X-Git-Url: https://git.tcpdump.org/tcpdump/blobdiff_plain/4e2e9c244affec1bdf012083a8af3c91403962f0..refs/pull/1034/head:/print-openflow.c diff --git a/print-openflow.c b/print-openflow.c index 87a68a47..6024a215 100644 --- a/print-openflow.c +++ b/print-openflow.c @@ -38,13 +38,22 @@ #include "netdissect-stdinc.h" +#define ND_LONGJMP_FROM_TCHECK #include "netdissect.h" #include "extract.h" #include "openflow.h" #include "oui.h" -#define OF_VER_1_0 0x01 +static const struct tok ofver_str[] = { + { OF_VER_1_0, "1.0" }, + { OF_VER_1_1, "1.1" }, + { OF_VER_1_2, "1.2" }, + { OF_VER_1_3, "1.3" }, + { OF_VER_1_4, "1.4" }, + { OF_VER_1_5, "1.5" }, + { 0, NULL } +}; const struct tok onf_exp_str[] = { { ONF_EXP_ONF, "ONF Extensions" }, @@ -55,6 +64,9 @@ const struct tok onf_exp_str[] = { { ONF_EXP_WMOB, "Wireless and Mobility Extensions" }, { ONF_EXP_FABS, "Forwarding Abstractions Extensions" }, { ONF_EXP_OTRANS, "Optical Transport Extensions" }, + { ONF_EXP_NBLNCTU, "Network Benchmarking Lab, NCTU" }, + { ONF_EXP_MPCE, "Mobile Packet Core Extensions" }, + { ONF_EXP_MPLSTPSPTN, "MPLS-TP OpenFlow Extensions for SPTN" }, { 0, NULL } }; @@ -65,12 +77,65 @@ of_vendor_name(const uint32_t vendor) return tok2str(table, "unknown", vendor); } +void +of_bitmap_print(netdissect_options *ndo, + const struct tok *t, const uint32_t v, const uint32_t u) +{ + /* Assigned bits? */ + if (v & ~u) + ND_PRINT(" (%s)", bittok2str(t, "", v)); + /* Unassigned bits? */ + if (v & u) + ND_PRINT(" (bogus)"); +} + +void +of_data_print(netdissect_options *ndo, + const u_char *cp, const u_int len) +{ + if (len == 0) + return; + /* data */ + ND_PRINT("\n\t data (%u octets)", len); + if (ndo->ndo_vflag >= 2) + hex_and_ascii_print(ndo, "\n\t ", cp, len); + else + ND_TCHECK_LEN(cp, len); +} + static void -of_header_print(netdissect_options *ndo, const uint8_t version, const uint8_t type, - const uint16_t length, const uint32_t xid) +of_message_print(netdissect_options *ndo, + const u_char *cp, uint16_t len, + const struct of_msgtypeinfo *mti) { - ND_PRINT("\n\tversion unknown (0x%02x), type 0x%02x, length %u, xid 0x%08x", - version, type, length, xid); + /* + * Here "cp" and "len" stand for the message part beyond the common + * OpenFlow 1.0 header, if any. + * + * Most message types are longer than just the header, and the length + * constraints may be complex. When possible, validate the constraint + * completely here (REQ_FIXLEN), otherwise check that the message is + * long enough to begin the decoding (REQ_MINLEN) and have the + * type-specific function do any remaining validation. + */ + + if (!mti) + goto tcheck_remainder; + + if ((mti->req_what == REQ_FIXLEN && len != mti->req_value) || + (mti->req_what == REQ_MINLEN && len < mti->req_value)) + goto invalid; + + if (!ndo->ndo_vflag || !mti->decoder) + goto tcheck_remainder; + + mti->decoder(ndo, cp, len); + return; + +invalid: + nd_print_invalid(ndo); +tcheck_remainder: + ND_TCHECK_LEN(cp, len); } /* Print a TCP segment worth of OpenFlow messages presuming the segment begins @@ -84,23 +149,45 @@ openflow_print(netdissect_options *ndo, const u_char *cp, u_int len) /* Print a single OpenFlow message. */ uint8_t version, type; uint16_t length; - uint32_t xid; + const struct of_msgtypeinfo *mti; - if (len < OF_HEADER_FIXLEN) - goto invalid; /* version */ version = GET_U_1(cp); OF_FWD(1); + ND_PRINT("\n\tversion %s", + tok2str(ofver_str, "unknown (0x%02x)", version)); /* type */ + if (len < 1) + goto partial_header; type = GET_U_1(cp); OF_FWD(1); + mti = + version == OF_VER_1_0 ? of10_identify_msgtype(type) : + version == OF_VER_1_3 ? of13_identify_msgtype(type) : + NULL; + if (mti && mti->name) + ND_PRINT(", type %s", mti->name); + else + ND_PRINT(", type unknown (0x%02x)", type); /* length */ + if (len < 2) + goto partial_header; length = GET_BE_U_2(cp); OF_FWD(2); + ND_PRINT(", length %u%s", length, + length < OF_HEADER_FIXLEN ? " (too short!)" : ""); /* xid */ - xid = GET_BE_U_4(cp); + if (len < 4) + goto partial_header; + ND_PRINT(", xid 0x%08x", GET_BE_U_4(cp)); OF_FWD(4); + /* + * When a TCP packet can contain several protocol messages, + * and at the same time a protocol message can span several + * TCP packets, decoding an incomplete message at the end of + * a TCP packet requires attention to detail in this loop. + * * Message length includes the header length and a message * always includes the basic header. A message length underrun * fails decoding of the rest of the current packet. At the @@ -108,37 +195,34 @@ openflow_print(netdissect_options *ndo, const u_char *cp, u_int len) * possible even when it does not end within the current TCP * segment. * - * That is, do NOT require the header "length" to be small + * Specifically, to try to process the message body in this + * iteration do NOT require the header "length" to be small * enough for the full declared OpenFlow message to fit into * the remainder of the declared TCP segment, same as the full * declared TCP segment is not required to fit into the * captured packet buffer. + * + * But DO require the same at the end of this iteration to + * decrement "len" and to proceed to the next iteration. + * (Ideally the declared TCP payload end will be at or after + * the captured packet buffer end, but stay safe even when + * that's somehow not the case.) */ - if (length < OF_HEADER_FIXLEN) { - of_header_print(ndo, version, type, length, xid); + if (length < OF_HEADER_FIXLEN) goto invalid; - } - /* - * Decode known protocol versions further without printing the - * header (the type decoding is version-specific). - */ - switch (version) { - case OF_VER_1_0: - of10_header_body_print(ndo, cp, type, - length - OF_HEADER_FIXLEN, xid); + + of_message_print(ndo, cp, length - OF_HEADER_FIXLEN, mti); + if (length - OF_HEADER_FIXLEN > len) break; - default: - of_header_print(ndo, version, type, length, xid); - ND_TCHECK_LEN(cp, length - OF_HEADER_FIXLEN); - } OF_FWD(length - OF_HEADER_FIXLEN); } /* while (len) */ return; +partial_header: + ND_PRINT(" (end of TCP payload)"); + ND_TCHECK_LEN(cp, len); + return; invalid: /* fail the current packet */ nd_print_invalid(ndo); ND_TCHECK_LEN(cp, len); - return; -trunc: - nd_trunc(ndo); }