X-Git-Url: https://git.tcpdump.org/tcpdump/blobdiff_plain/d29f3dab95d8b28a62848fcb043b8ba40348bc3d..2d02497b02b040bd885825dba9230f86a8ffce0e:/print-zeromq.c diff --git a/print-zeromq.c b/print-zeromq.c index b2cf6db4..a23d98a1 100644 --- a/print-zeromq.c +++ b/print-zeromq.c @@ -1,7 +1,4 @@ /* - * This file implements decoding of ZeroMQ network protocol(s). - * - * * Copyright (c) 2013 The TCPDUMP project * All rights reserved. * @@ -28,11 +25,13 @@ * POSSIBILITY OF SUCH DAMAGE. */ +/* \summary: ZeroMQ Message Transport Protocol (ZMTP) printer */ + #ifdef HAVE_CONFIG_H #include "config.h" #endif -#include +#include #include "netdissect.h" #include "extract.h" @@ -75,9 +74,10 @@ static const char tstr[] = " [|zmtp1]"; */ static const u_char * -zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) { - u_int64_t body_len_declared, body_len_captured, header_len; - u_int8_t flags; +zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) +{ + uint64_t body_len_declared, body_len_captured, header_len; + uint8_t flags; ND_PRINT((ndo, "\n\t")); ND_TCHECK2(*cp, 1); /* length/0xFF */ @@ -85,22 +85,18 @@ zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) { if (cp[0] != 0xFF) { header_len = 1; /* length */ body_len_declared = cp[0]; - if (body_len_declared == 0) - return cp + header_len; /* skip to next frame */ - ND_PRINT((ndo, " frame flags+body (8-bit) length %u", cp[0])); - ND_TCHECK2(*cp, header_len + 1); /* length, flags */ - flags = cp[1]; + ND_PRINT((ndo, " frame flags+body (8-bit) length %" PRIu64, body_len_declared)); } else { header_len = 1 + 8; /* 0xFF, length */ ND_PRINT((ndo, " frame flags+body (64-bit) length")); ND_TCHECK2(*cp, header_len); /* 0xFF, length */ body_len_declared = EXTRACT_64BITS(cp + 1); - if (body_len_declared == 0) - return cp + header_len; /* skip to next frame */ ND_PRINT((ndo, " %" PRIu64, body_len_declared)); - ND_TCHECK2(*cp, header_len + 1); /* 0xFF, length, flags */ - flags = cp[9]; } + if (body_len_declared == 0) + return cp + header_len; /* skip to the next frame */ + ND_TCHECK2(*cp, header_len + 1); /* ..., flags */ + flags = cp[header_len]; body_len_captured = ep - cp - header_len; if (body_len_declared > body_len_captured) @@ -108,7 +104,7 @@ zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) { ND_PRINT((ndo, ", flags 0x%02x", flags)); if (ndo->ndo_vflag) { - u_int64_t body_len_printed = MIN(body_len_captured, body_len_declared); + uint64_t body_len_printed = min(body_len_captured, body_len_declared); ND_PRINT((ndo, " (%s|%s|%s|%s|%s|%s|%s|%s)", flags & 0x80 ? "MBZ" : "-", @@ -121,7 +117,7 @@ zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) { flags & 0x01 ? "MORE" : "-")); if (ndo->ndo_vflag == 1) - body_len_printed = MIN(VBYTES + 1, body_len_printed); + body_len_printed = min(VBYTES + 1, body_len_printed); if (body_len_printed > 1) { ND_PRINT((ndo, ", first %" PRIu64 " byte(s) of body:", body_len_printed - 1)); hex_and_ascii_print(ndo, "\n\t ", cp + header_len + 1, body_len_printed - 1); @@ -129,8 +125,15 @@ zmtp1_print_frame(netdissect_options *ndo, const u_char *cp, const u_char *ep) { } } - ND_TCHECK2(*cp, header_len + body_len_declared); /* Next frame within the buffer ? */ - return cp + header_len + body_len_declared; + /* + * Do not advance cp by the sum of header_len and body_len_declared + * before each offset has successfully passed ND_TCHECK2() as the + * sum can roll over (9 + 0xfffffffffffffff7 = 0) and cause an + * infinite loop. + */ + cp += header_len; + ND_TCHECK2(*cp, body_len_declared); /* Next frame within the buffer ? */ + return cp + body_len_declared; trunc: ND_PRINT((ndo, "%s", tstr)); @@ -138,8 +141,9 @@ trunc: } void -zmtp1_print(netdissect_options *ndo, const u_char *cp, u_int len) { - const u_char *ep = MIN(ndo->ndo_snapend, cp + len); +zmtp1_print(netdissect_options *ndo, const u_char *cp, u_int len) +{ + const u_char *ep = min(ndo->ndo_snapend, cp + len); ND_PRINT((ndo, ": ZMTP/1.0")); while (cp < ep) @@ -163,9 +167,10 @@ zmtp1_print(netdissect_options *ndo, const u_char *cp, u_int len) { */ static const u_char * -zmtp1_print_intermediate_part(netdissect_options *ndo, const u_char *cp, const u_int len) { +zmtp1_print_intermediate_part(netdissect_options *ndo, const u_char *cp, const u_int len) +{ u_int frame_offset; - u_int64_t remaining_len; + uint64_t remaining_len; ND_TCHECK2(*cp, 2); frame_offset = EXTRACT_16BITS(cp); @@ -186,10 +191,10 @@ zmtp1_print_intermediate_part(netdissect_options *ndo, const u_char *cp, const u if (frame_offset > remaining_len) ND_PRINT((ndo, " (%"PRIu64" captured)", remaining_len)); if (ndo->ndo_vflag) { - u_int64_t len_printed = MIN(frame_offset, remaining_len); + uint64_t len_printed = min(frame_offset, remaining_len); if (ndo->ndo_vflag == 1) - len_printed = MIN(VBYTES, len_printed); + len_printed = min(VBYTES, len_printed); if (len_printed > 1) { ND_PRINT((ndo, ", first %"PRIu64" byte(s):", len_printed)); hex_and_ascii_print(ndo, "\n\t ", cp, len_printed); @@ -205,8 +210,9 @@ trunc: } void -zmtp1_print_datagram(netdissect_options *ndo, const u_char *cp, const u_int len) { - const u_char *ep = MIN(ndo->ndo_snapend, cp + len); +zmtp1_print_datagram(netdissect_options *ndo, const u_char *cp, const u_int len) +{ + const u_char *ep = min(ndo->ndo_snapend, cp + len); cp = zmtp1_print_intermediate_part(ndo, cp, len); while (cp < ep)