]> The Tcpdump Group git mirrors - tcpdump/blobdiff - print-cdp.c
Revert partially the commit 21b1273
[tcpdump] / print-cdp.c
index 257f5131b52c2df7b4d7c9f3269dde5643634e2f..0ab646e51dee71dd63296ee4bd1b9c80a58ac94a 100644 (file)
  * Code by Gert Doering, SpaceNet GmbH, [email protected]
  *
  * Reference documentation:
- *    http://www.cisco.com/univercd/cc/td/doc/product/lan/trsrb/frames.htm
+ *    https://web.archive.org/web/20000914194913/http://www.cisco.com/univercd/cc/td/doc/product/lan/trsrb/frames.pdf
  */
 
-#ifndef lint
-static const char rcsid[] =
-    "@(#) $Header: /tcpdump/master/tcpdump/print-cdp.c,v 1.6 2001-06-15 07:54:19 itojun Exp $";
-#endif
+/* \summary: Cisco Discovery Protocol (CDP) printer */
 
 #ifdef HAVE_CONFIG_H
-#include "config.h"
+#include <config.h>
 #endif
 
-#include <sys/param.h>
-#include <sys/time.h>
-
-#include <netinet/in.h>
+#include "netdissect-stdinc.h"
 
-#include <ctype.h>
-#include <netdb.h>
-#include <stdio.h>
 #include <string.h>
 
-#include "interface.h"
+#include "netdissect.h"
 #include "addrtoname.h"
-#include "extract.h"                   /* must come after interface.h */
+#include "extract.h"
+#include "nlpid.h"
+
+
+#define CDP_HEADER_LEN             4
+#define CDP_HEADER_VERSION_OFFSET  0
+#define CDP_HEADER_TTL_OFFSET      1
+#define CDP_HEADER_CHECKSUM_OFFSET 2
+
+#define CDP_TLV_HEADER_LEN  4
+#define CDP_TLV_TYPE_OFFSET 0
+#define CDP_TLV_LEN_OFFSET  2
+
+static const struct tok cdp_tlv_values[] = {
+    { 0x01,             "Device-ID"},
+    { 0x02,             "Address"},
+    { 0x03,             "Port-ID"},
+    { 0x04,             "Capability"},
+    { 0x05,             "Version String"},
+    { 0x06,             "Platform"},
+    { 0x07,             "Prefixes"},
+    { 0x08,             "Protocol-Hello option"},
+    { 0x09,             "VTP Management Domain"},
+    { 0x0a,             "Native VLAN ID"},
+    { 0x0b,             "Duplex"},
+    { 0x0e,             "ATA-186 VoIP VLAN assignment"},
+    { 0x0f,             "ATA-186 VoIP VLAN request"},
+    { 0x10,             "power consumption"},
+    { 0x11,             "MTU"},
+    { 0x12,             "AVVID trust bitmap"},
+    { 0x13,             "AVVID untrusted ports CoS"},
+    { 0x14,             "System Name"},
+    { 0x15,             "System Object ID (not decoded)"},
+    { 0x16,             "Management Addresses"},
+    { 0x17,             "Physical Location"},
+    { 0, NULL}
+};
+
+static const struct tok cdp_capability_values[] = {
+    { 0x01,             "Router" },
+    { 0x02,             "Transparent Bridge" },
+    { 0x04,             "Source Route Bridge" },
+    { 0x08,             "L2 Switch" },
+    { 0x10,             "L3 capable" },
+    { 0x20,             "IGMP snooping" },
+    { 0x40,             "L1 capable" },
+    { 0, NULL }
+};
 
-static void cdp_print_addr(const u_char *, int);
-static void cdp_print_prefixes(const u_char *, int);
+static int cdp_print_addr(netdissect_options *, const u_char *, u_int);
+static int cdp_print_prefixes(netdissect_options *, const u_char *, u_int);
+static unsigned int cdp_get_number(netdissect_options *, const u_char *, u_int);
 
 void
-cdp_print(const u_char *p, u_int length, u_int caplen,
-         const u_char *esrc, const u_char *edst)
+cdp_print(netdissect_options *ndo,
+          const u_char *pptr, u_int length, u_int caplen)
 {
-       int i;
-       int type, len;
+       u_int type, len, i;
+       const u_char *tptr;
 
-       /* Cisco Discovery Protocol */
-
-       if (caplen < 4) {
-               (void)printf("[|cdp]");
+       ndo->ndo_protocol = "cdp";
+       if (caplen < CDP_HEADER_LEN) {
+               nd_print_trunc(ndo);
                return;
        }
 
-       i = 0;          /* CDP data starts at offset 0 */
-       printf("CDP v%u, ttl=%us", p[i], p[i + 1]);
-       i += 4;         /* skip version, TTL and chksum */
+       tptr = pptr; /* temporary pointer */
 
-       while (i < length) {
-               if (i + 4 > caplen)
-                       goto trunc;
-               type = (p[i] <<  8) + p[i + 1];
-               len  = (p[i + 2] << 8) + p[i + 3];
+       ND_TCHECK_LEN(tptr, CDP_HEADER_LEN);
+       ND_PRINT("CDPv%u, ttl: %us",
+                                          GET_U_1((tptr + CDP_HEADER_VERSION_OFFSET)),
+                                          GET_U_1(tptr + CDP_HEADER_TTL_OFFSET));
+       if (ndo->ndo_vflag)
+               ND_PRINT(", checksum: 0x%04x (unverified), length %u",
+                        GET_BE_U_2(tptr + CDP_HEADER_CHECKSUM_OFFSET),
+                        length);
+       tptr += CDP_HEADER_LEN;
 
-               if (vflag > 1)
-                       printf("\n\t");
+       while (tptr < (pptr+length)) {
+               ND_TCHECK_LEN(tptr, CDP_TLV_HEADER_LEN); /* read out Type and Length */
+               type = GET_BE_U_2(tptr + CDP_TLV_TYPE_OFFSET);
+               len  = GET_BE_U_2(tptr + CDP_TLV_LEN_OFFSET); /* object length includes the 4 bytes header length */
+               if (len < CDP_TLV_HEADER_LEN) {
+                   if (ndo->ndo_vflag)
+                       ND_PRINT("\n\t%s (0x%02x), TLV length: %u byte%s (too short)",
+                              tok2str(cdp_tlv_values,"unknown field type", type),
+                              type,
+                              len,
+                              PLURAL_SUFFIX(len)); /* plural */
+                   else
+                       ND_PRINT(", %s TLV length %u too short",
+                              tok2str(cdp_tlv_values,"unknown field type", type),
+                              len);
+                   break;
+               }
+               tptr += CDP_TLV_HEADER_LEN;
+               len -= CDP_TLV_HEADER_LEN;
 
-               if (vflag)
-                       printf(" %02x/%02x", type, len);
+               ND_TCHECK_LEN(tptr, len);
 
-               if (i + len > caplen)
-                       goto trunc;
+               if (ndo->ndo_vflag || type == 1) { /* in non-verbose mode just print Device-ID */
 
-               switch (type) {
-               case 0x01:
-                       printf(" DevID '%.*s'", len - 4, p + i + 4);
+                   if (ndo->ndo_vflag)
+                       ND_PRINT("\n\t%s (0x%02x), value length: %u byte%s: ",
+                              tok2str(cdp_tlv_values,"unknown field type", type),
+                              type,
+                              len,
+                              PLURAL_SUFFIX(len)); /* plural */
+
+                   switch (type) {
+
+                   case 0x01: /* Device-ID */
+                       if (!ndo->ndo_vflag)
+                           ND_PRINT(", Device-ID ");
+                       ND_PRINT("'");
+                       (void)nd_printn(ndo, tptr, len, NULL);
+                       ND_PRINT("'");
                        break;
-               case 0x02:
-                       printf(" Addr");
-                       cdp_print_addr(p + i + 4, len - 4);
+                   case 0x02: /* Address */
+                       if (cdp_print_addr(ndo, tptr, len) < 0)
+                           goto trunc;
                        break;
-               case 0x03:
-                       printf(" PortID '%.*s'", len - 4, p + i + 4);
+                   case 0x03: /* Port-ID */
+                       ND_PRINT("'");
+                       (void)nd_printn(ndo, tptr, len, NULL);
+                       ND_PRINT("'");
                        break;
-               case 0x04:
-                       printf(" CAP 0x%02x", (unsigned) p[i + 7]);
+                   case 0x04: /* Capabilities */
+                       if (len < 4)
+                           goto trunc;
+                       ND_PRINT("(0x%08x): %s",
+                              GET_BE_U_4(tptr),
+                              bittok2str(cdp_capability_values, "none", GET_BE_U_4(tptr)));
                        break;
-               case 0x05:
-                       if (vflag > 1)
-                               printf(" Version:\n%.*s", len - 4, p + i + 4);
-                       else
-                               printf(" Version: (suppressed)");
+                   case 0x05: /* Version */
+                       ND_PRINT("\n\t  ");
+                       for (i=0;i<len;i++) {
+                           u_char c;
+
+                           c = GET_U_1(tptr + i);
+                           if (c == '\n') /* lets rework the version string to
+                                             get a nice indentation */
+                               ND_PRINT("\n\t  ");
+                           else
+                               fn_print_char(ndo, c);
+                       }
                        break;
-               case 0x06:
-                       printf(" Platform: '%.*s'", len - 4, p + i + 4);
+                   case 0x06: /* Platform */
+                       ND_PRINT("'");
+                       (void)nd_printn(ndo, tptr, len, NULL);
+                       ND_PRINT("'");
                        break;
-               case 0x07:
-                       cdp_print_prefixes(p + i + 4, len - 4);
+                   case 0x07: /* Prefixes */
+                       if (cdp_print_prefixes(ndo, tptr, len) < 0)
+                           goto trunc;
                        break;
-               case 0x09:              /* guess - not documented */
-                       printf(" VTP Management Domain: '%.*s'", len - 4,
-                           p + i + 4);
+                   case 0x08: /* Protocol Hello Option - not documented */
                        break;
-               case 0x0a:              /* guess - not documented */
-                       printf(" Native VLAN ID: %d",
-                           (p[i + 4] << 8) + p[i + 4 + 1] - 1);
+                   case 0x09: /* VTP Mgmt Domain  - CDPv2 */
+                       ND_PRINT("'");
+                       (void)nd_printn(ndo, tptr, len, NULL);
+                       ND_PRINT("'");
                        break;
-               case 0x0b:              /* guess - not documented */
-                       printf(" Duplex: %s", p[i + 4] ? "full": "half");
+                   case 0x0a: /* Native VLAN ID - CDPv2 */
+                       if (len < 2)
+                           goto trunc;
+                       ND_PRINT("%u", GET_BE_U_2(tptr));
                        break;
-               default:
-                       printf(" unknown field type %02x, len %d", type, len);
+                   case 0x0b: /* Duplex - CDPv2 */
+                       if (len < 1)
+                           goto trunc;
+                       ND_PRINT("%s", GET_U_1(tptr) ? "full": "half");
                        break;
-               }
 
-               /* avoid infinite loop */
-               if (len == 0)
+                   /* https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cata/186/2_12_m/english/release/notes/186rn21m.html
+                    * plus more details from other sources
+                    *
+                    * There are apparently versions of the request with both
+                    * 2 bytes and 3 bytes of value.  The 3 bytes of value
+                    * appear to be a 1-byte application type followed by a
+                    * 2-byte VLAN ID; the 2 bytes of value are unknown
+                    * (they're 0x20 0x00 in some captures I've seen; that
+                    * is not a valid VLAN ID, as VLAN IDs are 12 bits).
+                    *
+                    * The replies all appear to be 3 bytes long.
+                    */
+                   case 0x0e: /* ATA-186 VoIP VLAN assignment - incomplete doc. */
+                       if (len < 3)
+                           goto trunc;
+                       ND_PRINT("app %u, vlan %u", GET_U_1(tptr),
+                                GET_BE_U_2(tptr + 1));
+                       break;
+                   case 0x0f: /* ATA-186 VoIP VLAN request - incomplete doc. */
+                       if (len < 2)
+                           goto trunc;
+                       if (len == 2)
+                           ND_PRINT("unknown 0x%04x", GET_BE_U_2(tptr));
+                       else
+                           ND_PRINT("app %u, vlan %u", GET_U_1(tptr),
+                                    GET_BE_U_2(tptr + 1));
+                       break;
+                   case 0x10: /* Power - not documented */
+                       ND_PRINT("%1.2fW", cdp_get_number(ndo, tptr, len) / 1000.0);
+                       break;
+                   case 0x11: /* MTU - not documented */
+                       if (len < 4)
+                           goto trunc;
+                       ND_PRINT("%u bytes", GET_BE_U_4(tptr));
+                       break;
+                   case 0x12: /* AVVID trust bitmap - not documented */
+                       if (len < 1)
+                           goto trunc;
+                       ND_PRINT("0x%02x", GET_U_1(tptr));
                        break;
-               i += len;
+                   case 0x13: /* AVVID untrusted port CoS - not documented */
+                       if (len < 1)
+                           goto trunc;
+                       ND_PRINT("0x%02x", GET_U_1(tptr));
+                       break;
+                   case 0x14: /* System Name - not documented */
+                       ND_PRINT("'");
+                       (void)nd_printn(ndo, tptr, len, NULL);
+                       ND_PRINT("'");
+                       break;
+                   case 0x16: /* System Object ID - not documented */
+                       if (cdp_print_addr(ndo, tptr, len) < 0)
+                               goto trunc;
+                       break;
+                   case 0x17: /* Physical Location - not documented */
+                       if (len < 1)
+                           goto trunc;
+                       ND_PRINT("0x%02x", GET_U_1(tptr));
+                       if (len > 1) {
+                               ND_PRINT("/");
+                               (void)nd_printn(ndo, tptr + 1, len - 1, NULL);
+                       }
+                       break;
+                   default:
+                       print_unknown_data(ndo, tptr, "\n\t  ", len);
+                       break;
+                   }
+               }
+               tptr = tptr+len;
        }
+       if (ndo->ndo_vflag < 1)
+           ND_PRINT(", length %u", caplen);
 
        return;
-
 trunc:
-       printf("[|cdp]");
+       nd_print_trunc(ndo);
 }
 
-static void
-cdp_print_addr(const u_char * p, int l)
+/*
+ * Protocol type values.
+ *
+ * PT_NLPID means that the protocol type field contains an OSI NLPID.
+ *
+ * PT_IEEE_802_2 means that the protocol type field contains an IEEE 802.2
+ * LLC header that specifies that the payload is for that protocol.
+ */
+#define PT_NLPID               1       /* OSI NLPID */
+#define PT_IEEE_802_2          2       /* IEEE 802.2 LLC header */
+
+static int
+cdp_print_addr(netdissect_options *ndo,
+              const u_char * p, u_int l)
 {
-       int pl, al, num;
+       u_int pt, pl, al, num;
        const u_char *endp = p + l;
+       static const u_char prot_ipv6[] = {
+               0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00, 0x86, 0xdd
+       };
 
-       num = (p[0] << 24) + (p[1] << 16) + (p[2] << 8) + p[3];
+       ND_TCHECK_4(p);
+       if (p + 4 > endp)
+               goto trunc;
+       num = GET_BE_U_4(p);
        p += 4;
 
-       printf(" (%d): ", num);
-
-       while (p < endp && num >= 0) {
-               if (p + 2 >= endp)
-                       break;
-               pl = p[1];
+       while (p < endp && num != 0) {
+               ND_TCHECK_2(p);
+               if (p + 2 > endp)
+                       goto trunc;
+               pt = GET_U_1(p);                /* type of "protocol" field */
+               pl = GET_U_1(p + 1);    /* length of "protocol" field */
                p += 2;
 
-               /* special case: IPv4, protocol type=0xcc, addr. length=4 */
-               if (p + 3 >= endp)
-                       break;
-               if (pl == 1 && *p == 0xcc && p[1] == 0 && p[2] == 4) {
-                       if (p + 7 >= endp)
-                               break;
+               ND_TCHECK_2(p + pl);
+               if (p + pl + 2 > endp)
+                       goto trunc;
+               al = GET_BE_U_2(p + pl);        /* address length */
+
+               if (pt == PT_NLPID && pl == 1 && GET_U_1(p) == NLPID_IP &&
+                   al == 4) {
+                       /*
+                        * IPv4: protocol type = NLPID, protocol length = 1
+                        * (1-byte NLPID), protocol = 0xcc (NLPID for IPv4),
+                        * address length = 4
+                        */
                        p += 3;
 
-                       printf("IPv4 %u.%u.%u.%u ", p[0], p[1], p[2], p[3]);
+                       if (p + 4 > endp)
+                               goto trunc;
+                       ND_PRINT("IPv4 (%u) %s", num, GET_IPADDR_STRING(p));
                        p += 4;
-               } else {        /* generic case: just print raw data */
-                       if (p + pl >= endp)
-                               break;
-                       printf("pt=0x%02x, pl=%d, pb=", *(p-2), pl);
-                       while (pl-- > 0)
-                               printf(" %02x", *p++);
-                       al = (*p << 8) + *(p + 1);
-                       if (p + 2 + al >= endp)
-                               break;
-                       printf(", al=%d, a=", al);
+               }
+               else if (pt == PT_IEEE_802_2 && pl == 8 &&
+                   memcmp(p, prot_ipv6, 8) == 0 && al == 16) {
+                       /*
+                        * IPv6: protocol type = IEEE 802.2 header,
+                        * protocol length = 8 (size of LLC+SNAP header),
+                        * protocol = LLC+SNAP header with the IPv6
+                        * Ethertype, address length = 16
+                        */
+                       p += 10;
+                       ND_TCHECK_LEN(p, al);
+                       if (p + al > endp)
+                               goto trunc;
+
+                       ND_PRINT("IPv6 (%u) %s", num, GET_IP6ADDR_STRING(p));
+                       p += al;
+               }
+               else {
+                       /*
+                        * Generic case: just print raw data
+                        */
+                       ND_TCHECK_LEN(p, pl);
+                       if (p + pl > endp)
+                               goto trunc;
+                       ND_PRINT("pt=0x%02x, pl=%u, pb=", GET_U_1((p - 2)),
+                                pl);
+                       while (pl != 0) {
+                               ND_PRINT(" %02x", GET_U_1(p));
+                               p++;
+                               pl--;
+                       }
+                       ND_TCHECK_2(p);
+                       if (p + 2 > endp)
+                               goto trunc;
+                       ND_PRINT(", al=%u, a=", al);
                        p += 2;
-                       while (al-- > 0)
-                               printf(" %02x", *p++);
+                       ND_TCHECK_LEN(p, al);
+                       if (p + al > endp)
+                               goto trunc;
+                       while (al != 0) {
+                               ND_PRINT(" %02x", GET_U_1(p));
+                               p++;
+                               al--;
+                       }
                }
-               printf("  ");
                num--;
+               if (num)
+                       ND_PRINT(" ");
        }
+
+       return 0;
+
+trunc:
+       return -1;
 }
 
 
-static void
-cdp_print_prefixes(const u_char * p, int l)
+static int
+cdp_print_prefixes(netdissect_options *ndo,
+                  const u_char * p, u_int l)
 {
-       printf(" IPv4 Prefixes (%d):", l / 5);
+       if (l % 5)
+               goto trunc;
+
+       ND_PRINT(" IPv4 Prefixes (%u):", l / 5);
 
        while (l > 0) {
-               if (l < 5)
-                       break;
-               printf(" %u.%u.%u.%u/%u", p[0], p[1], p[2], p[3], p[4]);
+               ND_PRINT(" %u.%u.%u.%u/%u",
+                         GET_U_1(p), GET_U_1(p + 1), GET_U_1(p + 2),
+                         GET_U_1(p + 3), GET_U_1(p + 4));
                l -= 5;
                p += 5;
        }
+
+       return 0;
+
+trunc:
+       return -1;
+}
+
+/* read in a <n>-byte number, MSB first
+ * (of course this can handle max sizeof(int))
+ */
+static unsigned int
+cdp_get_number(netdissect_options *ndo, const u_char * p, u_int l)
+{
+    unsigned int res=0;
+    while( l>0 )
+    {
+       res = (res<<8) + GET_U_1(p);
+       p++; l--;
+    }
+    return res;
 }