1
##################################################
2
# Samba4 NDR parser generator for IDL structures
3
# Copyright tridge@samba.org 2000-2003
4
# Copyright tpot@samba.org 2001,2005
5
# Copyright jelmer@samba.org 2004-2007
6
# Portions based on idl2eth.c by Ronnie Sahlberg
7
# released under the GNU GPL
13
Parse::Pidl::Wireshark::NDR - Parser generator for Wireshark
17
package Parse::Pidl::Wireshark::NDR;
21
@EXPORT_OK = qw(field2name %res PrintIdl StripPrefixes RegisterInterfaceHandoff register_hf_field CheckUsed ProcessImport ProcessInclude find_type DumpEttList DumpEttDeclaration DumpHfList DumpHfDeclaration DumpFunctionTable register_type register_ett);
24
use Parse::Pidl qw(error warning);
25
use Parse::Pidl::Typelist qw(getType);
26
use Parse::Pidl::Util qw(has_property property_matches make_str);
27
use Parse::Pidl::NDR qw(ContainsString GetNextLevel);
28
use Parse::Pidl::Dump qw(DumpType DumpFunction);
29
use Parse::Pidl::Wireshark::Conformance qw(ReadConformance);
32
use vars qw($VERSION);
35
my %return_types = ();
36
my %dissector_used = ();
38
my %ptrtype_mappings = (
39
"unique" => "NDR_POINTER_UNIQUE",
40
"ref" => "NDR_POINTER_REF",
41
"ptr" => "NDR_POINTER_PTR"
46
my ($s, $prefixes) = @_;
48
foreach (@$prefixes) {
55
# Convert a IDL structure field name (e.g access_mask) to a prettier
56
# string like 'Access Mask'.
62
$field =~ s/_/ /g; # Replace underscores with spaces
63
$field =~ s/(\w+)/\u\L$1/g; # Capitalise each word
71
my $self = {res => {hdr => "", def => "", code => ""}, tabs => "", cur_fn => undef,
72
hf_used => {}, ett => [], conformance => undef
81
$self->{cur_fn} = $fn;
86
die("Inconsistent state: $fn != $self->{cur_fn}") if ($fn ne $self->{cur_fn});
87
$self->{cur_fn} = undef;
93
return if (defined($self->{cur_fn}) and defined($self->{conformance}->{manual}->{$self->{cur_fn}}));
96
$self->{res}->{code} .= $self->{tabs};
97
$self->{res}->{code} .= $d;
99
$self->{res}->{code} .="\n";
102
sub pidl_hdr($$) { my ($self,$x) = @_; $self->{res}->{hdr} .= "$x\n"; }
103
sub pidl_def($$) { my ($self,$x) = @_; $self->{res}->{def} .= "$x\n"; }
108
$self->{tabs} .= "\t";
114
$self->{tabs} = substr($self->{tabs}, 0, -1);
119
my ($self, $idl) = @_;
121
foreach (split /\n/, $idl) {
122
$self->pidl_code("/* IDL: $_ */");
125
$self->pidl_code("");
128
#####################################################################
129
# parse the interface definitions
132
my($self, $interface) = @_;
133
$self->Const($_,$interface->{NAME}) foreach (@{$interface->{CONSTS}});
134
$self->Type($_, $_->{NAME}, $interface->{NAME}) foreach (@{$interface->{TYPES}});
135
$self->Function($_,$interface->{NAME}) foreach (@{$interface->{FUNCTIONS}});
140
my ($self, $e,$name,$ifname) = @_;
141
my $valsstring = "$ifname\_$name\_vals";
142
my $dissectorname = "$ifname\_dissect\_enum\_".StripPrefixes($name, $self->{conformance}->{strip_prefixes});
144
return if (defined($self->{conformance}->{noemit}->{StripPrefixes($name, $self->{conformance}->{strip_prefixes})}));
146
foreach (@{$e->{ELEMENTS}}) {
147
if (/([^=]*)=(.*)/) {
148
$self->pidl_hdr("#define $1 ($2)");
152
$self->pidl_hdr("extern const value_string $valsstring\[];");
153
$self->pidl_hdr("int $dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 *param _U_);");
155
$self->pidl_def("const value_string ".$valsstring."[] = {");
156
foreach (@{$e->{ELEMENTS}}) {
157
next unless (/([^=]*)=(.*)/);
158
$self->pidl_def("\t{ $1, \"$1\" },");
161
$self->pidl_def("{ 0, NULL }");
162
$self->pidl_def("};");
164
$self->pidl_fn_start($dissectorname);
165
$self->pidl_code("int");
166
$self->pidl_code("$dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 *param _U_)");
167
$self->pidl_code("{");
169
$self->pidl_code("g$e->{BASE_TYPE} parameter=0;");
170
$self->pidl_code("if(param){");
172
$self->pidl_code("parameter=(g$e->{BASE_TYPE})*param;");
174
$self->pidl_code("}");
175
$self->pidl_code("offset = dissect_ndr_$e->{BASE_TYPE}(tvb, offset, pinfo, tree, drep, hf_index, ¶meter);");
176
$self->pidl_code("if(param){");
178
$self->pidl_code("*param=(guint32)parameter;");
180
$self->pidl_code("}");
181
$self->pidl_code("return offset;");
183
$self->pidl_code("}\n");
184
$self->pidl_fn_end($dissectorname);
186
my $enum_size = $e->{BASE_TYPE};
187
$enum_size =~ s/uint//g;
188
$self->register_type($name, "offset = $dissectorname(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);", "FT_UINT$enum_size", "BASE_DEC", "0", "VALS($valsstring)", $enum_size / 8);
193
my ($self,$e,$name,$ifname) = @_;
194
my $dissectorname = "$ifname\_dissect\_bitmap\_".StripPrefixes($name, $self->{conformance}->{strip_prefixes});
196
$self->register_ett("ett_$ifname\_$name");
198
$self->pidl_hdr("int $dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 param _U_);");
200
$self->pidl_fn_start($dissectorname);
201
$self->pidl_code("int");
202
$self->pidl_code("$dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 param _U_)");
203
$self->pidl_code("{");
205
$self->pidl_code("proto_item *item = NULL;");
206
$self->pidl_code("proto_tree *tree = NULL;");
207
$self->pidl_code("");
209
$self->pidl_code("g$e->{BASE_TYPE} flags;");
210
if ($e->{ALIGN} > 1) {
211
$self->pidl_code("ALIGN_TO_$e->{ALIGN}_BYTES;");
214
$self->pidl_code("");
216
$self->pidl_code("if (parent_tree) {");
218
$self->pidl_code("item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, $e->{ALIGN}, TRUE);");
219
$self->pidl_code("tree = proto_item_add_subtree(item,ett_$ifname\_$name);");
221
$self->pidl_code("}\n");
223
$self->pidl_code("offset = dissect_ndr_$e->{BASE_TYPE}(tvb, offset, pinfo, NULL, drep, -1, &flags);");
225
$self->pidl_code("proto_item_append_text(item, \": \");\n");
226
$self->pidl_code("if (!flags)");
227
$self->pidl_code("\tproto_item_append_text(item, \"(No values set)\");\n");
229
foreach (@{$e->{ELEMENTS}}) {
230
next unless (/([^ ]*) (.*)/);
231
my ($en,$ev) = ($1,$2);
232
my $hf_bitname = "hf_$ifname\_$name\_$en";
233
my $filtername = "$ifname\.$name\.$en";
235
$self->{hf_used}->{$hf_bitname} = 1;
237
$self->register_hf_field($hf_bitname, field2name($en), $filtername, "FT_BOOLEAN", $e->{ALIGN} * 8, "TFS(&$name\_$en\_tfs)", $ev, "");
239
$self->pidl_def("static const true_false_string $name\_$en\_tfs = {");
240
if (defined($self->{conformance}->{tfs}->{$hf_bitname})) {
241
$self->pidl_def(" $self->{conformance}->{tfs}->{$hf_bitname}->{TRUE_STRING},");
242
$self->pidl_def(" $self->{conformance}->{tfs}->{$hf_bitname}->{FALSE_STRING},");
243
$self->{conformance}->{tfs}->{$hf_bitname}->{USED} = 1;
245
$self->pidl_def(" \"$en is SET\",");
246
$self->pidl_def(" \"$en is NOT SET\",");
248
$self->pidl_def("};");
250
$self->pidl_code("proto_tree_add_boolean(tree, $hf_bitname, tvb, offset-$e->{ALIGN}, $e->{ALIGN}, flags);");
251
$self->pidl_code("if (flags&$ev){");
252
$self->pidl_code("\tproto_item_append_text(item, \"$en\");");
253
$self->pidl_code("\tif (flags & (~$ev))");
254
$self->pidl_code("\t\tproto_item_append_text(item, \", \");");
255
$self->pidl_code("}");
256
$self->pidl_code("flags&=(~$ev);");
257
$self->pidl_code("");
260
$self->pidl_code("if (flags) {");
261
$self->pidl_code("\tproto_item_append_text(item, \"Unknown bitmap value 0x%x\", flags);");
262
$self->pidl_code("}\n");
263
$self->pidl_code("return offset;");
265
$self->pidl_code("}\n");
266
$self->pidl_fn_end($dissectorname);
268
my $size = $e->{BASE_TYPE};
270
$self->register_type($name, "offset = $dissectorname(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);", "FT_UINT$size", "BASE_HEX", "0", "NULL", $size/8);
273
sub ElementLevel($$$$$$$)
275
my ($self,$e,$l,$hf,$myname,$pn,$ifname) = @_;
279
if (defined($self->{conformance}->{dissectorparams}->{$myname})) {
280
$param = $self->{conformance}->{dissectorparams}->{$myname}->{PARAM};
283
if ($l->{TYPE} eq "POINTER") {
285
if ($l->{LEVEL} eq "TOP") {
287
} elsif ($l->{LEVEL} eq "EMBEDDED") {
290
$self->pidl_code("offset = dissect_ndr_$type\_pointer(tvb, offset, pinfo, tree, drep, $myname\_, $ptrtype_mappings{$l->{POINTER_TYPE}}, \"Pointer to ".field2name(StripPrefixes($e->{NAME}, $self->{conformance}->{strip_prefixes})) . " ($e->{TYPE})\",$hf);");
291
} elsif ($l->{TYPE} eq "ARRAY") {
292
if ($l->{IS_INLINE}) {
293
error($e->{ORIGINAL}, "Inline arrays not supported");
294
} elsif ($l->{IS_FIXED}) {
295
$self->pidl_code("int i;");
296
$self->pidl_code("for (i = 0; i < $l->{SIZE_IS}; i++)");
297
$self->pidl_code("\toffset = $myname\_(tvb, offset, pinfo, tree, drep);");
300
$type .= "c" if ($l->{IS_CONFORMANT});
301
$type .= "v" if ($l->{IS_VARYING});
303
unless ($l->{IS_ZERO_TERMINATED}) {
304
$self->pidl_code("offset = dissect_ndr_u" . $type . "array(tvb, offset, pinfo, tree, drep, $myname\_);");
306
my $nl = GetNextLevel($e,$l);
307
$self->pidl_code("char *data;");
308
$self->pidl_code("");
309
$self->pidl_code("offset = dissect_ndr_$type" . "string(tvb, offset, pinfo, tree, drep, sizeof(g$nl->{DATA_TYPE}), $hf, FALSE, &data);");
310
$self->pidl_code("proto_item_append_text(tree, \": %s\", data);");
313
} elsif ($l->{TYPE} eq "DATA") {
314
if ($l->{DATA_TYPE} eq "string") {
315
my $bs = 2; # Byte size defaults to that of UCS2
318
($bs = 1) if (property_matches($e, "flag", ".*LIBNDR_FLAG_STR_ASCII.*"));
320
if (property_matches($e, "flag", ".*LIBNDR_FLAG_STR_SIZE4.*") and property_matches($e, "flag", ".*LIBNDR_FLAG_STR_LEN4.*")) {
321
$self->pidl_code("char *data;\n");
322
$self->pidl_code("offset = dissect_ndr_cvstring(tvb, offset, pinfo, tree, drep, $bs, $hf, FALSE, &data);");
323
$self->pidl_code("proto_item_append_text(tree, \": %s\", data);");
324
} elsif (property_matches($e, "flag", ".*LIBNDR_FLAG_STR_SIZE4.*")) {
325
$self->pidl_code("offset = dissect_ndr_vstring(tvb, offset, pinfo, tree, drep, $bs, $hf, FALSE, NULL);");
327
warn("Unable to handle string with flags $e->{PROPERTIES}->{flag}");
332
if ($self->{conformance}->{imports}->{$l->{DATA_TYPE}}) {
333
$call = $self->{conformance}->{imports}->{$l->{DATA_TYPE}}->{DATA};
334
$self->{conformance}->{imports}->{$l->{DATA_TYPE}}->{USED} = 1;
335
} elsif (defined($self->{conformance}->{imports}->{"$pn.$e->{NAME}"})) {
336
$call = $self->{conformance}->{imports}->{"$pn.$e->{NAME}"}->{DATA};
337
$self->{conformance}->{imports}->{"$pn.$e->{NAME}"}->{USED} = 1;
339
} elsif (defined($self->{conformance}->{types}->{$l->{DATA_TYPE}})) {
340
$call= $self->{conformance}->{types}->{$l->{DATA_TYPE}}->{DISSECTOR_NAME};
341
$self->{conformance}->{types}->{$l->{DATA_TYPE}}->{USED} = 1;
343
$self->pidl_code("offset = $ifname\_dissect_struct_" . $l->{DATA_TYPE} . "(tvb,offset,pinfo,tree,drep,$hf,$param);");
348
$call =~ s/\@HF\@/$hf/g;
349
$call =~ s/\@PARAM\@/$param/g;
350
$self->pidl_code($call);
352
} elsif ($_->{TYPE} eq "SUBCONTEXT") {
353
my $num_bits = ($l->{HEADER_SIZE}*8);
354
$self->pidl_code("guint$num_bits size;");
355
$self->pidl_code("int start_offset = offset;");
356
$self->pidl_code("tvbuff_t *subtvb;");
357
$self->pidl_code("offset = dissect_ndr_uint$num_bits(tvb, offset, pinfo, tree, drep, $hf, &size);");
358
$self->pidl_code("proto_tree_add_text(tree, tvb, start_offset, offset - start_offset + size, \"Subcontext size\");");
360
$self->pidl_code("subtvb = tvb_new_subset(tvb, offset, size, -1);");
361
$self->pidl_code("$myname\_(subtvb, 0, pinfo, tree, drep);");
363
die("Unknown type `$_->{TYPE}'");
369
my ($self,$e,$pn,$ifname) = @_;
371
my $dissectorname = "$ifname\_dissect\_element\_".StripPrefixes($pn, $self->{conformance}->{strip_prefixes})."\_".StripPrefixes($e->{NAME}, $self->{conformance}->{strip_prefixes});
373
my $call_code = "offset = $dissectorname(tvb, offset, pinfo, tree, drep);";
375
my $type = $self->find_type($e->{TYPE});
377
if (not defined($type)) {
381
VALSSTRING => "NULL",
382
FT_TYPE => "FT_NONE",
383
BASE_TYPE => "BASE_HEX"
387
if (ContainsString($e)) {
390
VALSSTRING => "NULL",
391
FT_TYPE => "FT_STRING",
392
BASE_TYPE => "BASE_DEC"
396
my $hf = $self->register_hf_field("hf_$ifname\_$pn\_$e->{NAME}", field2name($e->{NAME}), "$ifname.$pn.$e->{NAME}", $type->{FT_TYPE}, $type->{BASE_TYPE}, $type->{VALSSTRING}, $type->{MASK}, "");
397
$self->{hf_used}->{$hf} = 1;
399
my $eltname = StripPrefixes($pn, $self->{conformance}->{strip_prefixes}) . ".$e->{NAME}";
400
if (defined($self->{conformance}->{noemit}->{$eltname})) {
406
foreach (@{$e->{LEVELS}}) {
407
next if ($_->{TYPE} eq "SWITCH");
408
$self->pidl_def("static int $dissectorname$add(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_);");
409
$self->pidl_fn_start("$dissectorname$add");
410
$self->pidl_code("static int");
411
$self->pidl_code("$dissectorname$add(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_)");
412
$self->pidl_code("{");
415
$self->ElementLevel($e,$_,$hf,$dissectorname.$add,$pn,$ifname);
417
$self->pidl_code("");
418
$self->pidl_code("return offset;");
420
$self->pidl_code("}\n");
421
$self->pidl_fn_end("$dissectorname$add");
423
last if ($_->{TYPE} eq "ARRAY" and $_->{IS_ZERO_TERMINATED});
431
my ($self, $fn,$ifname) = @_;
435
foreach (@{$fn->{ELEMENTS}}) {
436
$dissectornames{$_->{NAME}} = $self->Element($_, $fn->{NAME}, $ifname) if not defined($dissectornames{$_->{NAME}});
439
my $fn_name = $_->{NAME};
440
$fn_name =~ s/^${ifname}_//;
442
$self->PrintIdl(DumpFunction($fn->{ORIGINAL}));
443
$self->pidl_fn_start("$ifname\_dissect\_$fn_name\_response");
444
$self->pidl_code("static int");
445
$self->pidl_code("$ifname\_dissect\_${fn_name}_response(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_)");
446
$self->pidl_code("{");
448
if ( not defined($fn->{RETURN_TYPE})) {
449
} elsif ($fn->{RETURN_TYPE} eq "NTSTATUS" or $fn->{RETURN_TYPE} eq "WERROR")
451
$self->pidl_code("guint32 status;\n");
452
} elsif (my $type = getType($fn->{RETURN_TYPE})) {
453
if ($type->{DATA}->{TYPE} eq "ENUM") {
454
$self->pidl_code("g".Parse::Pidl::Typelist::enum_type_fn($type->{DATA}) . " status;\n");
455
} elsif ($type->{DATA}->{TYPE} eq "SCALAR") {
456
$self->pidl_code("g$fn->{RETURN_TYPE} status;\n");
458
error($fn, "return type `$fn->{RETURN_TYPE}' not yet supported");
461
error($fn, "unknown return type `$fn->{RETURN_TYPE}'");
464
$self->pidl_code("pinfo->dcerpc_procedure_name=\"${fn_name}\";");
465
foreach (@{$fn->{ELEMENTS}}) {
466
if (grep(/out/,@{$_->{DIRECTION}})) {
467
$self->pidl_code("$dissectornames{$_->{NAME}}");
468
$self->pidl_code("offset = dissect_deferred_pointers(pinfo, tvb, offset, drep);");
469
$self->pidl_code("");
473
if (not defined($fn->{RETURN_TYPE})) {
474
} elsif ($fn->{RETURN_TYPE} eq "NTSTATUS") {
475
$self->pidl_code("offset = dissect_ntstatus(tvb, offset, pinfo, tree, drep, hf\_$ifname\_status, &status);\n");
476
$self->pidl_code("if (status != 0 && check_col(pinfo->cinfo, COL_INFO))");
477
$self->pidl_code("\tcol_append_fstr(pinfo->cinfo, COL_INFO, \", Error: %s\", val_to_str(status, NT_errors, \"Unknown NT status 0x%08x\"));\n");
478
$return_types{$ifname}->{"status"} = ["NTSTATUS", "NT Error"];
479
} elsif ($fn->{RETURN_TYPE} eq "WERROR") {
480
$self->pidl_code("offset = dissect_ndr_uint32(tvb, offset, pinfo, tree, drep, hf\_$ifname\_werror, &status);\n");
481
$self->pidl_code("if (status != 0 && check_col(pinfo->cinfo, COL_INFO))");
482
$self->pidl_code("\tcol_append_fstr(pinfo->cinfo, COL_INFO, \", Error: %s\", val_to_str(status, WERR_errors, \"Unknown DOS error 0x%08x\"));\n");
484
$return_types{$ifname}->{"werror"} = ["WERROR", "Windows Error"];
485
} elsif (my $type = getType($fn->{RETURN_TYPE})) {
486
if ($type->{DATA}->{TYPE} eq "ENUM") {
487
my $return_type = "g".Parse::Pidl::Typelist::enum_type_fn($type->{DATA});
488
my $return_dissect = "dissect_ndr_" .Parse::Pidl::Typelist::enum_type_fn($type->{DATA});
490
$self->pidl_code("offset = $return_dissect(tvb, offset, pinfo, tree, drep, hf\_$ifname\_$fn->{RETURN_TYPE}_status, &status);");
491
$self->pidl_code("if (status != 0 && check_col(pinfo->cinfo, COL_INFO))");
492
$self->pidl_code("\tcol_append_fstr(pinfo->cinfo, COL_INFO, \", Status: %s\", val_to_str(status, $ifname\_$fn->{RETURN_TYPE}\_vals, \"Unknown " . $fn->{RETURN_TYPE} . " error 0x%08x\"));\n");
493
$return_types{$ifname}->{$fn->{RETURN_TYPE}."_status"} = [$fn->{RETURN_TYPE}, $fn->{RETURN_TYPE}];
494
} elsif ($type->{DATA}->{TYPE} eq "SCALAR") {
495
$self->pidl_code("offset = dissect_ndr_$fn->{RETURN_TYPE}(tvb, offset, pinfo, tree, drep, hf\_$ifname\_$fn->{RETURN_TYPE}_status, &status);");
496
$self->pidl_code("if (status != 0 && check_col(pinfo->cinfo, COL_INFO))");
497
$self->pidl_code("\tcol_append_fstr(pinfo->cinfo, COL_INFO, \", Status: %d\", status);\n");
498
$return_types{$ifname}->{$fn->{RETURN_TYPE}."_status"} = [$fn->{RETURN_TYPE}, $fn->{RETURN_TYPE}];
502
$self->pidl_code("return offset;");
504
$self->pidl_code("}\n");
505
$self->pidl_fn_end("$ifname\_dissect\_$fn_name\_response");
507
$self->pidl_fn_start("$ifname\_dissect\_$fn_name\_request");
508
$self->pidl_code("static int");
509
$self->pidl_code("$ifname\_dissect\_${fn_name}_request(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *tree _U_, guint8 *drep _U_)");
510
$self->pidl_code("{");
512
$self->pidl_code("pinfo->dcerpc_procedure_name=\"${fn_name}\";");
513
foreach (@{$fn->{ELEMENTS}}) {
514
if (grep(/in/,@{$_->{DIRECTION}})) {
515
$self->pidl_code("$dissectornames{$_->{NAME}}");
516
$self->pidl_code("offset = dissect_deferred_pointers(pinfo, tvb, offset, drep);");
521
$self->pidl_code("return offset;");
523
$self->pidl_code("}\n");
524
$self->pidl_fn_end("$ifname\_dissect\_$fn_name\_request");
529
my ($self,$e,$name,$ifname) = @_;
530
my $dissectorname = "$ifname\_dissect\_struct\_".StripPrefixes($name, $self->{conformance}->{strip_prefixes});
532
return if (defined($self->{conformance}->{noemit}->{StripPrefixes($name, $self->{conformance}->{strip_prefixes})}));
534
$self->register_ett("ett_$ifname\_$name");
537
($res.="\t".$self->Element($_, $name, $ifname)."\n\n") foreach (@{$e->{ELEMENTS}});
539
$self->pidl_hdr("int $dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 param _U_);");
541
$self->pidl_fn_start($dissectorname);
542
$self->pidl_code("int");
543
$self->pidl_code("$dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 param _U_)");
544
$self->pidl_code("{");
546
$self->pidl_code("proto_item *item = NULL;");
547
$self->pidl_code("proto_tree *tree = NULL;");
548
$self->pidl_code("int old_offset;");
549
$self->pidl_code("");
551
if ($e->{ALIGN} > 1) {
552
$self->pidl_code("ALIGN_TO_$e->{ALIGN}_BYTES;");
554
$self->pidl_code("");
556
$self->pidl_code("old_offset = offset;");
557
$self->pidl_code("");
558
$self->pidl_code("if (parent_tree) {");
560
$self->pidl_code("item = proto_tree_add_item(parent_tree, hf_index, tvb, offset, -1, TRUE);");
561
$self->pidl_code("tree = proto_item_add_subtree(item, ett_$ifname\_$name);");
563
$self->pidl_code("}");
565
$self->pidl_code("\n$res");
567
$self->pidl_code("proto_item_set_len(item, offset-old_offset);\n");
568
$self->pidl_code("return offset;");
570
$self->pidl_code("}\n");
571
$self->pidl_fn_end($dissectorname);
573
$self->register_type($name, "offset = $dissectorname(tvb,offset,pinfo,tree,drep,\@HF\@,\@PARAM\@);", "FT_NONE", "BASE_NONE", 0, "NULL", 0);
578
my ($self,$e,$name,$ifname) = @_;
580
my $dissectorname = "$ifname\_dissect_".StripPrefixes($name, $self->{conformance}->{strip_prefixes});
582
return if (defined($self->{conformance}->{noemit}->{StripPrefixes($name, $self->{conformance}->{strip_prefixes})}));
584
$self->register_ett("ett_$ifname\_$name");
587
foreach (@{$e->{ELEMENTS}}) {
588
$res.="\n\t\t$_->{CASE}:\n";
589
if ($_->{TYPE} ne "EMPTY") {
590
$res.="\t\t\t".$self->Element($_, $name, $ifname)."\n";
592
$res.="\t\tbreak;\n";
597
my $switch_dt = getType($e->{SWITCH_TYPE});
598
if ($switch_dt->{DATA}->{TYPE} eq "ENUM") {
599
$switch_type = "g".Parse::Pidl::Typelist::enum_type_fn($switch_dt->{DATA});
600
$switch_dissect = "dissect_ndr_" .Parse::Pidl::Typelist::enum_type_fn($switch_dt->{DATA});
601
} elsif ($switch_dt->{DATA}->{TYPE} eq "SCALAR") {
602
$switch_type = "g$e->{SWITCH_TYPE}";
603
$switch_dissect = "dissect_ndr_$e->{SWITCH_TYPE}";
606
$self->pidl_fn_start($dissectorname);
607
$self->pidl_code("static int");
608
$self->pidl_code("$dissectorname(tvbuff_t *tvb _U_, int offset _U_, packet_info *pinfo _U_, proto_tree *parent_tree _U_, guint8 *drep _U_, int hf_index _U_, guint32 param _U_)");
609
$self->pidl_code("{");
611
$self->pidl_code("proto_item *item = NULL;");
612
$self->pidl_code("proto_tree *tree = NULL;");
613
$self->pidl_code("int old_offset;");
614
$self->pidl_code("$switch_type level;");
615
$self->pidl_code("");
617
$self->pidl_code("old_offset = offset;");
618
$self->pidl_code("if (parent_tree) {");
620
$self->pidl_code("item = proto_tree_add_text(parent_tree, tvb, offset, -1, \"$name\");");
621
$self->pidl_code("tree = proto_item_add_subtree(item, ett_$ifname\_$name);");
623
$self->pidl_code("}");
625
$self->pidl_code("");
627
$self->pidl_code("offset = $switch_dissect(tvb, offset, pinfo, tree, drep, hf_index, &level);");
629
if ($e->{ALIGN} > 1) {
630
$self->pidl_code("ALIGN_TO_$e->{ALIGN}_BYTES;");
631
$self->pidl_code("");
635
$self->pidl_code("switch(level) {$res\t}");
636
$self->pidl_code("proto_item_set_len(item, offset-old_offset);\n");
637
$self->pidl_code("return offset;");
639
$self->pidl_code("}");
640
$self->pidl_fn_end($dissectorname);
642
$self->register_type($name, "offset = $dissectorname(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);", "FT_NONE", "BASE_NONE", 0, "NULL", 0);
647
my ($self,$const,$ifname) = @_;
649
if (!defined($const->{ARRAY_LEN}[0])) {
650
$self->pidl_hdr("#define $const->{NAME}\t( $const->{VALUE} )\n");
652
$self->pidl_hdr("#define $const->{NAME}\t $const->{VALUE}\n");
658
my ($self,$e,$name,$ifname) = @_;
660
$self->Type($e->{DATA}, $name, $ifname);
665
my ($self, $e, $name, $ifname) = @_;
667
$self->PrintIdl(DumpType($e->{ORIGINAL}));
675
}->{$e->{TYPE}}->($self, $e, $name, $ifname);
678
sub RegisterInterface($$)
682
$self->pidl_fn_start("proto_register_dcerpc_$x->{NAME}");
683
$self->pidl_code("void proto_register_dcerpc_$x->{NAME}(void)");
684
$self->pidl_code("{");
687
$self->{res}->{code}.=$self->DumpHfList()."\n";
688
$self->{res}->{code}.="\n".DumpEttList($self->{ett})."\n";
690
if (defined($x->{UUID})) {
691
# These can be changed to non-pidl_code names if the old dissectors
692
# in epan/dissctors are deleted.
694
my $name = uc($x->{NAME}) . " (pidl)";
695
my $short_name = uc($x->{NAME});
696
my $filter_name = $x->{NAME};
698
if (has_property($x, "helpstring")) {
699
$name = $x->{PROPERTIES}->{helpstring};
702
if (defined($self->{conformance}->{protocols}->{$x->{NAME}})) {
703
$short_name = $self->{conformance}->{protocols}->{$x->{NAME}}->{SHORTNAME};
704
$name = $self->{conformance}->{protocols}->{$x->{NAME}}->{LONGNAME};
705
$filter_name = $self->{conformance}->{protocols}->{$x->{NAME}}->{FILTERNAME};
708
$self->pidl_code("proto_dcerpc_$x->{NAME} = proto_register_protocol(".make_str($name).", ".make_str($short_name).", ".make_str($filter_name).");");
710
$self->pidl_code("proto_register_field_array(proto_dcerpc_$x->{NAME}, hf, array_length (hf));");
711
$self->pidl_code("proto_register_subtree_array(ett, array_length(ett));");
713
$self->pidl_code("proto_dcerpc = proto_get_id_by_filter_name(\"dcerpc\");");
714
$self->pidl_code("proto_register_field_array(proto_dcerpc, hf, array_length(hf));");
715
$self->pidl_code("proto_register_subtree_array(ett, array_length(ett));");
719
$self->pidl_code("}\n");
720
$self->pidl_fn_end("proto_register_dcerpc_$x->{NAME}");
723
sub RegisterInterfaceHandoff($$)
727
if (defined($x->{UUID})) {
728
$self->pidl_fn_start("proto_reg_handoff_dcerpc_$x->{NAME}");
729
$self->pidl_code("void proto_reg_handoff_dcerpc_$x->{NAME}(void)");
730
$self->pidl_code("{");
732
$self->pidl_code("dcerpc_init_uuid(proto_dcerpc_$x->{NAME}, ett_dcerpc_$x->{NAME},");
733
$self->pidl_code("\t&uuid_dcerpc_$x->{NAME}, ver_dcerpc_$x->{NAME},");
734
$self->pidl_code("\t$x->{NAME}_dissectors, hf_$x->{NAME}_opnum);");
736
$self->pidl_code("}");
737
$self->pidl_fn_end("proto_reg_handoff_dcerpc_$x->{NAME}");
739
$self->{hf_used}->{"hf_$x->{NAME}_opnum"} = 1;
747
foreach (@includes) {
748
$self->pidl_hdr("#include \"$_\"");
758
next if($_ eq "security");
761
$self->pidl_hdr("#include \"packet-dcerpc-$_\.h\"");
766
sub ProcessInterface($$)
770
push(@{$self->{conformance}->{strip_prefixes}}, $x->{NAME});
772
my $define = "__PACKET_DCERPC_" . uc($_->{NAME}) . "_H";
773
$self->pidl_hdr("#ifndef $define");
774
$self->pidl_hdr("#define $define");
777
$self->pidl_def("static gint proto_dcerpc_$x->{NAME} = -1;");
778
$self->register_ett("ett_dcerpc_$x->{NAME}");
779
$self->register_hf_field("hf_$x->{NAME}_opnum", "Operation", "$x->{NAME}.opnum", "FT_UINT16", "BASE_DEC", "NULL", 0, "");
781
if (defined($x->{UUID})) {
782
my $if_uuid = $x->{UUID};
784
$self->pidl_def("/* Version information */\n\n");
786
$self->pidl_def("static e_uuid_t uuid_dcerpc_$x->{NAME} = {");
787
$self->pidl_def("\t0x" . substr($if_uuid, 1, 8)
788
. ", 0x" . substr($if_uuid, 10, 4)
789
. ", 0x" . substr($if_uuid, 15, 4) . ",");
790
$self->pidl_def("\t{ 0x" . substr($if_uuid, 20, 2)
791
. ", 0x" . substr($if_uuid, 22, 2)
792
. ", 0x" . substr($if_uuid, 25, 2)
793
. ", 0x" . substr($if_uuid, 27, 2)
794
. ", 0x" . substr($if_uuid, 29, 2)
795
. ", 0x" . substr($if_uuid, 31, 2)
796
. ", 0x" . substr($if_uuid, 33, 2)
797
. ", 0x" . substr($if_uuid, 35, 2) . " }");
798
$self->pidl_def("};");
800
my $maj = $x->{VERSION};
801
$maj =~ s/\.(.*)$//g;
802
$self->pidl_def("static guint16 ver_dcerpc_$x->{NAME} = $maj;");
806
$return_types{$x->{NAME}} = {};
808
$self->Interface($x);
810
$self->pidl_code("\n".DumpFunctionTable($x));
812
foreach (keys %{$return_types{$x->{NAME}}}) {
813
my ($type, $desc) = @{$return_types{$x->{NAME}}->{$_}};
814
my $dt = $self->find_type($type);
815
$dt or die("Unable to find information about return type `$type'");
816
$self->register_hf_field("hf_$x->{NAME}_$_", $desc, "$x->{NAME}.$_", $dt->{FT_TYPE}, "BASE_HEX", $dt->{VALSSTRING}, 0, "");
817
$self->{hf_used}->{"hf_$x->{NAME}_$_"} = 1;
820
$self->RegisterInterface($x);
821
$self->RegisterInterfaceHandoff($x);
823
$self->pidl_hdr("#endif /* $define */");
830
return $self->{conformance}->{types}->{$n};
833
sub register_type($$$$$$$$)
835
my ($self, $type,$call,$ft,$base,$mask,$vals,$length) = @_;
837
return if (defined($self->{conformance}->{types}->{$type}));
839
$self->{conformance}->{types}->{$type} = {
841
DISSECTOR_NAME => $call,
850
# Loads the default types
853
my ($self, $cnf_file) = @_;
855
$self->{conformance} = {
860
ReadConformance($cnf_file, $self->{conformance}) or print STDERR "warning: No conformance file `$cnf_file'\n";
862
foreach my $bytes (qw(1 2 4 8)) {
863
my $bits = $bytes * 8;
864
$self->register_type("uint$bits", "offset = PIDL_dissect_uint$bits(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);", "FT_UINT$bits", "BASE_DEC", 0, "NULL", $bytes);
865
$self->register_type("int$bits", "offset = PIDL_dissect_uint$bits(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);", "FT_INT$bits", "BASE_DEC", 0, "NULL", $bytes);
868
$self->register_type("udlong", "offset = dissect_ndr_duint32(tvb, offset, pinfo, tree, drep, \@HF\@, NULL);", "FT_UINT64", "BASE_DEC", 0, "NULL", 4);
869
$self->register_type("bool8", "offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_INT8", "BASE_DEC", 0, "NULL", 1);
870
$self->register_type("char", "offset = PIDL_dissect_uint8(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_INT8", "BASE_DEC", 0, "NULL", 1);
871
$self->register_type("long", "offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_INT32", "BASE_DEC", 0, "NULL", 4);
872
$self->register_type("dlong", "offset = dissect_ndr_duint32(tvb, offset, pinfo, tree, drep, \@HF\@, NULL);","FT_INT64", "BASE_DEC", 0, "NULL", 8);
873
$self->register_type("GUID", "offset = dissect_ndr_uuid_t(tvb, offset, pinfo, tree, drep, \@HF\@, NULL);","FT_GUID", "BASE_NONE", 0, "NULL", 4);
874
$self->register_type("policy_handle", "offset = PIDL_dissect_policy_hnd(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_BYTES", "BASE_NONE", 0, "NULL", 4);
875
$self->register_type("NTTIME", "offset = dissect_ndr_nt_NTTIME(tvb, offset, pinfo, tree, drep, \@HF\@);","FT_ABSOLUTE_TIME", "BASE_NONE", 0, "NULL", 4);
876
$self->register_type("NTTIME_hyper", "offset = dissect_ndr_nt_NTTIME(tvb, offset, pinfo, tree, drep, \@HF\@);","FT_ABSOLUTE_TIME", "BASE_NONE", 0, "NULL", 4);
877
$self->register_type("time_t", "offset = dissect_ndr_time_t(tvb, offset, pinfo,tree, drep, \@HF\@, NULL);","FT_ABSOLUTE_TIME", "BASE_DEC", 0, "NULL", 4);
878
$self->register_type("NTTIME_1sec", "offset = dissect_ndr_nt_NTTIME(tvb, offset, pinfo, tree, drep, \@HF\@);", "FT_ABSOLUTE_TIME", "BASE_NONE", 0, "NULL", 4);
879
$self->register_type("SID", "
880
dcerpc_info *di = (dcerpc_info *)pinfo->private_data;
882
di->hf_index = \@HF\@;
884
offset = dissect_ndr_nt_SID_with_options(tvb, offset, pinfo, tree, drep, param);
885
","FT_STRING", "BASE_DEC", 0, "NULL", 4);
886
$self->register_type("WERROR",
887
"offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_UINT32", "BASE_DEC", 0, "VALS(WERR_errors)", 4);
888
$self->register_type("NTSTATUS",
889
"offset = PIDL_dissect_uint32(tvb, offset, pinfo, tree, drep, \@HF\@, \@PARAM\@);","FT_UINT32", "BASE_DEC", 0, "VALS(NT_errors)", 4);
893
#####################################################################
894
# Generate Wireshark parser and header code
897
my($self,$ndr,$idl_file,$h_filename,$cnf_file) = @_;
899
$self->Initialize($cnf_file);
901
return (undef, undef) if defined($self->{conformance}->{noemit_dissector});
905
This filter was automatically generated
906
from $idl_file and $cnf_file.
908
Pidl is a perl based IDL compiler for DCE/RPC idl files.
909
It is maintained by the Samba team, not the Wireshark team.
910
Instructions on how to download and install Pidl can be
911
found at http://wiki.wireshark.org/Pidl
916
$self->pidl_hdr($notice);
918
$self->{res}->{headers} = "\n";
919
$self->{res}->{headers} .= "#ifdef HAVE_CONFIG_H\n";
920
$self->{res}->{headers} .= "#include \"config.h\"\n";
921
$self->{res}->{headers} .= "#endif\n\n";
923
$self->{res}->{headers} .= "#ifdef _MSC_VER\n";
924
$self->{res}->{headers} .= "#pragma warning(disable:4005)\n";
925
$self->{res}->{headers} .= "#pragma warning(disable:4013)\n";
926
$self->{res}->{headers} .= "#pragma warning(disable:4018)\n";
927
$self->{res}->{headers} .= "#pragma warning(disable:4101)\n";
928
$self->{res}->{headers} .= "#endif\n\n";
930
$self->{res}->{headers} .= "#include <glib.h>\n";
931
$self->{res}->{headers} .= "#include <string.h>\n";
932
$self->{res}->{headers} .= "#include <epan/packet.h>\n\n";
934
$self->{res}->{headers} .= "#include \"packet-dcerpc.h\"\n";
935
$self->{res}->{headers} .= "#include \"packet-dcerpc-nt.h\"\n";
936
$self->{res}->{headers} .= "#include \"packet-windows-common.h\"\n";
938
my $h_basename = basename($h_filename);
940
$self->{res}->{headers} .= "#include \"$h_basename\"\n";
941
$self->pidl_code("");
943
if (defined($self->{conformance}->{ett})) {
944
register_ett($self,$_) foreach(@{$self->{conformance}->{ett}})
947
# Wireshark protocol registration
950
$self->ProcessInterface($_) if ($_->{TYPE} eq "INTERFACE");
951
$self->ProcessImport(@{$_->{PATHS}}) if ($_->{TYPE} eq "IMPORT");
952
$self->ProcessInclude(@{$_->{PATHS}}) if ($_->{TYPE} eq "INCLUDE");
955
$self->{res}->{ett} = DumpEttDeclaration($self->{ett});
956
$self->{res}->{hf} = $self->DumpHfDeclaration();
958
my $parser = $notice;
959
$parser.= $self->{res}->{headers};
960
$parser.=$self->{res}->{ett};
961
$parser.=$self->{res}->{hf};
962
$parser.=$self->{res}->{def};
963
if (exists ($self->{conformance}->{override})) {
964
$parser.=$self->{conformance}->{override};
966
$parser.=$self->{res}->{code};
968
my $header = "/* autogenerated by pidl */\n\n";
969
$header.=$self->{res}->{hdr};
971
$self->CheckUsed($self->{conformance});
973
return ($parser,$header);
976
###############################################################################
978
###############################################################################
982
my ($self, $name) = @_;
984
push (@{$self->{ett}}, $name);
990
my $res = "\tstatic gint *ett[] = {\n";
992
$res .= "\t\t&$_,\n";
998
sub DumpEttDeclaration
1001
my $res = "\n/* Ett declarations */\n";
1003
$res .= "static gint $_ = -1;\n";
1009
###############################################################################
1011
###############################################################################
1013
sub register_hf_field($$$$$$$$$)
1015
my ($self,$index,$name,$filter_name,$ft_type,$base_type,$valsstring,$mask,$blurb) = @_;
1017
if (defined ($self->{conformance}->{hf_renames}->{$index})) {
1018
$self->{conformance}->{hf_renames}->{$index}->{USED} = 1;
1019
return $self->{conformance}->{hf_renames}->{$index}->{NEWNAME};
1022
$self->{conformance}->{header_fields}->{$index} = {
1025
FILTER => $filter_name,
1026
FT_TYPE => $ft_type,
1027
BASE_TYPE => $base_type,
1028
VALSSTRING => $valsstring,
1033
if ((not defined($blurb) or $blurb eq "") and
1034
defined($self->{conformance}->{fielddescription}->{$index})) {
1035
$self->{conformance}->{header_fields}->{$index}->{BLURB} =
1036
$self->{conformance}->{fielddescription}->{$index}->{DESCRIPTION};
1037
$self->{conformance}->{fielddescription}->{$index}->{USED} = 1;
1043
sub DumpHfDeclaration($)
1048
$res = "\n/* Header field declarations */\n";
1050
foreach (keys %{$self->{conformance}->{header_fields}})
1052
$res .= "static gint $_ = -1;\n";
1061
my $res = "\tstatic hf_register_info hf[] = {\n";
1063
foreach (values %{$self->{conformance}->{header_fields}})
1065
$res .= "\t{ &$_->{INDEX},
1066
{ ".make_str($_->{NAME}).", ".make_str($_->{FILTER}).", $_->{FT_TYPE}, $_->{BASE_TYPE}, $_->{VALSSTRING}, $_->{MASK}, ".make_str($_->{BLURB}).", HFILL }},
1070
return $res."\t};\n";
1074
###############################################################################
1076
###############################################################################
1078
sub DumpFunctionTable($)
1082
my $res = "static dcerpc_sub_dissector $if->{NAME}\_dissectors[] = {\n";
1083
foreach (@{$if->{FUNCTIONS}}) {
1084
my $fn_name = $_->{NAME};
1085
$fn_name =~ s/^$if->{NAME}_//;
1086
$res.= "\t{ $_->{OPNUM}, \"$fn_name\",\n";
1087
$res.= "\t $if->{NAME}_dissect_${fn_name}_request, $if->{NAME}_dissect_${fn_name}_response},\n";
1090
$res .= "\t{ 0, NULL, NULL, NULL }\n";
1097
my ($self, $conformance) = @_;
1098
foreach (values %{$conformance->{header_fields}}) {
1099
if (not defined($self->{hf_used}->{$_->{INDEX}})) {
1100
warning($_->{POS}, "hf field `$_->{INDEX}' not used");
1104
foreach (values %{$conformance->{hf_renames}}) {
1105
if (not $_->{USED}) {
1106
warning($_->{POS}, "hf field `$_->{OLDNAME}' not used");
1110
foreach (values %{$conformance->{dissectorparams}}) {
1111
if (not $_->{USED}) {
1112
warning($_->{POS}, "dissector param never used");
1116
foreach (values %{$conformance->{imports}}) {
1117
if (not $_->{USED}) {
1118
warning($_->{POS}, "import never used");
1122
foreach (values %{$conformance->{types}}) {
1123
if (not $_->{USED} and defined($_->{POS})) {
1124
warning($_->{POS}, "type never used");
1128
foreach (values %{$conformance->{fielddescription}}) {
1129
if (not $_->{USED}) {
1130
warning($_->{POS}, "description never used");
1134
foreach (values %{$conformance->{tfs}}) {
1135
if (not $_->{USED}) {
1136
warning($_->{POS}, "True/False description never used");