wireshark/capture.h

116 lines
4.0 KiB
C
Raw Normal View History

/* capture.h
* Definitions for packet capture windows
*
* $Id: capture.h,v 1.43 2004/03/04 19:31:20 ulfl Exp $
*
* Ethereal - Network traffic analyzer
* By Gerald Combs <gerald@ethereal.com>
* Copyright 1998 Gerald Combs
*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2
* of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*/
#ifndef __CAPTURE_H__
#define __CAPTURE_H__
#ifdef HAVE_LIBPCAP
/* Name we give to the child process when doing a "-S" capture. */
#define CHILD_NAME "ethereal-capture"
typedef struct {
gboolean has_snaplen; /* TRUE if maximum capture packet
length is specified */
int snaplen; /* Maximum captured packet length */
int promisc_mode; /* Capture in promiscuous mode */
int linktype; /* Data link type to use, or -1 for
"use default" */
int sync_mode; /* Fork a child to do the capture,
and sync between them */
gboolean multi_files_on; /* TRUE if ring buffer in use */
gboolean has_file_duration; /* TRUE if ring duration specified */
gint32 file_duration; /* Switch file after n seconds */
gboolean has_ring_num_files;/* TRUE if ring num_files specified */
guint32 ring_num_files; /* Number of multiple buffer files */
gboolean has_autostop_files;/* TRUE if maximum number of capture files
are specified */
gint32 autostop_files; /* Maximum number of capture files */
gboolean has_autostop_packets; /* TRUE if maximum packet count is
specified */
int autostop_packets; /* Maximum packet count */
gboolean has_autostop_filesize; /* TRUE if maximum capture file size
is specified */
gint32 autostop_filesize; /* Maximum capture file size */
gboolean has_autostop_duration; /* TRUE if maximum capture duration
is specified */
gint32 autostop_duration; /* Maximum capture duration */
} capture_options;
extern capture_options capture_opts;
extern gboolean quit_after_cap; /* Makes a "capture only mode". Implies -k */
extern gboolean capture_child; /* if this is the child for "-S" */
/* Open a specified file, or create a temporary file, and start a capture
to the file in question. Returns TRUE if the capture starts
successfully, FALSE otherwise. */
gboolean do_capture(const char *save_file);
Add a new global flag "capture_child", which is TRUE if we're a child process for a sync mode or fork mode capture. Have that flag control whether we do things that *only* the parent or *only* the child should do, rather than basing it solely on the setting of "sync_mode" or "fork_mode" (or, in the case of stuff done in the child process either in sync mode or fork mode, rather than basing it on the setting of those flags at all). Split "do_capture()" into a "run_capture()" routine that starts a capture (possibly by forking off and execing a child process, if we're supposed to do sync mode or fork mode captures), and that assumes the file to which the capture is to write has already been opened and that "cf.save_file_fd" is the file descriptor for that file, and a "do_capture()" routine that creates a temporary file, getting an FD for it, and calls "run_capture()". Use "run_capture()", rather than "capture()", for "-k" captures, so that it'll do the capture in a child process if "-S" or "-F" was specified ("do_capture()" won't do because "-k" captures should write to the file specified by the "-w" flag, not some random temporary file). For child process captures, however, just use "capture()" - the child process shouldn't itself fork off a child if we're in sync or fork mode, and should just write to the file whose file descriptor was specified by the "-W" flag on the command line. All this allows you to do "ethereal -S -w <file> -i <interface> -k" to start a sync mode capture from the command line. svn path=/trunk/; revision=740
1999-09-30 06:50:01 +00:00
/* Do the low-level work of a capture. */
int capture(gboolean *stats_known, struct pcap_stat *stats);
/* Stop a capture from a menu item. */
void capture_stop(void);
/* Terminate the capture child cleanly when exiting. */
void kill_capture_child(void);
/* XXX: improve this macro (put something like this into epan/packet.h?) */
#define CAPTURE_PACKET_COUNTS sizeof(packet_counts) / sizeof (gint)
typedef struct {
/* handles */
gpointer callback_data; /* capture callback handle */
gpointer ui; /* user interfaces own handle */
/* capture info */
packet_counts *counts; /* protocol specific counters */
time_t running_time; /* running time since last update */
gint new_packets; /* packets since last update */
} capture_info;
/* create the capture info dialog */
extern void capture_info_create(
capture_info *cinfo);
/* Update the capture info counters in the dialog */
extern void capture_info_update(
capture_info *cinfo);
/* destroy the capture info dialog again */
extern void capture_info_destroy(
capture_info *cinfo);
#endif /* HAVE_LIBPCAP */
#define EMPTY_FILTER ""
#endif /* capture.h */