char
*p
, u_int
);
409 static u_int
print_bacp_config_options(netdissect_options
*, const u_char
*p
, u_int
);
410 static void handle_ppp(netdissect_options
*, u_int proto
, const u_char
*p
, u_int length
);
412 /* generic Control Protocol (e.g. LCP, IPCP, CCP, etc.) handler */
414 handle_ctrl_proto(netdissect_options
*ndo
,
415 u_int proto
, const u_char
*pptr
, u_int length
)
419 u_int (*pfunc
)(netdissect_options
*, const u_char
*, u_int
);
425 typestr
= tok2str(ppptype2str
, "unknown ctrl-proto (0x%04x)", proto
);
426 ND_PRINT("%s, ", typestr
);
428 if (length
< 4) /* FIXME weak boundary checking */
432 code
= GET_U_1(tptr
);
435 ND_PRINT("%s (0x%02x), id %u, length %u",
436 tok2str(cpcodes
, "Unknown Opcode",code
),
438 GET_U_1(tptr
), /* ID */
446 len
= GET_BE_U_2(tptr
);
450 ND_PRINT("\n\tencoded length %u (< 4))", len
);
455 ND_PRINT("\n\tencoded length %u (> packet length %u))", len
, length
);
460 ND_PRINT("\n\tencoded length %u (=Option(s) length %u)", len
, len
- 4);
463 return; /* there may be a NULL confreq etc. */
465 if (ndo
->ndo_vflag
> 1)
466 print_unknown_data(ndo
, pptr
- 2, "\n\t", 6);
474 ND_PRINT("\n\t Magic-Num 0x%08x", GET_BE_U_4(tptr
));
477 ND_PRINT(" Vendor: %s (%u)",
478 tok2str(oui_values
,"Unknown",GET_BE_U_3(tptr
)),
480 /* XXX: need to decode Kind and Value(s)? */
482 case CPCODES_CONF_REQ
:
483 case CPCODES_CONF_ACK
:
484 case CPCODES_CONF_NAK
:
485 case CPCODES_CONF_REJ
:
486 tlen
= len
- 4; /* Code(1), Identifier(1) and Length(2) */
490 pfunc
= print_lcp_config_options
;
493 pfunc
= print_ipcp_config_options
;
496 pfunc
= print_ip6cp_config_options
;
499 pfunc
= print_ccp_config_options
;
502 pfunc
= print_bacp_config_options
;
506 * No print routine for the options for
513 if (pfunc
== NULL
) /* catch the above null pointer if unknown CP */
516 if ((advance
= (*pfunc
)(ndo
, tptr
, len
)) == 0)
518 if (tlen
< advance
) {
519 ND_PRINT(" [remaining options length %u < %u]",
521 nd_print_invalid(ndo
);
529 case CPCODES_TERM_REQ
:
530 case CPCODES_TERM_ACK
:
531 /* XXX: need to decode Data? */
533 case CPCODES_CODE_REJ
:
534 /* XXX: need to decode Rejected-Packet? */
536 case CPCODES_PROT_REJ
:
540 ND_PRINT("\n\t Rejected %s Protocol (0x%04x)",
541 tok2str(ppptype2str
,"unknown", GET_BE_U_2(tptr
)),
543 /* XXX: need to decode Rejected-Information? - hexdump for now */
545 ND_PRINT("\n\t Rejected Packet");
546 print_unknown_data(ndo
, tptr
+ 2, "\n\t ", len
- 2);
549 case CPCODES_ECHO_REQ
:
550 case CPCODES_ECHO_RPL
:
551 case CPCODES_DISC_REQ
:
555 ND_PRINT("\n\t Magic-Num 0x%08x", GET_BE_U_4(tptr
));
556 /* XXX: need to decode Data? - hexdump for now */
558 ND_PRINT("\n\t -----trailing data-----");
559 ND_TCHECK_LEN(tptr
+ 4, len
- 8);
560 print_unknown_data(ndo
, tptr
+ 4, "\n\t ", len
- 8);
567 ND_PRINT("\n\t Magic-Num 0x%08x", GET_BE_U_4(tptr
));
568 /* RFC 1661 says this is intended to be human readable */
570 ND_PRINT("\n\t Message\n\t ");
571 if (nd_printn(ndo
, tptr
+ 4, len
- 4, ndo
->ndo_snapend
))
575 case CPCODES_TIME_REM
:
579 ND_PRINT("\n\t Magic-Num 0x%08x", GET_BE_U_4(tptr
));
580 ND_TCHECK_4(tptr
+ 4);
581 ND_PRINT(", Seconds-Remaining %us", GET_BE_U_4(tptr
+ 4));
582 /* XXX: need to decode Message? */
585 /* XXX this is dirty but we do not get the
586 * original pointer passed to the begin
588 if (ndo
->ndo_vflag
<= 1)
589 print_unknown_data(ndo
, pptr
- 2, "\n\t ", length
+ 2);
595 ND_PRINT("[|%s]", typestr
);
598 /* LCP config options */
600 print_lcp_config_options(netdissect_options
*ndo
,
601 const u_char
*p
, u_int length
)
609 len
= GET_U_1(p
+ 1);
613 if (opt
< NUM_LCPOPTS
)
614 ND_PRINT("\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
615 lcpconfopts
[opt
], opt
, len
);
617 ND_PRINT("\n\tunknown LCP option 0x%02x", opt
);
620 if (opt
< NUM_LCPOPTS
)
621 ND_PRINT("\n\t %s Option (0x%02x), length %u", lcpconfopts
[opt
], opt
, len
);
623 ND_PRINT("\n\tunknown LCP option 0x%02x", opt
);
630 ND_PRINT(" (length bogus, should be >= 6)");
634 ND_PRINT(": Vendor: %s (%u)",
635 tok2str(oui_values
,"Unknown",GET_BE_U_3(p
+ 2)),
639 ND_PRINT(", kind: 0x%02x", GET_U_1(p
+ 5));
640 ND_PRINT(", Value: 0x");
641 for (i
= 0; i
< len
- 6; i
++) {
642 ND_TCHECK_1(p
+ 6 + i
);
643 ND_PRINT("%02x", GET_U_1(p
+ 6 + i
));
649 ND_PRINT(" (length bogus, should be = 4)");
653 ND_PRINT(": %u", GET_BE_U_2(p
+ 2));
657 ND_PRINT(" (length bogus, should be = 6)");
661 ND_PRINT(": 0x%08x", GET_BE_U_4(p
+ 2));
665 ND_PRINT(" (length bogus, should be >= 4)");
670 tok2str(ppptype2str
, "Unknown Auth Proto (0x04x)", GET_BE_U_2(p
+ 2)));
672 switch (GET_BE_U_2(p
+ 2)) {
676 tok2str(authalg_values
, "Unknown Auth Alg %u", GET_U_1(p
+ 4)));
678 case PPP_PAP
: /* fall through */
684 print_unknown_data(ndo
, p
, "\n\t", len
);
689 ND_PRINT(" (length bogus, should be >= 4)");
693 if (GET_BE_U_2(p
+ 2) == PPP_LQM
)
696 ND_PRINT(": unknown");
700 ND_PRINT(" (length bogus, should be = 6)");
704 ND_PRINT(": 0x%08x", GET_BE_U_4(p
+ 2));
712 ND_PRINT(" (length bogus, should be = 4)");
716 ND_PRINT(": 0x%04x", GET_BE_U_2(p
+ 2));
720 ND_PRINT(" (length bogus, should be >= 3)");
725 ND_PRINT(": Callback Operation %s (%u)",
726 tok2str(ppp_callback_values
, "Unknown", GET_U_1(p
+ 2)),
731 ND_PRINT(" (length bogus, should be = 4)");
735 ND_PRINT(": %u", GET_BE_U_2(p
+ 2));
739 ND_PRINT(" (length bogus, should be >= 3)");
743 switch (GET_U_1(p
+ 2)) { /* class */
748 ND_PRINT(": Local"); /* XXX */
752 ND_PRINT(" (length bogus, should be = 7)");
756 ND_PRINT(": IPv4 %s", GET_IPADDR_STRING(p
+ 3));
760 ND_PRINT(" (length bogus, should be = 9)");
764 ND_PRINT(": MAC %s", GET_ETHERADDR_STRING(p
+ 3));
767 ND_PRINT(": Magic-Num-Block"); /* XXX */
770 ND_PRINT(": PSNDN"); /* XXX */
773 ND_PRINT(": Unknown class %u", GET_U_1(p
+ 2));
778 /* XXX: to be supported */
803 * Unknown option; dump it as raw bytes now if we're
804 * not going to do so below.
806 if (ndo
->ndo_vflag
< 2)
807 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2);
811 if (ndo
->ndo_vflag
> 1)
812 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2); /* exclude TLV header */
822 static const struct tok ppp_ml_flag_values
[] = {
829 handle_mlppp(netdissect_options
*ndo
,
830 const u_char
*p
, u_int length
)
836 ND_PRINT("[|mlppp]");
839 if (!ND_TTEST_2(p
)) {
840 ND_PRINT("[|mlppp]");
844 ND_PRINT("seq 0x%03x, Flags [%s], length %u",
845 (GET_BE_U_2(p
))&0x0fff,
846 /* only support 12-Bit sequence space for now */
847 bittok2str(ppp_ml_flag_values
, "none", GET_U_1(p
) & 0xc0),
853 handle_chap(netdissect_options
*ndo
,
854 const u_char
*p
, u_int length
)
857 u_int val_size
, name_size
, msg_size
;
865 } else if (length
< 4) {
867 ND_PRINT("[|chap 0x%02x]", GET_U_1(p
));
873 ND_PRINT("CHAP, %s (0x%02x)",
874 tok2str(chapcode_values
,"unknown",code
),
879 ND_PRINT(", id %u", GET_U_1(p
)); /* ID */
887 * Note that this is a generic CHAP decoding routine. Since we
888 * don't know which flavor of CHAP (i.e. CHAP-MD5, MS-CHAPv1,
889 * MS-CHAPv2) is used at this point, we can't decode packet
890 * specifically to each algorithms. Instead, we simply decode
891 * the GCD (Gratest Common Denominator) for all algorithms.
896 if (length
- (p
- p0
) < 1)
899 val_size
= GET_U_1(p
); /* value size */
901 if (length
- (p
- p0
) < val_size
)
903 ND_PRINT(", Value ");
904 for (i
= 0; i
< val_size
; i
++) {
906 ND_PRINT("%02x", GET_U_1(p
));
909 name_size
= len
- (u_int
)(p
- p0
);
911 for (i
= 0; i
< name_size
; i
++) {
913 fn_print_char(ndo
, GET_U_1(p
));
919 msg_size
= len
- (u_int
)(p
- p0
);
921 for (i
= 0; i
< msg_size
; i
++) {
923 fn_print_char(ndo
, GET_U_1(p
));
934 /* PAP (see RFC 1334) */
936 handle_pap(netdissect_options
*ndo
,
937 const u_char
*p
, u_int length
)
940 u_int peerid_len
, passwd_len
, msg_len
;
948 } else if (length
< 4) {
950 ND_PRINT("[|pap 0x%02x]", GET_U_1(p
));
956 ND_PRINT("PAP, %s (0x%02x)",
957 tok2str(papcode_values
, "unknown", code
),
962 ND_PRINT(", id %u", GET_U_1(p
)); /* ID */
970 ND_PRINT(", length %u > packet size", len
);
974 if (length
< (size_t)(p
- p0
)) {
975 ND_PRINT(", length %u < PAP header length", length
);
981 /* A valid Authenticate-Request is 6 or more octets long. */
984 if (length
- (p
- p0
) < 1)
987 peerid_len
= GET_U_1(p
); /* Peer-ID Length */
989 if (length
- (p
- p0
) < peerid_len
)
992 for (i
= 0; i
< peerid_len
; i
++) {
994 fn_print_char(ndo
, GET_U_1(p
));
998 if (length
- (p
- p0
) < 1)
1001 passwd_len
= GET_U_1(p
); /* Password Length */
1003 if (length
- (p
- p0
) < passwd_len
)
1005 ND_PRINT(", Name ");
1006 for (i
= 0; i
< passwd_len
; i
++) {
1008 fn_print_char(ndo
, GET_U_1(p
));
1014 /* Although some implementations ignore truncation at
1015 * this point and at least one generates a truncated
1016 * packet, RFC 1334 section 2.2.2 clearly states that
1017 * both AACK and ANAK are at least 5 bytes long.
1021 if (length
- (p
- p0
) < 1)
1024 msg_len
= GET_U_1(p
); /* Msg-Length */
1026 if (length
- (p
- p0
) < msg_len
)
1029 for (i
= 0; i
< msg_len
; i
++) {
1031 fn_print_char(ndo
, GET_U_1(p
));
1044 handle_bap(netdissect_options
*ndo _U_
,
1045 const u_char
*p _U_
, u_int length _U_
)
1047 /* XXX: to be supported!! */
1051 /* IPCP config options */
1053 print_ipcp_config_options(netdissect_options
*ndo
,
1054 const u_char
*p
, u_int length
)
1057 u_int compproto
, ipcomp_subopttotallen
, ipcomp_subopt
, ipcomp_suboptlen
;
1063 len
= GET_U_1(p
+ 1);
1067 ND_PRINT("\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1068 tok2str(ipcpopt_values
,"unknown",opt
),
1074 ND_PRINT("\n\t %s Option (0x%02x), length %u",
1075 tok2str(ipcpopt_values
,"unknown",opt
),
1080 case IPCPOPT_2ADDR
: /* deprecated */
1082 ND_PRINT(" (length bogus, should be = 10)");
1086 ND_PRINT(": src %s, dst %s",
1087 GET_IPADDR_STRING(p
+ 2),
1088 GET_IPADDR_STRING(p
+ 6));
1090 case IPCPOPT_IPCOMP
:
1092 ND_PRINT(" (length bogus, should be >= 4)");
1096 compproto
= GET_BE_U_2(p
+ 2);
1098 ND_PRINT(": %s (0x%02x):",
1099 tok2str(ipcpopt_compproto_values
, "Unknown", compproto
),
1102 switch (compproto
) {
1104 /* XXX: VJ-Comp parameters should be decoded */
1106 case IPCPOPT_IPCOMP_HDRCOMP
:
1107 if (len
< IPCPOPT_IPCOMP_MINLEN
) {
1108 ND_PRINT(" (length bogus, should be >= %u)",
1109 IPCPOPT_IPCOMP_MINLEN
);
1113 ND_TCHECK_LEN(p
+ 2, IPCPOPT_IPCOMP_MINLEN
);
1114 ND_PRINT("\n\t TCP Space %u, non-TCP Space %u"
1115 ", maxPeriod %u, maxTime %u, maxHdr %u",
1120 GET_BE_U_2(p
+ 12));
1122 /* suboptions present ? */
1123 if (len
> IPCPOPT_IPCOMP_MINLEN
) {
1124 ipcomp_subopttotallen
= len
- IPCPOPT_IPCOMP_MINLEN
;
1125 p
+= IPCPOPT_IPCOMP_MINLEN
;
1127 ND_PRINT("\n\t Suboptions, length %u", ipcomp_subopttotallen
);
1129 while (ipcomp_subopttotallen
>= 2) {
1131 ipcomp_subopt
= GET_U_1(p
);
1132 ipcomp_suboptlen
= GET_U_1(p
+ 1);
1135 if (ipcomp_subopt
== 0 ||
1136 ipcomp_suboptlen
== 0 )
1139 /* XXX: just display the suboptions for now */
1140 ND_PRINT("\n\t\t%s Suboption #%u, length %u",
1141 tok2str(ipcpopt_compproto_subopt_values
,
1146 if (ipcomp_subopttotallen
< ipcomp_suboptlen
) {
1147 ND_PRINT(" [remaining suboptions length %u < %u]",
1148 ipcomp_subopttotallen
, ipcomp_suboptlen
);
1149 nd_print_invalid(ndo
);
1152 ipcomp_subopttotallen
-= ipcomp_suboptlen
;
1153 p
+= ipcomp_suboptlen
;
1162 case IPCPOPT_ADDR
: /* those options share the same format - fall through */
1163 case IPCPOPT_MOBILE4
:
1164 case IPCPOPT_PRIDNS
:
1165 case IPCPOPT_PRINBNS
:
1166 case IPCPOPT_SECDNS
:
1167 case IPCPOPT_SECNBNS
:
1169 ND_PRINT(" (length bogus, should be = 6)");
1173 ND_PRINT(": %s", GET_IPADDR_STRING(p
+ 2));
1177 * Unknown option; dump it as raw bytes now if we're
1178 * not going to do so below.
1180 if (ndo
->ndo_vflag
< 2)
1181 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2);
1184 if (ndo
->ndo_vflag
> 1)
1185 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2); /* exclude TLV header */
1189 ND_PRINT("[|ipcp]");
1193 /* IP6CP config options */
1195 print_ip6cp_config_options(netdissect_options
*ndo
,
1196 const u_char
*p
, u_int length
)
1204 len
= GET_U_1(p
+ 1);
1208 ND_PRINT("\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1209 tok2str(ip6cpopt_values
,"unknown",opt
),
1215 ND_PRINT("\n\t %s Option (0x%02x), length %u",
1216 tok2str(ip6cpopt_values
,"unknown",opt
),
1223 ND_PRINT(" (length bogus, should be = 10)");
1227 ND_PRINT(": %04x:%04x:%04x:%04x",
1235 * Unknown option; dump it as raw bytes now if we're
1236 * not going to do so below.
1238 if (ndo
->ndo_vflag
< 2)
1239 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2);
1242 if (ndo
->ndo_vflag
> 1)
1243 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2); /* exclude TLV header */
1248 ND_PRINT("[|ip6cp]");
1253 /* CCP config options */
1255 print_ccp_config_options(netdissect_options
*ndo
,
1256 const u_char
*p
, u_int length
)
1264 len
= GET_U_1(p
+ 1);
1268 ND_PRINT("\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1269 tok2str(ccpconfopts_values
, "Unknown", opt
),
1275 ND_PRINT("\n\t %s Option (0x%02x), length %u",
1276 tok2str(ccpconfopts_values
, "Unknown", opt
),
1281 case CCPOPT_BSDCOMP
:
1283 ND_PRINT(" (length bogus, should be >= 3)");
1287 ND_PRINT(": Version: %u, Dictionary Bits: %u",
1288 GET_U_1(p
+ 2) >> 5,
1289 GET_U_1(p
+ 2) & 0x1f);
1293 ND_PRINT(" (length bogus, should be >= 4)");
1297 ND_PRINT(": Features: %u, PxP: %s, History: %u, #CTX-ID: %u",
1298 (GET_U_1(p
+ 2) & 0xc0) >> 6,
1299 (GET_U_1(p
+ 2) & 0x20) ? "Enabled" : "Disabled",
1300 GET_U_1(p
+ 2) & 0x1f,
1303 case CCPOPT_DEFLATE
:
1305 ND_PRINT(" (length bogus, should be >= 4)");
1309 ND_PRINT(": Window: %uK, Method: %s (0x%x), MBZ: %u, CHK: %u",
1310 (GET_U_1(p
+ 2) & 0xf0) >> 4,
1311 ((GET_U_1(p
+ 2) & 0x0f) == 8) ? "zlib" : "unknown",
1312 GET_U_1(p
+ 2) & 0x0f,
1313 (GET_U_1(p
+ 3) & 0xfc) >> 2,
1314 GET_U_1(p
+ 3) & 0x03);
1317 /* XXX: to be supported */
1324 case CCPOPT_STACLZS
:
1335 * Unknown option; dump it as raw bytes now if we're
1336 * not going to do so below.
1338 if (ndo
->ndo_vflag
< 2)
1339 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2);
1342 if (ndo
->ndo_vflag
> 1)
1343 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2); /* exclude TLV header */
1352 /* BACP config options */
1354 print_bacp_config_options(netdissect_options
*ndo
,
1355 const u_char
*p
, u_int length
)
1363 len
= GET_U_1(p
+ 1);
1367 ND_PRINT("\n\t %s Option (0x%02x), length %u (length bogus, should be >= 2)",
1368 tok2str(bacconfopts_values
, "Unknown", opt
),
1374 ND_PRINT("\n\t %s Option (0x%02x), length %u",
1375 tok2str(bacconfopts_values
, "Unknown", opt
),
1382 ND_PRINT(" (length bogus, should be = 6)");
1386 ND_PRINT(": Magic-Num 0x%08x", GET_BE_U_4(p
+ 2));
1390 * Unknown option; dump it as raw bytes now if we're
1391 * not going to do so below.
1393 if (ndo
->ndo_vflag
< 2)
1394 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2);
1397 if (ndo
->ndo_vflag
> 1)
1398 print_unknown_data(ndo
, p
+ 2, "\n\t ", len
- 2); /* exclude TLV header */
1403 ND_PRINT("[|bacp]");
1408 ppp_hdlc(netdissect_options
*ndo
,
1409 const u_char
*p
, u_int length
)
1419 b
= (u_char
*)nd_malloc(ndo
, length
);
1424 * Unescape all the data into a temporary, private, buffer.
1425 * Do this so that we dont overwrite the original packet
1428 for (s
= p
, t
= b
, i
= length
; i
!= 0 && ND_TTEST_1(s
); i
--) {
1432 if (i
<= 1 || !ND_TTEST_1(s
))
1435 c
= GET_U_1(s
) ^ 0x20;
1442 * Change the end pointer, so bounds checks work.
1444 se
= ndo
->ndo_snapend
;
1445 ndo
->ndo_snapend
= t
;
1446 length
= ND_BYTES_AVAILABLE_AFTER(b
);
1448 /* now lets guess about the payload codepoint format */
1451 proto
= GET_U_1(b
); /* start with a one-octet codepoint guess */
1455 ip_print(ndo
, b
+ 1, length
- 1);
1458 ip6_print(ndo
, b
+ 1, length
- 1);
1460 default: /* no luck - try next guess */
1466 proto
= GET_BE_U_2(b
); /* next guess - load two octets */
1469 case (PPP_ADDRESS
<< 8 | PPP_CONTROL
): /* looks like a PPP frame */
1472 proto
= GET_BE_U_2(b
+ 2); /* load the PPP proto-id */
1473 handle_ppp(ndo
, proto
, b
+ 4, length
- 4);
1475 default: /* last guess - proto must be a PPP proto-id */
1476 handle_ppp(ndo
, proto
, b
+ 2, length
- 2);
1481 ndo
->ndo_snapend
= se
;
1485 ndo
->ndo_snapend
= se
;
1486 nd_print_trunc(ndo
);
1492 handle_ppp(netdissect_options
*ndo
,
1493 u_int proto
, const u_char
*p
, u_int length
)
1495 if ((proto
& 0xff00) == 0x7e00) { /* is this an escape code ? */
1496 ppp_hdlc(ndo
, p
- 1, length
);
1501 case PPP_LCP
: /* fall through */
1508 handle_ctrl_proto(ndo
, proto
, p
, length
);
1511 handle_mlppp(ndo
, p
, length
);
1514 handle_chap(ndo
, p
, length
);
1517 handle_pap(ndo
, p
, length
);
1519 case PPP_BAP
: /* XXX: not yet completed */
1520 handle_bap(ndo
, p
, length
);
1522 case ETHERTYPE_IP
: /*XXX*/
1525 ip_print(ndo
, p
, length
);
1527 case ETHERTYPE_IPV6
: /*XXX*/
1529 ip6_print(ndo
, p
, length
);
1531 case ETHERTYPE_IPX
: /*XXX*/
1533 ipx_print(ndo
, p
, length
);
1536 isoclns_print(ndo
, p
, length
);
1538 case PPP_MPLS_UCAST
:
1539 case PPP_MPLS_MCAST
:
1540 mpls_print(ndo
, p
, length
);
1543 ND_PRINT("compressed PPP data");
1546 ND_PRINT("%s ", tok2str(ppptype2str
, "unknown PPP protocol (0x%04x)", proto
));
1547 print_unknown_data(ndo
, p
, "\n\t", length
);
1552 /* Standard PPP printer */
1554 ppp_print(netdissect_options
*ndo
,
1555 const u_char
*p
, u_int length
)
1557 u_int proto
,ppp_header
;
1558 u_int olen
= length
; /* _o_riginal length */
1561 ndo
->ndo_protocol
= "ppp";
1563 * Here, we assume that p points to the Address and Control
1564 * field (if they present).
1569 ppp_header
= GET_BE_U_2(p
);
1571 switch(ppp_header
) {
1572 case (PPP_WITHDIRECTION_IN
<< 8 | PPP_CONTROL
):
1573 if (ndo
->ndo_eflag
) ND_PRINT("In ");
1578 case (PPP_WITHDIRECTION_OUT
<< 8 | PPP_CONTROL
):
1579 if (ndo
->ndo_eflag
) ND_PRINT("Out ");
1584 case (PPP_ADDRESS
<< 8 | PPP_CONTROL
):
1585 p
+= 2; /* ACFC not used */
1597 if (GET_U_1(p
) % 2) {
1598 proto
= GET_U_1(p
); /* PFC is used */
1604 proto
= GET_BE_U_2(p
);
1611 ND_PRINT("%s (0x%04x), length %u: ",
1612 tok2str(ppptype2str
, "unknown", proto
),
1616 handle_ppp(ndo
, proto
, p
, length
);
1619 nd_print_trunc(ndo
);
1624 /* PPP I/F printer */
1626 ppp_if_print(netdissect_options
*ndo
,
1627 const struct pcap_pkthdr
*h
, const u_char
*p
)
1629 u_int length
= h
->len
;
1630 u_int caplen
= h
->caplen
;
1632 ndo
->ndo_protocol
= "ppp_if";
1633 if (caplen
< PPP_HDRLEN
) {
1634 nd_print_trunc(ndo
);
1640 * XXX: seems to assume that there are 2 octets prepended to an
1641 * actual PPP frame. The 1st octet looks like Input/Output flag
1642 * while 2nd octet is unknown, at least to me
1643 * (mshindo@mshindo.net).
1645 * That was what the original tcpdump code did.
1647 * FreeBSD's "if_ppp.c" *does* set the first octet to 1 for outbound
1648 * packets and 0 for inbound packets - but only if the
1649 * protocol field has the 0x8000 bit set (i.e., it's a network
1650 * control protocol); it does so before running the packet through
1651 * "bpf_filter" to see if it should be discarded, and to see
1652 * if we should update the time we sent the most recent packet...
1654 * ...but it puts the original address field back after doing
1657 * NetBSD's "if_ppp.c" doesn't set the first octet in that fashion.
1659 * I don't know if any PPP implementation handed up to a BPF
1660 * device packets with the first octet being 1 for outbound and
1661 * 0 for inbound packets, so I (guy@alum.mit.edu) don't know
1662 * whether that ever needs to be checked or not.
1664 * Note that NetBSD has a DLT_PPP_SERIAL, which it uses for PPP,
1665 * and its tcpdump appears to assume that the frame always
1666 * begins with an address field and a control field, and that
1667 * the address field might be 0x0f or 0x8f, for Cisco
1668 * point-to-point with HDLC framing as per section 4.3.1 of RFC
1669 * 1547, as well as 0xff, for PPP in HDLC-like framing as per
1672 * (Is the Cisco framing in question what DLT_C_HDLC, in
1676 ND_PRINT("%c %4d %02x ", GET_U_1(p
) ? 'O' : 'I',
1677 length
, GET_U_1(p
+ 1));
1680 ppp_print(ndo
, p
, length
);
1686 * PPP I/F printer to use if we know that RFC 1662-style PPP in HDLC-like
1687 * framing, or Cisco PPP with HDLC framing as per section 4.3.1 of RFC 1547,
1688 * is being used (i.e., we don't check for PPP_ADDRESS and PPP_CONTROL,
1689 * discard them *if* those are the first two octets, and parse the remaining
1690 * packet as a PPP packet, as "ppp_print()" does).
1692 * This handles, for example, DLT_PPP_SERIAL in NetBSD.
1695 ppp_hdlc_if_print(netdissect_options
*ndo
,
1696 const struct pcap_pkthdr
*h
, const u_char
*p
)
1698 u_int length
= h
->len
;
1699 u_int caplen
= h
->caplen
;
1703 ndo
->ndo_protocol
= "ppp_hdlc_if";
1705 nd_print_trunc(ndo
);
1709 switch (GET_U_1(p
)) {
1713 nd_print_trunc(ndo
);
1718 ND_PRINT("%02x %02x %u ", GET_U_1(p
),
1719 GET_U_1(p
+ 1), length
);
1724 proto
= GET_BE_U_2(p
);
1728 ND_PRINT("%s: ", tok2str(ppptype2str
, "unknown PPP protocol (0x%04x)", proto
));
1730 handle_ppp(ndo
, proto
, p
, length
);
1735 return (chdlc_if_print(ndo
, h
, p
));
1739 nd_print_trunc(ndo
);
1744 ND_PRINT("%02x %02x %u ", GET_U_1(p
),
1745 GET_U_1(p
+ 1), length
);
1750 * XXX - NetBSD's "ppp_netbsd_serial_if_print()" treats
1751 * the next two octets as an Ethernet type; does that
1754 ND_PRINT("unknown addr %02x; ctrl %02x", GET_U_1(p
),
1762 #define PPP_BSDI_HDRLEN 24
1764 /* BSD/OS specific PPP printer */
1766 ppp_bsdos_if_print(netdissect_options
*ndo _U_
,
1767 const struct pcap_pkthdr
*h _U_
, const u_char
*p _U_
)
1771 u_int length
= h
->len
;
1772 u_int caplen
= h
->caplen
;
1778 ndo
->ndo_protocol
= "ppp_bsdos_if";
1779 if (caplen
< PPP_BSDI_HDRLEN
) {
1780 nd_print_trunc(ndo
);
1787 if (GET_U_1(p
) == PPP_ADDRESS
&&
1788 GET_U_1(p
+ 1) == PPP_CONTROL
) {
1790 ND_PRINT("%02x %02x ", GET_U_1(p
),
1797 ND_PRINT("%u ", length
);
1798 /* Retrieve the protocol type */
1799 if (GET_U_1(p
) & 01) {
1800 /* Compressed protocol field */
1803 ND_PRINT("%02x ", ptype
);
1807 /* Un-compressed protocol field */
1808 ptype
= GET_BE_U_2(p
);
1810 ND_PRINT("%04x ", ptype
);
1817 ND_PRINT("%c ", GET_U_1(p
+ SLC_DIR
) ? 'O' : 'I');
1818 llhl
= GET_U_1(p
+ SLC_LLHL
);
1820 /* link level header */
1821 struct ppp_header
*ph
;
1823 q
= p
+ SLC_BPFHDRLEN
;
1824 ph
= (struct ppp_header
*)q
;
1825 if (ph
->phdr_addr
== PPP_ADDRESS
1826 && ph
->phdr_ctl
== PPP_CONTROL
) {
1828 ND_PRINT("%02x %02x ", GET_U_1(q
),
1830 ptype
= GET_BE_U_2(&ph
->phdr_type
);
1831 if (ndo
->ndo_eflag
&& (ptype
== PPP_VJC
|| ptype
== PPP_VJNC
)) {
1832 ND_PRINT("%s ", tok2str(ppptype2str
,
1833 "proto-#%u", ptype
));
1836 if (ndo
->ndo_eflag
) {
1838 for (i
= 0; i
< llhl
; i
++)
1839 ND_PRINT("%02x", GET_U_1(q
+ i
));
1845 ND_PRINT("%u ", length
);
1846 if (GET_U_1(p
+ SLC_CHL
)) {
1847 q
= p
+ SLC_BPFHDRLEN
+ llhl
;
1851 ptype
= vjc_print(ndo
, q
, ptype
);
1852 hdrlength
= PPP_BSDI_HDRLEN
;
1856 ip_print(ndo
, p
, length
);
1859 ip6_print(ndo
, p
, length
);
1861 case PPP_MPLS_UCAST
:
1862 case PPP_MPLS_MCAST
:
1863 mpls_print(ndo
, p
, length
);
1868 ptype
= vjc_print(ndo
, q
, ptype
);
1869 hdrlength
= PPP_BSDI_HDRLEN
;
1873 ip_print(ndo
, p
, length
);
1876 ip6_print(ndo
, p
, length
);
1878 case PPP_MPLS_UCAST
:
1879 case PPP_MPLS_MCAST
:
1880 mpls_print(ndo
, p
, length
);
1885 if (ndo
->ndo_eflag
) {
1887 for (i
= 0; i
< llhl
; i
++)
1896 hdrlength
= PPP_BSDI_HDRLEN
;
1899 length
-= hdrlength
;
1904 ip_print(p
, length
);
1907 ip6_print(ndo
, p
, length
);
1909 case PPP_MPLS_UCAST
:
1910 case PPP_MPLS_MCAST
:
1911 mpls_print(ndo
, p
, length
);
1914 ND_PRINT("%s ", tok2str(ppptype2str
, "unknown PPP protocol (0x%04x)", ptype
));
1920 #endif /* __bsdi__ */