aboutsummaryrefslogtreecommitdiffstats
path: root/wiretap/wtap.c
blob: e002d18e012466e2bdc2e69e26316c0ba266ad19 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
/* wtap.c
 *
 * $Id: wtap.c,v 1.7 1999/03/01 18:57:07 gram Exp $
 *
 * Wiretap Library
 * Copyright (c) 1998 by Gilbert Ramirez <gram@verdict.uthscsa.edu>
 * 
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License
 * as published by the Free Software Foundation; either version 2
 * of the License, or (at your option) any later version.
 * 
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 * 
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.
 *
 */

#include "wtap.h"
#include "buffer.h"
#include "bpf-engine.h"
#include "rt-compile.h"

FILE* wtap_file(wtap *wth)
{
	return wth->fh;
}

int wtap_file_type(wtap *wth)
{
	return wth->file_type;
}


int wtap_snapshot_length(wtap *wth)
{
	return wth->snapshot_length;
}

void wtap_close(wtap *wth)
{
	/* free up memory. If any capture structure ever allocates
	 * its own memory, it would be better to make a *close() function
	 * for each filetype, like pcap_close(0, lanalyzer_close(), etc.
	 * But for now this will work. */
	switch(wth->file_type) {
		case WTAP_FILE_PCAP:
			g_free(wth->capture.pcap);
			break;

		case WTAP_FILE_LANALYZER:
			g_free(wth->capture.lanalyzer);
			break;

		case WTAP_FILE_NGSNIFFER:
			g_free(wth->capture.ngsniffer);
			break;

		case WTAP_FILE_NETMON:
			g_free(wth->capture.netmon);
			break;

		/* default:
			 nothing */
	}

	fclose(wth->fh);
}

void wtap_loop(wtap *wth, int count, wtap_handler callback, u_char* user)
{
	int data_offset;
	int ret;
	int pkt_encap;

	while ((data_offset = wth->subtype_read(wth)) > 0) {
		/* offline filter? */
		if (wth->filter_type == WTAP_FILTER_OFFLINE) {
			pkt_encap = wth->phdr.pkt_encap;

			/* do we have a compiled filter for this
			 * encapsulation type? */
			if (!wth->filter.offline[pkt_encap])
				wtap_offline_filter_compile(wth, pkt_encap);

			/* run the filter */
			ret = bpf_run_filter(
					buffer_start_ptr(wth->frame_buffer),
					wth->phdr.caplen,
					wth->filter.offline[pkt_encap],
					wth->offline_filter_lengths[pkt_encap]
					);
			
			/* if the packet made it through the filter,
			 * send the data to the user */
			if (ret > 0)
				callback(user, &wth->phdr, data_offset,
				    buffer_start_ptr(wth->frame_buffer));
		}
		else
			callback(user, &wth->phdr, data_offset,
			    buffer_start_ptr(wth->frame_buffer));
	}
}