2 * Copyright (c) 1990, 1991, 1993, 1994, 1995, 1996, 1997
3 * John Robert LoVerso. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
9 * 1. Redistributions of source code must retain the above copyright
10 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
17 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
21 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
25 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28 * This implementation has been influenced by the CMU SNMP release,
29 * by Steve Waldbusser. However, this shares no code with that system.
30 * Additional ASN.1 insight gained from Marshall T. Rose's _The_Open_Book_.
31 * Earlier forms of this implementation were derived and/or inspired by an
32 * awk script originally written by C. Philip Wood of LANL (but later
33 * heavily modified by John Robert LoVerso). The copyright notice for
34 * that work is preserved below, even though it may not rightly apply
37 * Support for SNMPv2c/SNMPv3 and the ability to link the module against
38 * the libsmi was added by J. Schoenwaelder, Copyright (c) 1999.
40 * This started out as a very simple program, but the incremental decoding
41 * (into the BE structure) complicated things.
43 # Los Alamos National Laboratory
45 # Copyright (c) 1990, 1991, 1993, 1994, 1995, 1996, 1997
46 # This software was produced under a U.S. Government contract
47 # (W-7405-ENG-36) by Los Alamos National Laboratory, which is
48 # operated by the University of California for the U.S. Department
49 # of Energy. The U.S. Government is licensed to use, reproduce,
50 # and distribute this software. Permission is granted to the
51 # public to copy and use this software without charge, provided
52 # that this Notice and any statement of authorship are reproduced
53 # on all copies. Neither the Government nor the University makes
54 # any warranty, express or implied, or assumes any liability or
55 # responsibility for the use of this software.
56 # @(#)snmp.awk.x 1.1 (LANL) 1/15/90
59 /* \summary: Simple Network Management Protocol (SNMP) printer */
65 #include "netdissect-stdinc.h"
74 #include "netdissect.h"
77 #undef OPAQUE /* defined in <wingdi.h> */
79 static const char tstr
[] = "[|snmp]";
82 * Universal ASN.1 types
83 * (we only care about the tag values for those allowed in the Internet SMI)
85 static const char *Universal
[] = {
98 "U-8","U-9","U-10","U-11", /* 8-11 */
99 "U-12","U-13","U-14","U-15", /* 12-15 */
106 * Application-wide ASN.1 types from the Internet SMI and their tags
108 static const char *Application
[] = {
125 * Context-specific ASN.1 types for the SNMP PDUs and their tags
127 static const char *Context
[] = {
148 #define NOTIFY_CLASS(x) (x == TRAP || x == V2TRAP || x == INFORMREQ)
149 #define READ_CLASS(x) (x == GETREQ || x == GETNEXTREQ || x == GETBULKREQ)
150 #define WRITE_CLASS(x) (x == SETREQ)
151 #define RESPONSE_CLASS(x) (x == GETRESP)
152 #define INTERNAL_CLASS(x) (x == REPORT)
155 * Context-specific ASN.1 types for the SNMP Exceptions and their tags
157 static const char *Exceptions
[] = {
159 #define NOSUCHOBJECT 0
161 #define NOSUCHINSTANCE 1
163 #define ENDOFMIBVIEW 2
167 * Private ASN.1 types
168 * The Internet SMI does not specify any
170 static const char *Private
[] = {
175 * error-status values for any SNMP PDU
177 static const char *ErrorStatus
[] = {
191 "resourceUnavailable",
194 "authorizationError",
198 #define DECODE_ErrorStatus(e) \
199 ( e >= 0 && (size_t)e < sizeof(ErrorStatus)/sizeof(ErrorStatus[0]) \
201 : (nd_snprintf(errbuf, sizeof(errbuf), "err=%u", e), errbuf))
204 * generic-trap values in the SNMP Trap-PDU
206 static const char *GenericTrap
[] = {
211 "authenticationFailure",
214 #define GT_ENTERPRISE 6
216 #define DECODE_GenericTrap(t) \
217 ( t >= 0 && (size_t)t < sizeof(GenericTrap)/sizeof(GenericTrap[0]) \
219 : (nd_snprintf(buf, sizeof(buf), "gt=%d", t), buf))
222 * ASN.1 type class table
223 * Ties together the preceding Universal, Application, Context, and Private
226 #define defineCLASS(x) { "x", x, sizeof(x)/sizeof(x[0]) } /* not ANSI-C */
227 static const struct {
232 defineCLASS(Universal
),
234 defineCLASS(Application
),
235 #define APPLICATION 1
236 defineCLASS(Context
),
238 defineCLASS(Private
),
240 defineCLASS(Exceptions
),
245 * defined forms for ASN.1 types
247 static const char *Form
[] = {
251 #define CONSTRUCTED 1
255 * A structure for the OID tree for the compiled-in MIB.
256 * This is stored as a general-order tree.
259 const char *desc
; /* name of object */
260 u_char oid
; /* sub-id following parent */
261 u_char type
; /* object type (unused) */
262 struct obj
*child
, *next
; /* child and next sibling pointers */
266 * Include the compiled in SNMP MIB. "mib.h" is produced by feeding
267 * RFC-1156 format files into "makemib". "mib.h" MUST define at least
268 * a value for `mibroot'.
270 * In particular, this is gross, as this is including initialized structures,
271 * and by right shouldn't be an "include" file.
276 * This defines a list of OIDs which will be abbreviated on output.
277 * Currently, this includes the prefixes for the Internet MIB, the
278 * private enterprises tree, and the experimental tree.
280 #define OID_FIRST_OCTET(x, y) (((x)*40) + (y)) /* X.690 8.19.4 */
283 static const uint8_t mib_oid
[] = { OID_FIRST_OCTET(1, 3), 6, 1, 2, 1 };
285 #ifndef NO_ABREV_ENTER
286 static const uint8_t enterprises_oid
[] = { OID_FIRST_OCTET(1, 3), 6, 1, 4, 1 };
288 #ifndef NO_ABREV_EXPERI
289 static const uint8_t experimental_oid
[] = { OID_FIRST_OCTET(1, 3), 6, 1, 3 };
291 #ifndef NO_ABBREV_SNMPMODS
292 static const uint8_t snmpModules_oid
[] = { OID_FIRST_OCTET(1, 3), 6, 1, 6, 3 };
295 #define OBJ_ABBREV_ENTRY(prefix, obj) \
296 { prefix, &_ ## obj ## _obj, obj ## _oid, sizeof (obj ## _oid) }
297 static const struct obj_abrev
{
298 const char *prefix
; /* prefix for this abrev */
299 struct obj
*node
; /* pointer into object table */
300 const uint8_t *oid
; /* ASN.1 encoded OID */
301 size_t oid_len
; /* length of OID */
302 } obj_abrev_list
[] = {
304 /* .iso.org.dod.internet.mgmt.mib */
305 OBJ_ABBREV_ENTRY("", mib
),
307 #ifndef NO_ABREV_ENTER
308 /* .iso.org.dod.internet.private.enterprises */
309 OBJ_ABBREV_ENTRY("E:", enterprises
),
311 #ifndef NO_ABREV_EXPERI
312 /* .iso.org.dod.internet.experimental */
313 OBJ_ABBREV_ENTRY("X:", experimental
),
315 #ifndef NO_ABBREV_SNMPMODS
316 /* .iso.org.dod.internet.snmpV2.snmpModules */
317 OBJ_ABBREV_ENTRY("S:", snmpModules
),
323 * This is used in the OID print routine to walk down the object tree
324 * rooted at `mibroot'.
326 #define OBJ_PRINT(o, suppressdot) \
330 if ((o) == objp->oid) \
332 } while ((objp = objp->next) != NULL); \
335 ND_PRINT(suppressdot?"%s":".%s", objp->desc); \
336 objp = objp->child; \
338 ND_PRINT(suppressdot?"%u":".%u", (o)); \
342 * This is the definition for the Any-Data-Type storage used purely for
343 * temporary internal representation while decoding an ASN.1 data stream.
355 u_char form
, class; /* tag info */
366 #define BE_INETADDR 8
369 #define BE_NOSUCHOBJECT 128
370 #define BE_NOSUCHINST 129
371 #define BE_ENDOFMIBVIEW 130
375 * SNMP versions recognized by this module
377 static const char *SnmpVersion
[] = {
379 #define SNMP_VERSION_1 0
381 #define SNMP_VERSION_2 1
383 #define SNMP_VERSION_2U 2
385 #define SNMP_VERSION_3 3
389 * Defaults for SNMP PDU components
391 #define DEF_COMMUNITY "public"
394 * constants for ASN.1 decoding
397 #define ASNLEN_INETADDR 4
400 #define ASN_BIT8 0x80
401 #define ASN_LONGLEN 0x80
403 #define ASN_ID_BITS 0x1f
404 #define ASN_FORM_BITS 0x20
405 #define ASN_FORM_SHIFT 5
406 #define ASN_CLASS_BITS 0xc0
407 #define ASN_CLASS_SHIFT 6
409 #define ASN_ID_EXT 0x1f /* extension ID in tag field */
412 * This decodes the next ASN.1 object in the stream pointed to by "p"
413 * (and of real-length "len") and stores the intermediate data in the
414 * provided BE object.
416 * This returns -l if it fails (i.e., the ASN.1 stream is not valid).
417 * O/w, this returns the number of bytes parsed from "p".
420 asn1_parse(netdissect_options
*ndo
,
421 const u_char
*p
, u_int len
, struct be
*elem
)
423 u_char form
, class, id
;
429 ND_PRINT("[nothing to parse]");
435 * it would be nice to use a bit field, but you can't depend on them.
436 * +---+---+---+---+---+---+---+---+
438 * +---+---+---+---+---+---+---+---+
441 id
= EXTRACT_U_1(p
) & ASN_ID_BITS
; /* lower 5 bits, range 00-1f */
443 form
= (EXTRACT_U_1(p
) & 0xe0) >> 5; /* move upper 3 bits to lower 3 */
444 class = form
>> 1; /* bits 7&6 -> bits 1&0, range 0-3 */
445 form
&= 0x1; /* bit 5 -> bit 0, range 0-1 */
447 form
= (u_char
)(EXTRACT_U_1(p
) & ASN_FORM_BITS
) >> ASN_FORM_SHIFT
;
448 class = (u_char
)(EXTRACT_U_1(p
) & ASN_CLASS_BITS
) >> ASN_CLASS_SHIFT
;
454 /* extended tag field */
455 if (id
== ASN_ID_EXT
) {
457 * The ID follows, as a sequence of octets with the
458 * 8th bit set and the remaining 7 bits being
459 * the next 7 bits of the value, terminated with
460 * an octet with the 8th bit not set.
462 * First, assemble all the octets with the 8th
463 * bit set. XXX - this doesn't handle a value
464 * that won't fit in 32 bits.
468 while (EXTRACT_U_1(p
) & ASN_BIT8
) {
470 ND_PRINT("[Xtagfield?]");
473 id
= (id
<< 7) | (EXTRACT_U_1(p
) & ~ASN_BIT8
);
480 ND_PRINT("[Xtagfield?]");
484 elem
->id
= id
= (id
<< 7) | EXTRACT_U_1(p
);
490 ND_PRINT("[no asnlen]");
494 elem
->asnlen
= EXTRACT_U_1(p
);
496 if (elem
->asnlen
& ASN_BIT8
) {
497 uint32_t noct
= elem
->asnlen
% ASN_BIT8
;
500 ND_PRINT("[asnlen? %d<%d]", len
, noct
);
503 ND_TCHECK_LEN(p
, noct
);
504 for (; noct
-- > 0; len
--, hdr
++) {
505 elem
->asnlen
= (elem
->asnlen
<< ASN_SHIFT8
) | EXTRACT_U_1(p
);
509 if (len
< elem
->asnlen
) {
510 ND_PRINT("[len%d<asnlen%u]", len
, elem
->asnlen
);
513 if (form
>= sizeof(Form
)/sizeof(Form
[0])) {
514 ND_PRINT("[form?%d]", form
);
517 if (class >= sizeof(Class
)/sizeof(Class
[0])) {
518 ND_PRINT("[class?%c/%d]", *Form
[form
], class);
521 if ((int)id
>= Class
[class].numIDs
) {
522 ND_PRINT("[id?%c/%s/%d]", *Form
[form
], Class
[class].name
, id
);
525 ND_TCHECK_LEN(p
, elem
->asnlen
);
542 if (elem
->asnlen
== 0) {
543 ND_PRINT("[asnlen=0]");
546 if (EXTRACT_U_1(p
) & ASN_BIT8
) /* negative */
548 for (i
= elem
->asnlen
; i
!= 0; p
++, i
--)
549 data
= (data
<< ASN_SHIFT8
) | EXTRACT_U_1(p
);
550 elem
->data
.integer
= data
;
556 elem
->data
.raw
= (const uint8_t *)p
;
560 elem
->type
= BE_NULL
;
561 elem
->data
.raw
= NULL
;
565 elem
->type
= BE_OCTET
;
566 elem
->data
.raw
= (const uint8_t *)p
;
567 ND_PRINT("[P/U/%s]", Class
[class].Id
[id
]);
575 elem
->type
= BE_INETADDR
;
576 elem
->data
.raw
= (const uint8_t *)p
;
585 for (i
= elem
->asnlen
; i
!= 0; p
++, i
--)
586 data
= (data
<< 8) + EXTRACT_U_1(p
);
587 elem
->data
.uns
= data
;
593 elem
->type
= BE_UNS64
;
595 for (i
= elem
->asnlen
; i
!= 0; p
++, i
--)
596 data64
= (data64
<< 8) + EXTRACT_U_1(p
);
597 elem
->data
.uns64
= data64
;
602 elem
->type
= BE_OCTET
;
603 elem
->data
.raw
= (const uint8_t *)p
;
605 Class
[class].Id
[id
]);
613 elem
->type
= BE_NOSUCHOBJECT
;
614 elem
->data
.raw
= NULL
;
618 elem
->type
= BE_NOSUCHINST
;
619 elem
->data
.raw
= NULL
;
623 elem
->type
= BE_ENDOFMIBVIEW
;
624 elem
->data
.raw
= NULL
;
630 ND_PRINT("[P/%s/%s]", Class
[class].name
, Class
[class].Id
[id
]);
631 elem
->type
= BE_OCTET
;
632 elem
->data
.raw
= (const uint8_t *)p
;
643 elem
->data
.raw
= (const uint8_t *)p
;
647 elem
->type
= BE_OCTET
;
648 elem
->data
.raw
= (const uint8_t *)p
;
649 ND_PRINT("C/U/%s", Class
[class].Id
[id
]);
656 elem
->data
.raw
= (const uint8_t *)p
;
660 elem
->type
= BE_OCTET
;
661 elem
->data
.raw
= (const uint8_t *)p
;
662 ND_PRINT("C/%s/%s", Class
[class].name
, Class
[class].Id
[id
]);
669 return elem
->asnlen
+ hdr
;
672 ND_PRINT("%s", tstr
);
677 asn1_print_octets(netdissect_options
*ndo
, struct be
*elem
)
679 const u_char
*p
= (const u_char
*)elem
->data
.raw
;
680 uint32_t asnlen
= elem
->asnlen
;
683 ND_TCHECK_LEN(p
, asnlen
);
684 for (i
= asnlen
; i
!= 0; p
++, i
--)
685 ND_PRINT("_%.2x", EXTRACT_U_1(p
));
689 ND_PRINT("%s", tstr
);
694 asn1_print_string(netdissect_options
*ndo
, struct be
*elem
)
696 int printable
= 1, first
= 1;
698 uint32_t asnlen
= elem
->asnlen
;
702 ND_TCHECK_LEN(p
, asnlen
);
703 for (i
= asnlen
; printable
&& i
!= 0; p
++, i
--)
704 printable
= ND_ISPRINT(EXTRACT_U_1(p
));
708 if (fn_printn(ndo
, p
, asnlen
, ndo
->ndo_snapend
)) {
714 for (i
= asnlen
; i
!= 0; p
++, i
--) {
715 ND_PRINT(first
? "%.2x" : "_%.2x", EXTRACT_U_1(p
));
722 ND_PRINT("%s", tstr
);
727 * Display the ASN.1 object represented by the BE object.
728 * This used to be an integral part of asn1_parse() before the intermediate
732 asn1_print(netdissect_options
*ndo
,
736 uint32_t asnlen
= elem
->asnlen
;
739 switch (elem
->type
) {
742 if (asn1_print_octets(ndo
, elem
) == -1)
750 int o
= 0, first
= -1;
752 p
= (const u_char
*)elem
->data
.raw
;
754 if (!ndo
->ndo_nflag
&& asnlen
> 2) {
755 const struct obj_abrev
*a
= &obj_abrev_list
[0];
756 for (; a
->node
; a
++) {
759 if (!ND_TTEST_LEN(p
, a
->oid_len
))
761 if (memcmp(a
->oid
, p
, a
->oid_len
) == 0) {
762 objp
= a
->node
->child
;
765 ND_PRINT("%s", a
->prefix
);
772 for (; i
!= 0; p
++, i
--) {
774 o
= (o
<< ASN_SHIFT7
) + (EXTRACT_U_1(p
) & ~ASN_BIT8
);
775 if (EXTRACT_U_1(p
) & ASN_LONGLEN
)
779 * first subitem encodes two items with
781 * (see X.690:1997 clause 8.19 for the details)
802 ND_PRINT("%d", elem
->data
.integer
);
806 ND_PRINT("%u", elem
->data
.uns
);
810 ND_PRINT("%" PRIu64
, elem
->data
.uns64
);
814 if (asn1_print_string(ndo
, elem
) == -1)
819 ND_PRINT("Seq(%u)", elem
->asnlen
);
823 if (asnlen
!= ASNLEN_INETADDR
)
824 ND_PRINT("[inetaddr len!=%d]", ASNLEN_INETADDR
);
825 p
= (const u_char
*)elem
->data
.raw
;
826 ND_TCHECK_LEN(p
, asnlen
);
827 for (i
= asnlen
; i
!= 0; p
++, i
--) {
828 ND_PRINT((i
== asnlen
) ? "%u" : ".%u", EXTRACT_U_1(p
));
832 case BE_NOSUCHOBJECT
:
834 case BE_ENDOFMIBVIEW
:
835 ND_PRINT("[%s]", Class
[EXCEPTIONS
].Id
[elem
->id
]);
839 ND_PRINT("%s(%u)", Class
[CONTEXT
].Id
[elem
->id
], elem
->asnlen
);
843 ND_PRINT("[BE_ANY!?]");
853 ND_PRINT("%s", tstr
);
859 * This is a brute force ASN.1 printer: recurses to dump an entire structure.
860 * This will work for any ASN.1 stream, not just an SNMP PDU.
862 * By adding newlines and spaces at the correct places, this would print in
865 * This is not currently used.
868 asn1_decode(u_char
*p
, u_int length
)
873 while (i
>= 0 && length
> 0) {
874 i
= asn1_parse(ndo
, p
, length
, &elem
);
877 if (asn1_print(ndo
, &elem
) < 0)
879 if (elem
.type
== BE_SEQ
|| elem
.type
== BE_PDU
) {
881 asn1_decode(elem
.data
.raw
, elem
.asnlen
);
894 SmiBasetype basetype
;
898 static const struct smi2be smi2betab
[] = {
899 { SMI_BASETYPE_INTEGER32
, BE_INT
},
900 { SMI_BASETYPE_OCTETSTRING
, BE_STR
},
901 { SMI_BASETYPE_OCTETSTRING
, BE_INETADDR
},
902 { SMI_BASETYPE_OBJECTIDENTIFIER
, BE_OID
},
903 { SMI_BASETYPE_UNSIGNED32
, BE_UNS
},
904 { SMI_BASETYPE_INTEGER64
, BE_NONE
},
905 { SMI_BASETYPE_UNSIGNED64
, BE_UNS64
},
906 { SMI_BASETYPE_FLOAT32
, BE_NONE
},
907 { SMI_BASETYPE_FLOAT64
, BE_NONE
},
908 { SMI_BASETYPE_FLOAT128
, BE_NONE
},
909 { SMI_BASETYPE_ENUM
, BE_INT
},
910 { SMI_BASETYPE_BITS
, BE_STR
},
911 { SMI_BASETYPE_UNKNOWN
, BE_NONE
}
915 smi_decode_oid(netdissect_options
*ndo
,
916 struct be
*elem
, unsigned int *oid
,
917 unsigned int oidsize
, unsigned int *oidlen
)
919 const u_char
*p
= (const u_char
*)elem
->data
.raw
;
920 uint32_t asnlen
= elem
->asnlen
;
922 int o
= 0, first
= -1;
923 unsigned int firstval
;
925 for (*oidlen
= 0; i
!= 0; p
++, i
--) {
927 o
= (o
<< ASN_SHIFT7
) + (EXTRACT_U_1(p
) & ~ASN_BIT8
);
928 if (EXTRACT_U_1(p
) & ASN_LONGLEN
)
932 * first subitem encodes two items with 1st*OIDMUX+2nd
933 * (see X.690:1997 clause 8.19 for the details)
937 firstval
= o
/ OIDMUX
;
938 if (firstval
> 2) firstval
= 2;
939 o
-= firstval
* OIDMUX
;
940 if (*oidlen
< oidsize
) {
941 oid
[(*oidlen
)++] = firstval
;
944 if (*oidlen
< oidsize
) {
945 oid
[(*oidlen
)++] = o
;
952 ND_PRINT("%s", tstr
);
956 static int smi_check_type(SmiBasetype basetype
, int be
)
960 for (i
= 0; smi2betab
[i
].basetype
!= SMI_BASETYPE_UNKNOWN
; i
++) {
961 if (smi2betab
[i
].basetype
== basetype
&& smi2betab
[i
].be
== be
) {
969 static int smi_check_a_range(SmiType
*smiType
, SmiRange
*smiRange
,
974 switch (smiType
->basetype
) {
975 case SMI_BASETYPE_OBJECTIDENTIFIER
:
976 case SMI_BASETYPE_OCTETSTRING
:
977 if (smiRange
->minValue
.value
.unsigned32
978 == smiRange
->maxValue
.value
.unsigned32
) {
979 ok
= (elem
->asnlen
== smiRange
->minValue
.value
.unsigned32
);
981 ok
= (elem
->asnlen
>= smiRange
->minValue
.value
.unsigned32
982 && elem
->asnlen
<= smiRange
->maxValue
.value
.unsigned32
);
986 case SMI_BASETYPE_INTEGER32
:
987 ok
= (elem
->data
.integer
>= smiRange
->minValue
.value
.integer32
988 && elem
->data
.integer
<= smiRange
->maxValue
.value
.integer32
);
991 case SMI_BASETYPE_UNSIGNED32
:
992 ok
= (elem
->data
.uns
>= smiRange
->minValue
.value
.unsigned32
993 && elem
->data
.uns
<= smiRange
->maxValue
.value
.unsigned32
);
996 case SMI_BASETYPE_UNSIGNED64
:
1000 /* case SMI_BASETYPE_INTEGER64: SMIng */
1001 /* case SMI_BASETYPE_FLOAT32: SMIng */
1002 /* case SMI_BASETYPE_FLOAT64: SMIng */
1003 /* case SMI_BASETYPE_FLOAT128: SMIng */
1005 case SMI_BASETYPE_ENUM
:
1006 case SMI_BASETYPE_BITS
:
1007 case SMI_BASETYPE_UNKNOWN
:
1019 static int smi_check_range(SmiType
*smiType
, struct be
*elem
)
1024 for (smiRange
= smiGetFirstRange(smiType
);
1026 smiRange
= smiGetNextRange(smiRange
)) {
1028 ok
= smi_check_a_range(smiType
, smiRange
, elem
);
1036 SmiType
*parentType
;
1037 parentType
= smiGetParentType(smiType
);
1039 ok
= smi_check_range(parentType
, elem
);
1047 smi_print_variable(netdissect_options
*ndo
,
1048 struct be
*elem
, int *status
)
1050 unsigned int oid
[128], oidlen
;
1051 SmiNode
*smiNode
= NULL
;
1054 if (!nd_smi_module_loaded
) {
1055 *status
= asn1_print(ndo
, elem
);
1058 *status
= smi_decode_oid(ndo
, elem
, oid
, sizeof(oid
) / sizeof(unsigned int),
1062 smiNode
= smiGetNodeByOID(oidlen
, oid
);
1064 *status
= asn1_print(ndo
, elem
);
1067 if (ndo
->ndo_vflag
) {
1068 ND_PRINT("%s::", smiGetNodeModule(smiNode
)->name
);
1070 ND_PRINT("%s", smiNode
->name
);
1071 if (smiNode
->oidlen
< oidlen
) {
1072 for (i
= smiNode
->oidlen
; i
< oidlen
; i
++) {
1073 ND_PRINT(".%u", oid
[i
]);
1081 smi_print_value(netdissect_options
*ndo
,
1082 SmiNode
*smiNode
, u_short pduid
, struct be
*elem
)
1084 unsigned int i
, oid
[128], oidlen
;
1089 if (! smiNode
|| ! (smiNode
->nodekind
1090 & (SMI_NODEKIND_SCALAR
| SMI_NODEKIND_COLUMN
))) {
1091 return asn1_print(ndo
, elem
);
1094 if (elem
->type
== BE_NOSUCHOBJECT
1095 || elem
->type
== BE_NOSUCHINST
1096 || elem
->type
== BE_ENDOFMIBVIEW
) {
1097 return asn1_print(ndo
, elem
);
1100 if (NOTIFY_CLASS(pduid
) && smiNode
->access
< SMI_ACCESS_NOTIFY
) {
1101 ND_PRINT("[notNotifyable]");
1104 if (READ_CLASS(pduid
) && smiNode
->access
< SMI_ACCESS_READ_ONLY
) {
1105 ND_PRINT("[notReadable]");
1108 if (WRITE_CLASS(pduid
) && smiNode
->access
< SMI_ACCESS_READ_WRITE
) {
1109 ND_PRINT("[notWritable]");
1112 if (RESPONSE_CLASS(pduid
)
1113 && smiNode
->access
== SMI_ACCESS_NOT_ACCESSIBLE
) {
1114 ND_PRINT("[noAccess]");
1117 smiType
= smiGetNodeType(smiNode
);
1119 return asn1_print(ndo
, elem
);
1122 if (! smi_check_type(smiType
->basetype
, elem
->type
)) {
1123 ND_PRINT("[wrongType]");
1126 if (! smi_check_range(smiType
, elem
)) {
1127 ND_PRINT("[outOfRange]");
1130 /* resolve bits to named bits */
1132 /* check whether instance identifier is valid */
1134 /* apply display hints (integer, octetstring) */
1136 /* convert instance identifier to index type values */
1138 switch (elem
->type
) {
1140 if (smiType
->basetype
== SMI_BASETYPE_BITS
) {
1141 /* print bit labels */
1143 if (nd_smi_module_loaded
&&
1144 smi_decode_oid(ndo
, elem
, oid
,
1145 sizeof(oid
)/sizeof(unsigned int),
1147 smiNode
= smiGetNodeByOID(oidlen
, oid
);
1149 if (ndo
->ndo_vflag
) {
1150 ND_PRINT("%s::", smiGetNodeModule(smiNode
)->name
);
1152 ND_PRINT("%s", smiNode
->name
);
1153 if (smiNode
->oidlen
< oidlen
) {
1154 for (i
= smiNode
->oidlen
;
1156 ND_PRINT(".%u", oid
[i
]);
1166 if (smiType
->basetype
== SMI_BASETYPE_ENUM
) {
1167 for (nn
= smiGetFirstNamedNumber(smiType
);
1169 nn
= smiGetNextNamedNumber(nn
)) {
1170 if (nn
->value
.value
.integer32
1171 == elem
->data
.integer
) {
1172 ND_PRINT("%s", nn
->name
);
1173 ND_PRINT("(%d)", elem
->data
.integer
);
1183 return asn1_print(ndo
, elem
);
1190 * General SNMP header
1192 * version INTEGER {version-1(0)},
1193 * community OCTET STRING,
1196 * PDUs for all but Trap: (see rfc1157 from page 15 on)
1198 * request-id INTEGER,
1199 * error-status INTEGER,
1200 * error-index INTEGER,
1201 * varbindlist SEQUENCE OF
1209 * enterprise OBJECT IDENTIFIER,
1210 * agent-addr NetworkAddress,
1211 * generic-trap INTEGER,
1212 * specific-trap INTEGER,
1213 * time-stamp TimeTicks,
1214 * varbindlist SEQUENCE OF
1223 * Decode SNMP varBind
1226 varbind_print(netdissect_options
*ndo
,
1227 u_short pduid
, const u_char
*np
, u_int length
)
1232 SmiNode
*smiNode
= NULL
;
1236 /* Sequence of varBind */
1237 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1239 if (elem
.type
!= BE_SEQ
) {
1240 ND_PRINT("[!SEQ of varbind]");
1241 asn1_print(ndo
, &elem
);
1244 if ((u_int
)count
< length
)
1245 ND_PRINT("[%d extra after SEQ of varbind]", length
- count
);
1247 length
= elem
.asnlen
;
1248 np
= (const u_char
*)elem
.data
.raw
;
1250 for (ind
= 1; length
> 0; ind
++) {
1251 const u_char
*vbend
;
1257 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1259 if (elem
.type
!= BE_SEQ
) {
1260 ND_PRINT("[!varbind]");
1261 asn1_print(ndo
, &elem
);
1265 vblength
= length
- count
;
1267 length
= elem
.asnlen
;
1268 np
= (const u_char
*)elem
.data
.raw
;
1271 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1273 if (elem
.type
!= BE_OID
) {
1274 ND_PRINT("[objName!=OID]");
1275 asn1_print(ndo
, &elem
);
1279 smiNode
= smi_print_variable(ndo
, &elem
, &status
);
1281 status
= asn1_print(ndo
, &elem
);
1288 if (pduid
!= GETREQ
&& pduid
!= GETNEXTREQ
1289 && pduid
!= GETBULKREQ
)
1293 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1295 if (pduid
== GETREQ
|| pduid
== GETNEXTREQ
1296 || pduid
== GETBULKREQ
) {
1297 if (elem
.type
!= BE_NULL
) {
1298 ND_PRINT("[objVal!=NULL]");
1299 if (asn1_print(ndo
, &elem
) < 0)
1303 if (elem
.type
!= BE_NULL
) {
1305 status
= smi_print_value(ndo
, smiNode
, pduid
, &elem
);
1307 status
= asn1_print(ndo
, &elem
);
1319 * Decode SNMP PDUs: GetRequest, GetNextRequest, GetResponse, SetRequest,
1320 * GetBulk, Inform, V2Trap, and Report
1323 snmppdu_print(netdissect_options
*ndo
,
1324 u_short pduid
, const u_char
*np
, u_int length
)
1327 int count
= 0, error_status
;
1329 /* reqId (Integer) */
1330 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1332 if (elem
.type
!= BE_INT
) {
1333 ND_PRINT("[reqId!=INT]");
1334 asn1_print(ndo
, &elem
);
1338 ND_PRINT("R=%d ", elem
.data
.integer
);
1342 /* errorStatus (Integer) */
1343 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1345 if (elem
.type
!= BE_INT
) {
1346 ND_PRINT("[errorStatus!=INT]");
1347 asn1_print(ndo
, &elem
);
1351 if ((pduid
== GETREQ
|| pduid
== GETNEXTREQ
|| pduid
== SETREQ
1352 || pduid
== INFORMREQ
|| pduid
== V2TRAP
|| pduid
== REPORT
)
1353 && elem
.data
.integer
!= 0) {
1355 ND_PRINT("[errorStatus(%s)!=0]",
1356 DECODE_ErrorStatus(elem
.data
.integer
));
1357 } else if (pduid
== GETBULKREQ
) {
1358 ND_PRINT(" N=%d", elem
.data
.integer
);
1359 } else if (elem
.data
.integer
!= 0) {
1361 ND_PRINT(" %s", DECODE_ErrorStatus(elem
.data
.integer
));
1362 error_status
= elem
.data
.integer
;
1367 /* errorIndex (Integer) */
1368 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1370 if (elem
.type
!= BE_INT
) {
1371 ND_PRINT("[errorIndex!=INT]");
1372 asn1_print(ndo
, &elem
);
1375 if ((pduid
== GETREQ
|| pduid
== GETNEXTREQ
|| pduid
== SETREQ
1376 || pduid
== INFORMREQ
|| pduid
== V2TRAP
|| pduid
== REPORT
)
1377 && elem
.data
.integer
!= 0)
1378 ND_PRINT("[errorIndex(%d)!=0]", elem
.data
.integer
);
1379 else if (pduid
== GETBULKREQ
)
1380 ND_PRINT(" M=%d", elem
.data
.integer
);
1381 else if (elem
.data
.integer
!= 0) {
1383 ND_PRINT("[errorIndex(%d) w/o errorStatus]", elem
.data
.integer
);
1385 ND_PRINT("@%d", elem
.data
.integer
);
1386 } else if (error_status
) {
1387 ND_PRINT("[errorIndex==0]");
1392 varbind_print(ndo
, pduid
, np
, length
);
1397 * Decode SNMP Trap PDU
1400 trappdu_print(netdissect_options
*ndo
,
1401 const u_char
*np
, u_int length
)
1404 int count
= 0, generic
;
1408 /* enterprise (oid) */
1409 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1411 if (elem
.type
!= BE_OID
) {
1412 ND_PRINT("[enterprise!=OID]");
1413 asn1_print(ndo
, &elem
);
1416 if (asn1_print(ndo
, &elem
) < 0)
1423 /* agent-addr (inetaddr) */
1424 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1426 if (elem
.type
!= BE_INETADDR
) {
1427 ND_PRINT("[agent-addr!=INETADDR]");
1428 asn1_print(ndo
, &elem
);
1431 if (asn1_print(ndo
, &elem
) < 0)
1436 /* generic-trap (Integer) */
1437 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1439 if (elem
.type
!= BE_INT
) {
1440 ND_PRINT("[generic-trap!=INT]");
1441 asn1_print(ndo
, &elem
);
1444 generic
= elem
.data
.integer
;
1447 ND_PRINT(" %s", DECODE_GenericTrap(generic
));
1452 /* specific-trap (Integer) */
1453 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1455 if (elem
.type
!= BE_INT
) {
1456 ND_PRINT("[specific-trap!=INT]");
1457 asn1_print(ndo
, &elem
);
1460 if (generic
!= GT_ENTERPRISE
) {
1461 if (elem
.data
.integer
!= 0)
1462 ND_PRINT("[specific-trap(%d)!=0]", elem
.data
.integer
);
1464 ND_PRINT(" s=%d", elem
.data
.integer
);
1470 /* time-stamp (TimeTicks) */
1471 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1473 if (elem
.type
!= BE_UNS
) { /* XXX */
1474 ND_PRINT("[time-stamp!=TIMETICKS]");
1475 asn1_print(ndo
, &elem
);
1478 if (asn1_print(ndo
, &elem
) < 0)
1483 varbind_print(ndo
, TRAP
, np
, length
);
1488 * Decode arbitrary SNMP PDUs.
1491 pdu_print(netdissect_options
*ndo
,
1492 const u_char
*np
, u_int length
, int version
)
1498 if ((count
= asn1_parse(ndo
, np
, length
, &pdu
)) < 0)
1500 if (pdu
.type
!= BE_PDU
) {
1501 ND_PRINT("[no PDU]");
1504 if ((u_int
)count
< length
)
1505 ND_PRINT("[%d extra after PDU]", length
- count
);
1506 if (ndo
->ndo_vflag
) {
1509 if (asn1_print(ndo
, &pdu
) < 0)
1512 /* descend into PDU */
1513 length
= pdu
.asnlen
;
1514 np
= (const u_char
*)pdu
.data
.raw
;
1516 if (version
== SNMP_VERSION_1
&&
1517 (pdu
.id
== GETBULKREQ
|| pdu
.id
== INFORMREQ
||
1518 pdu
.id
== V2TRAP
|| pdu
.id
== REPORT
)) {
1519 ND_PRINT("[v2 PDU in v1 message]");
1523 if (version
== SNMP_VERSION_2
&& pdu
.id
== TRAP
) {
1524 ND_PRINT("[v1 PDU in v2 message]");
1530 trappdu_print(ndo
, np
, length
);
1540 snmppdu_print(ndo
, pdu
.id
, np
, length
);
1544 if (ndo
->ndo_vflag
) {
1550 * Decode a scoped SNMP PDU.
1553 scopedpdu_print(netdissect_options
*ndo
,
1554 const u_char
*np
, u_int length
, int version
)
1560 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1562 if (elem
.type
!= BE_SEQ
) {
1563 ND_PRINT("[!scoped PDU]");
1564 asn1_print(ndo
, &elem
);
1567 length
= elem
.asnlen
;
1568 np
= (const u_char
*)elem
.data
.raw
;
1570 /* contextEngineID (OCTET STRING) */
1571 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1573 if (elem
.type
!= BE_STR
) {
1574 ND_PRINT("[contextEngineID!=STR]");
1575 asn1_print(ndo
, &elem
);
1582 if (asn1_print_octets(ndo
, &elem
) == -1)
1586 /* contextName (OCTET STRING) */
1587 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1589 if (elem
.type
!= BE_STR
) {
1590 ND_PRINT("[contextName!=STR]");
1591 asn1_print(ndo
, &elem
);
1598 if (asn1_print_string(ndo
, &elem
) == -1)
1602 pdu_print(ndo
, np
, length
, version
);
1606 * Decode SNMP Community Header (SNMPv1 and SNMPv2c)
1609 community_print(netdissect_options
*ndo
,
1610 const u_char
*np
, u_int length
, int version
)
1615 /* Community (String) */
1616 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1618 if (elem
.type
!= BE_STR
) {
1619 ND_PRINT("[comm!=STR]");
1620 asn1_print(ndo
, &elem
);
1623 /* default community */
1624 if (!(elem
.asnlen
== sizeof(DEF_COMMUNITY
) - 1 &&
1625 strncmp((const char *)elem
.data
.str
, DEF_COMMUNITY
,
1626 sizeof(DEF_COMMUNITY
) - 1) == 0)) {
1629 if (asn1_print_string(ndo
, &elem
) == -1)
1636 pdu_print(ndo
, np
, length
, version
);
1640 * Decode SNMPv3 User-based Security Message Header (SNMPv3)
1643 usm_print(netdissect_options
*ndo
,
1644 const u_char
*np
, u_int length
)
1650 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1652 if (elem
.type
!= BE_SEQ
) {
1654 asn1_print(ndo
, &elem
);
1657 length
= elem
.asnlen
;
1658 np
= (const u_char
*)elem
.data
.raw
;
1660 /* msgAuthoritativeEngineID (OCTET STRING) */
1661 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1663 if (elem
.type
!= BE_STR
) {
1664 ND_PRINT("[msgAuthoritativeEngineID!=STR]");
1665 asn1_print(ndo
, &elem
);
1671 /* msgAuthoritativeEngineBoots (INTEGER) */
1672 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1674 if (elem
.type
!= BE_INT
) {
1675 ND_PRINT("[msgAuthoritativeEngineBoots!=INT]");
1676 asn1_print(ndo
, &elem
);
1680 ND_PRINT("B=%d ", elem
.data
.integer
);
1684 /* msgAuthoritativeEngineTime (INTEGER) */
1685 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1687 if (elem
.type
!= BE_INT
) {
1688 ND_PRINT("[msgAuthoritativeEngineTime!=INT]");
1689 asn1_print(ndo
, &elem
);
1693 ND_PRINT("T=%d ", elem
.data
.integer
);
1697 /* msgUserName (OCTET STRING) */
1698 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1700 if (elem
.type
!= BE_STR
) {
1701 ND_PRINT("[msgUserName!=STR]");
1702 asn1_print(ndo
, &elem
);
1709 if (asn1_print_string(ndo
, &elem
) == -1)
1713 /* msgAuthenticationParameters (OCTET STRING) */
1714 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1716 if (elem
.type
!= BE_STR
) {
1717 ND_PRINT("[msgAuthenticationParameters!=STR]");
1718 asn1_print(ndo
, &elem
);
1724 /* msgPrivacyParameters (OCTET STRING) */
1725 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1727 if (elem
.type
!= BE_STR
) {
1728 ND_PRINT("[msgPrivacyParameters!=STR]");
1729 asn1_print(ndo
, &elem
);
1735 if ((u_int
)count
< length
)
1736 ND_PRINT("[%d extra after usm SEQ]", length
- count
);
1740 * Decode SNMPv3 Message Header (SNMPv3)
1743 v3msg_print(netdissect_options
*ndo
,
1744 const u_char
*np
, u_int length
)
1750 const u_char
*xnp
= np
;
1751 int xlength
= length
;
1754 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1756 if (elem
.type
!= BE_SEQ
) {
1757 ND_PRINT("[!message]");
1758 asn1_print(ndo
, &elem
);
1761 length
= elem
.asnlen
;
1762 np
= (const u_char
*)elem
.data
.raw
;
1764 if (ndo
->ndo_vflag
) {
1768 /* msgID (INTEGER) */
1769 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1771 if (elem
.type
!= BE_INT
) {
1772 ND_PRINT("[msgID!=INT]");
1773 asn1_print(ndo
, &elem
);
1779 /* msgMaxSize (INTEGER) */
1780 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1782 if (elem
.type
!= BE_INT
) {
1783 ND_PRINT("[msgMaxSize!=INT]");
1784 asn1_print(ndo
, &elem
);
1790 /* msgFlags (OCTET STRING) */
1791 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1793 if (elem
.type
!= BE_STR
) {
1794 ND_PRINT("[msgFlags!=STR]");
1795 asn1_print(ndo
, &elem
);
1798 if (elem
.asnlen
!= 1) {
1799 ND_PRINT("[msgFlags size %d]", elem
.asnlen
);
1802 flags
= EXTRACT_U_1(elem
.data
.str
);
1803 if (flags
!= 0x00 && flags
!= 0x01 && flags
!= 0x03
1804 && flags
!= 0x04 && flags
!= 0x05 && flags
!= 0x07) {
1805 ND_PRINT("[msgFlags=0x%02X]", flags
);
1811 ND_PRINT("F=%s%s%s ",
1812 flags
& 0x01 ? "a" : "",
1813 flags
& 0x02 ? "p" : "",
1814 flags
& 0x04 ? "r" : "");
1816 /* msgSecurityModel (INTEGER) */
1817 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1819 if (elem
.type
!= BE_INT
) {
1820 ND_PRINT("[msgSecurityModel!=INT]");
1821 asn1_print(ndo
, &elem
);
1824 model
= elem
.data
.integer
;
1828 if ((u_int
)count
< length
)
1829 ND_PRINT("[%d extra after message SEQ]", length
- count
);
1831 if (ndo
->ndo_vflag
) {
1836 if (ndo
->ndo_vflag
) {
1840 ND_PRINT("[security model %d]", model
);
1844 np
= xnp
+ (np
- xnp
);
1845 length
= xlength
- (np
- xnp
);
1847 /* msgSecurityParameters (OCTET STRING) */
1848 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1850 if (elem
.type
!= BE_STR
) {
1851 ND_PRINT("[msgSecurityParameters!=STR]");
1852 asn1_print(ndo
, &elem
);
1859 usm_print(ndo
, elem
.data
.str
, elem
.asnlen
);
1860 if (ndo
->ndo_vflag
) {
1865 if (ndo
->ndo_vflag
) {
1866 ND_PRINT("{ ScopedPDU ");
1869 scopedpdu_print(ndo
, np
, length
, 3);
1871 if (ndo
->ndo_vflag
) {
1877 * Decode SNMP header and pass on to PDU printing routines
1880 snmp_print(netdissect_options
*ndo
,
1881 const u_char
*np
, u_int length
)
1889 /* initial Sequence */
1890 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1892 if (elem
.type
!= BE_SEQ
) {
1893 ND_PRINT("[!init SEQ]");
1894 asn1_print(ndo
, &elem
);
1897 if ((u_int
)count
< length
)
1898 ND_PRINT("[%d extra after iSEQ]", length
- count
);
1900 length
= elem
.asnlen
;
1901 np
= (const u_char
*)elem
.data
.raw
;
1903 /* Version (INTEGER) */
1904 if ((count
= asn1_parse(ndo
, np
, length
, &elem
)) < 0)
1906 if (elem
.type
!= BE_INT
) {
1907 ND_PRINT("[version!=INT]");
1908 asn1_print(ndo
, &elem
);
1912 switch (elem
.data
.integer
) {
1913 case SNMP_VERSION_1
:
1914 case SNMP_VERSION_2
:
1915 case SNMP_VERSION_3
:
1917 ND_PRINT("{ %s ", SnmpVersion
[elem
.data
.integer
]);
1920 ND_PRINT("SNMP [version = %d]", elem
.data
.integer
);
1923 version
= elem
.data
.integer
;
1928 case SNMP_VERSION_1
:
1929 case SNMP_VERSION_2
:
1930 community_print(ndo
, np
, length
, version
);
1932 case SNMP_VERSION_3
:
1933 v3msg_print(ndo
, np
, length
);
1936 ND_PRINT("[version = %d]", elem
.data
.integer
);
1940 if (ndo
->ndo_vflag
) {