1 /* capture-pcap-util-unix.c
2 * UN*X-specific utility routines for packet capture
6 * Wireshark - Network traffic analyzer
7 * By Gerald Combs <gerald@wireshark.org>
8 * Copyright 1998 Gerald Combs
10 * This program is free software; you can redistribute it and/or
11 * modify it under the terms of the GNU General Public License
12 * as published by the Free Software Foundation; either version 2
13 * of the License, or (at your option) any later version.
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 * GNU General Public License for more details.
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
42 #ifdef HAVE_SYS_SOCKET_H
43 #include <sys/socket.h>
46 #ifdef HAVE_SYS_IOCTL_H
47 #include <sys/ioctl.h>
53 * Keep Digital UNIX happy when including <net/if.h>.
59 #ifdef HAVE_SYS_SOCKIO_H
60 # include <sys/sockio.h>
63 #include "capture-pcap-util.h"
64 #include "capture-pcap-util-int.h"
66 #ifndef HAVE_PCAP_FINDALLDEVS
67 struct search_user_data {
73 search_for_if_cb(gpointer data, gpointer user_data);
76 #ifdef HAVE_PCAP_REMOTE
78 get_remote_interface_list(const char *hostname, const char *port,
79 int auth_type, const char *username,
80 const char *passwd, int *err, char **err_str)
82 struct pcap_rmtauth auth;
83 char source[PCAP_BUF_SIZE];
84 char errbuf[PCAP_ERRBUF_SIZE];
86 auth.type = auth_type;
87 auth.username = username;
88 auth.password = passwd;
90 if (pcap_createsrcstr(source, PCAP_SRC_IFREMOTE, hostname, port,
91 NULL, errbuf) == -1) {
92 *err = CANT_GET_INTERFACE_LIST;
94 *err_str = cant_get_if_list_error_message(errbuf);
97 return get_interface_list_findalldevs_ex(source, &auth, err, err_str);
102 get_interface_list(int *err, char **err_str)
104 #ifdef HAVE_PCAP_FINDALLDEVS
105 #ifdef HAVE_PCAP_REMOTE
106 char source[PCAP_BUF_SIZE];
107 char errbuf[PCAP_ERRBUF_SIZE];
109 if (pcap_createsrcstr(source, PCAP_SRC_IFLOCAL,
110 NULL, NULL, NULL, errbuf) == -1) {
111 *err = CANT_GET_INTERFACE_LIST;
113 *err_str = cant_get_if_list_error_message(errbuf);
116 return get_interface_list_findalldevs_ex(source, NULL, err, err_str);
118 return get_interface_list_findalldevs(err, err_str);
122 gint nonloopback_pos = 0;
123 struct ifreq *ifr, *last;
125 struct ifreq ifrflags;
126 int sock = socket(AF_INET, SOCK_DGRAM, 0);
127 struct search_user_data user_data;
132 char errbuf[PCAP_ERRBUF_SIZE];
135 *err = CANT_GET_INTERFACE_LIST;
136 if (err_str != NULL) {
137 *err_str = g_strdup_printf(
138 "Can't get list of interfaces: error opening socket: %s",
145 * This code came from: W. Richard Stevens: "UNIX Network Programming",
146 * Networking APIs: Sockets and XTI, Vol 1, page 434.
149 len = 100 * sizeof(struct ifreq);
154 memset (buf, 0, len);
155 if (ioctl(sock, SIOCGIFCONF, &ifc) < 0) {
156 if (errno != EINVAL || lastlen != 0) {
157 if (err_str != NULL) {
158 *err_str = g_strdup_printf(
159 "Can't get list of interfaces: SIOCGIFCONF ioctl error: %s",
165 if ((unsigned) ifc.ifc_len < sizeof(struct ifreq)) {
166 if (err_str != NULL) {
168 "Can't get list of interfaces: SIOCGIFCONF ioctl gave too small return buffer");
172 if (ifc.ifc_len == lastlen)
173 break; /* success, len has not changed */
174 lastlen = ifc.ifc_len;
176 len += 10 * sizeof(struct ifreq); /* increment */
179 ifr = (struct ifreq *) ifc.ifc_req;
180 last = (struct ifreq *) ((char *) ifr + ifc.ifc_len);
183 * Skip entries that begin with "dummy", or that include
184 * a ":" (the latter are Solaris virtuals).
186 if (strncmp(ifr->ifr_name, "dummy", 5) == 0 ||
187 strchr(ifr->ifr_name, ':') != NULL)
191 * If we already have this interface name on the list,
192 * don't add it, but, if we don't already have an IP
193 * address for it, add that address (SIOCGIFCONF returns,
194 * at least on BSD-flavored systems, one entry per
195 * interface *address*; if an interface has multiple
196 * addresses, we get multiple entries for it).
198 user_data.name = ifr->ifr_name;
199 user_data.if_info = NULL;
200 g_list_foreach(il, search_for_if_cb, &user_data);
201 if (user_data.if_info != NULL) {
202 if_info_add_address(user_data.if_info, &ifr->ifr_addr);
207 * Get the interface flags.
209 memset(&ifrflags, 0, sizeof ifrflags);
210 strncpy(ifrflags.ifr_name, ifr->ifr_name,
211 sizeof ifrflags.ifr_name);
212 if (ioctl(sock, SIOCGIFFLAGS, (char *)&ifrflags) < 0) {
215 if (err_str != NULL) {
216 *err_str = g_strdup_printf(
217 "Can't get list of interfaces: SIOCGIFFLAGS error getting flags for interface %s: %s",
218 ifr->ifr_name, strerror(errno));
224 * Skip interfaces that aren't up.
226 if (!(ifrflags.ifr_flags & IFF_UP))
230 * Skip interfaces that we can't open with "libpcap".
231 * Open with the minimum packet size - it appears that the
232 * IRIX SIOCSNOOPLEN "ioctl" may fail if the capture length
233 * supplied is too large, rather than just truncating it.
235 pch = pcap_open_live(ifr->ifr_name, MIN_PACKET_SIZE, 0, 0,
242 * If it's a loopback interface, add it at the end of the
243 * list, otherwise add it after the last non-loopback
244 * interface, so all loopback interfaces go at the end - we
245 * don't want a loopback interface to be the default capture
246 * device unless there are no non-loopback devices.
248 if_info = if_info_new(ifr->ifr_name, NULL);
249 if_info_add_address(if_info, &ifr->ifr_addr);
250 if ((ifrflags.ifr_flags & IFF_LOOPBACK) ||
251 strncmp(ifr->ifr_name, "lo", 2) == 0) {
252 if_info->loopback = TRUE;
253 il = g_list_append(il, if_info);
255 if_info->loopback = FALSE;
256 il = g_list_insert(il, if_info, nonloopback_pos);
258 * Insert the next non-loopback interface after this
266 ifr = (struct ifreq *) ((char *) ifr +
267 (ifr->ifr_addr.sa_len > sizeof(ifr->ifr_addr) ?
268 ifr->ifr_addr.sa_len : sizeof(ifr->ifr_addr)) +
271 ifr = (struct ifreq *) ((char *) ifr + sizeof(struct ifreq));
277 * OK, maybe we have support for the "any" device, to do a cooked
278 * capture on all interfaces at once.
279 * Try opening it and, if that succeeds, add it to the end of
280 * the list of interfaces.
282 pch = pcap_open_live("any", MIN_PACKET_SIZE, 0, 0, errbuf);
285 * It worked; we can use the "any" device.
287 if_info = if_info_new("any",
288 "Pseudo-device that captures on all interfaces");
289 il = g_list_insert(il, if_info, -1);
299 * No interfaces found.
301 *err = NO_INTERFACES_FOUND;
309 free_interface_list(il);
312 *err = CANT_GET_INTERFACE_LIST;
314 #endif /* HAVE_PCAP_FINDALLDEVS */
317 #ifndef HAVE_PCAP_FINDALLDEVS
319 search_for_if_cb(gpointer data, gpointer user_data)
321 struct search_user_data *search_user_data = user_data;
322 if_info_t *if_info = data;
324 if (strcmp(if_info->name, search_user_data->name) == 0)
325 search_user_data->if_info = if_info;
327 #endif /* HAVE_PCAP_FINDALLDEVS */
330 * Get an error message string for a CANT_GET_INTERFACE_LIST error from
331 * "get_interface_list()".
334 cant_get_if_list_error_message(const char *err_str)
336 return g_strdup_printf("Can't get list of interfaces: %s", err_str);
340 * Append the version of libpcap with which we were compiled to a GString.
343 get_compiled_pcap_version(GString *str)
345 #ifdef HAVE_PCAP_VERSION
346 extern char pcap_version[];
348 g_string_append_printf(str, "with libpcap %s", pcap_version);
350 g_string_append(str, "with libpcap (version unknown)");
355 * Append the version of libpcap with which we we're running to a GString.
358 get_runtime_pcap_version(GString *str)
360 g_string_append_printf(str, "with ");
361 #ifdef HAVE_PCAP_LIB_VERSION
362 g_string_sprintfa(str, pcap_lib_version());
364 g_string_append(str, "libpcap (version unknown)");
368 #else /* HAVE_LIBPCAP */
371 * Append an indication that we were not compiled with libpcap
375 get_compiled_pcap_version(GString *str)
377 g_string_append(str, "without libpcap");
381 * Don't append anything, as we weren't even compiled to use WinPcap.
384 get_runtime_pcap_version(GString *str _U_)
388 #endif /* HAVE_LIBPCAP */