Commit Graph

34473 Commits

Author SHA1 Message Date
Dr. Lars Völker 7f23130fc0 SOME/IP: Changed config was not respected (BUGFIX)
The SOME/IP dissector did not update its dynamic hf config, after a
config changes. This patch fixes this by updating the internal data
after the UAT post update CB.

Closes: #17197
2021-02-02 06:12:22 +00:00
Aitor Garcia 5837bcea5e GOOSE: New option to display float values
Added to the protocol a new option to display the decimal representation
of floating-point values.

Minor fixes: Avoid the double 'return' on dissect_goose_UtcTime function
and fix the simulation BLURB to follow other fields approach.
2021-02-01 23:08:06 +00:00
Richard Sharpe fb2a0b4a71 ieee80211: Add support for S1G including PV1.
S1G adapters should be shipping soon since Silex America has a dev-kit
available, so it is about time to add support for this.

Change-Id: I0225d87f78efbcbe88476921d4fce3d56a3ce0cd
2021-02-01 19:34:55 +00:00
Richard Sharpe fc5d8db628 ieee80211: Add support for Extended Capabilities up to Octet 13.
This has been tested with captures I have from WFA. There is some additional
stuff I want to add to capture info about STAs that support SAE as well, but
will need another commit for that.

Change-Id: Iafbba52094856192e63a21f1c32bb7d785221d66
2021-02-01 12:38:34 +00:00
Gerald Combs e642f94ecb [Automatic update for 2021-01-31]
Update manuf, services enterprise numbers, translations, and other items.
2021-01-31 22:18:47 +00:00
Martin Kaiser a5207b541e mtp3: create the statistics table only once
Use the new stat_tap_find_table function during init to check if our
statistics table already exists.
2021-01-31 14:48:21 +00:00
Martin Kaiser b00c3bd742 sip: create the statistics tables only once
For sip, we have two different statistics tables for requests and responses.
Create each table only once, check if it already exists.
2021-01-31 13:48:38 +00:00
Martin Kaiser b49b95af65 rpc: create the statistics table only once
Use the new stat_tap_find_table function during init to check if our
statistics table already exists.
2021-01-31 13:27:16 +00:00
Martin Kaiser f21f1c292a dhcp: create the statistics table only once
Use the new stat_tap_find_table function during init to check if our
statistics table already exists.
2021-01-31 10:36:22 +00:00
Martin Kaiser 8963dff518 ansi_a: dtap statistics: create the table only once
Use the new stat_tap_find_table function during init to check if our
statistics table already exists.
2021-01-31 09:32:20 +00:00
Eugene Adell ed9485ce00 TCP: Null pointer crashes Wireshark
Working on #6683 introduced this bug because of a lack of
control on the conditions when calculating in-flight.Closes #17186.
2021-01-30 12:38:51 +00:00
João Valverde 10178fdb09 Don't include config.h in system headers
Config.h must not be installed so configuration must be performed by client code.

Fixes #17190.
2021-01-30 10:06:20 +00:00
Martin Mathieson 5fbc354f86 Make more functions and vars static. 2021-01-29 10:05:32 +00:00
Martin Kaiser f4ac70818a stat_tap_table_ui: create tables only once during init
If you load a capture file and open any statistics dialog, you'll see the
list of collected items. Each time you press the Apply button (without entering a
display filter) another list of items will be created as a top-level entry
of the statistics tree. Only the first list will have the correct values,
all subsequent lists will not be populated.

Each statistic module defines a stat_tap_table_ui structure that contains a
stat_tap_init_cb function. This init function is called by
SimpleStatisticsDialog::fillTree before the tap listener is registered. This
happens each time we collect the statistics.

However, it seems that all init functions create a new stat_tap_table each
time they are called, even if they already have an existing stat_tap_table
of the same name.

This patch adds a stat_tap_find_table function to find a table by name.

As a first step, we update the ANSI A-I/F BSMAP Statistics to check if its
table is already registered. If it is, the table will not be created again.
2021-01-28 13:41:08 +00:00
Alexis La Goutte 9fc1ce7610 ieee80211: Add FILS Discovery (Public Action)
from 802.11ai(-2016).pdf

Closed: #17135
2021-01-28 12:29:53 +00:00
Jaap Keuter b4f74bac74 ZVT: clean up some data points 2021-01-28 11:17:54 +00:00
Simon Holesch 6508b02ec4 D-Bus: Improve signature validation
An invalid signature ("a{sa}") caused a segfault when the array inside
the entry had a length of zero. An array signature code ("a") must be
followed by a single complete type, and "}" is not one of them. Check
additional restrictions for structs and dict entries, which aren't
related to this bug.

Fixes #17176
2021-01-28 02:04:16 +01:00
Simon Holesch 266e99e11a D-Bus: Handle variants with empty signatures
This triggered a dissector bug:
epan/dissectors/packet-dbus.c:796: failed assertion "DISSECTOR_ASSERT_NOT_REACHED"

Fixes #17176
2021-01-28 02:04:16 +01:00
Simon Holesch 96169c25f6 D-Bus: Pop subtrees on error in D-Bus header
Not popping all subtrees triggers a dissector bug:
epan/proto.c:1136: failed assertion "ptvc->pushed_tree_index == 0"

Fixes #17176
2021-01-28 02:01:46 +01:00
Jaap Keuter 616d44cbb6 ZVT: Use standard TCP segment reassemble support function
Fixes #17177
2021-01-27 23:05:23 +00:00
Guy Harris 93a472575d Rename WTAP_ENCAP_ETL to WTAP_ENCAP_ETW.
It corresponds to LINKTYPE_ETW in pcap and pcapng files; the structures
in the record format come from the Event Tracing for Windows (ETW) API
rather than directly from Event Trace Log files.

While we're at it, explain what extcap/etl does.
2021-01-27 14:33:09 -08:00
Martin Mathieson efcaa68807 More checking of non-static symbols. 2021-01-27 20:16:21 +00:00
João Valverde be0171019c UDP: Clean up handling of zero-valued UDP checksums
Replace the somewhat weird field format
    "[Checksum: [missing]]"
with
    "Checksum: 0x0000 [ignored or illegal value]"

Improve code redability and fix XXX comment.
2021-01-27 16:46:15 +00:00
João Valverde 1ef2077904 UDP: Add preference to ignore zero checksum over IPv6
Closes #16972. See also #6232.
2021-01-27 12:25:19 +00:00
Joey Salazar d7ffd8f014 git: parse Git Protocol version from pkt-lines
In Git's packfile transfer protocol[1], the initial server response
contains the version of the Git Protocol in use; version 1 or version 2
[2].

Parse out this information following up on work started in MR !805 [3]
by Izabela Bakollari and advice provided by Ronnie Sahlberg, add it as a
field for ease of reading and filtering.

[1] https://www.kernel.org/pub/software/scm/git/docs/technical/pack-protocol.html
[2] https://www.kernel.org/pub/software/scm/git/docs/technical/protocol-v2.html
[3] https://gitlab.com/wireshark/wireshark/-/merge_requests/805

Related to #17093
2021-01-27 09:09:51 +00:00
Martin Mathieson ca4e5c2962 Next batch of unused globals. 2021-01-27 08:42:27 +00:00
Guy Harris c26addae44 One more check for connection_info being non-null is needed.
This fixes issue #17182.
2021-01-27 00:15:24 -08:00
Thomas Sailer 76abe23f6d Bluetooth BR/EDR RF: header decoding according to specification
According to the LINKTYPE_BLUETOOTH_BREDR_BB Packet Structure specification
(http://www.whiterocker.com/bt/LINKTYPE_BLUETOOTH_BREDR_BB.html), the
Bluetooth header should be formatted according to the Bluetooth
specification Volume 2, Part B, Section 6.4. However, right now
wireshark expects the header to be in a weird format,
specifically it expects the header fields to be MSB but the bits
within each header field to be LSB. (Bluetooth standard is all
LSB). Furthermore, it computes the HEC (header check, i.e. the header
CRC) with 4 bits arbitrarily masked.

This patch decodes the header according to the spec. It still accepts
the old format (if the broken HEC matches), and displays a warning.
2021-01-27 06:23:52 +00:00
Jaap Keuter 7664748e72 BT_EVT: Codecs are not vendor codecs 2021-01-27 05:49:20 +00:00
Martin Mathieson 795dce3a6e NR-RRC: Use mac-nr UEId to configure algorithms 2021-01-26 17:36:02 +00:00
Rubin Gerritsen 277890d7e1 Bluetooth: Fix NULL pointer dereference crash
Occured when a control procedure packet was logged without connection
context.

The bug was introduced in 0dab2494ca

Signed-off-by: Rubin Gerritsen <rubin.gerritsen@nordicsemi.no>
2021-01-26 10:53:35 +00:00
mbutkereit d536d11a28 QUIC: Add dissection of MP-QUIC draft-deconinck-quic-multipath 2021-01-26 09:18:38 +00:00
Eugene Adell f255f6c683 TCP: Taking SACK's into account for in flight calculation
TCP in flight calculation was based on Sequence analysis only.
We now also look at the SACK blocks and give a more accurate
view of the in flight reality. Closes #6683.
2021-01-26 08:20:43 +00:00
Rubin Gerritsen 32cadbacb1 Bluetooth: Detect invalid control procedure collision resolution
See Bluetooth Core Spec, Vol 6, Part B, Section 5.3

If the event counter is available, the procedure is marked as complete
when the instant is reached.

Signed-off-by: Rubin Gerritsen <rubin.gerritsen@nordicsemi.no>
2021-01-26 07:05:08 +00:00
Martin Mathieson 619b3128a1 Make some symbols static or delete them. 2021-01-26 06:30:38 +00:00
Gerald Combs 785e291c1b USB HID: Avoid allocating a huge amount of memory (second try).
10204490d7 / MR 80 ensured that we didn't grow field.usages due to an
underflow, but it neglected to check for a sane array size. Add another
check to make sure we don't wmem_array_grow() too much. Fixes #17165 and
fixes #16809 more completely.
2021-01-26 05:20:04 +00:00
Gerald Combs 26f0db01a7 USB HID: Fix a memory leak.
Replace mismatched g_strdup() + g_free()s with
wmem_strdup_printf(wmem_packet_scope(), ...). Fixes #17124.
2021-01-26 00:33:37 +00:00
Grzegorz Niemirowski 6a860c979a Fix TID bitmap name 2021-01-25 22:50:37 +01:00
Christian Krump 420c0aea1e EPL: various extensions
- fixed some datatype issues (detected by scripts of gitlab environment)
- shift some flag informations of info-column
2021-01-25 15:23:05 +00:00
Carl Hörberg 846985afba AMQP protocol method Exchange#unbind-ok got method id 51
Reference: https://www.rabbitmq.com/resources/specs/amqp0-9-1.extended.xml
It's obviously a copy paste error from way back, but method id 51 is what
rabbitmq sends back on Exchange#UnbindOk so they've kept the "error".
2021-01-25 13:29:19 +00:00
Moshe Kaplan 5693ca8d50 packet-someip.c: Fix copy-paste error
Fixes Coverity 1472261
2021-01-24 19:56:30 +00:00
Rubin Gerritsen 0dab2494ca Bluetooth: Match control procedure requests with responses
This makes it easier to read logs where both the master
and slave initiate control procedures at the same time.
Retransmitted packets are not part of the request/response
tracing.

In order to perform the analysis, direction information must
be available.

The matching is implemented by storing control procedure contexts
for each direction for each connection object as each direction
may initiate its own procedure.

Limitations:
- When there is a control procedure violation where a device
  initiates a new procedure before the previous is complete,
  only the first procedure is traced.
  It would be possible to create more advanced tracing by
  storing a list of contexts per frame.
  However, as this is anyways a specification violation, this
  adds unnecessary complexity.
- Control procedures involving an instant are marked as completed
  when the last frame is sent even though the control procedure
  is completed when the instant is reached.
  This is the best possible approach when the event counter is
  not available.
  Due to this limitation, we are not able to detect the control
  procedure violation where a device initiates a new procedure
  before the instant is reached.

The following control procedure violations are detected:
- Starting a control procedure before the previous is complete.
  Control procedure violations where a new procedure is started
  before the instant is reached is currently not detected.
  That requires knowing the event counter.
- Control procedure packets that are not valid responses to an
  existing ongoing control procedure.

Signed-off-by: Rubin Gerritsen <rubin.gerritsen@nordicsemi.no>
2021-01-24 14:12:20 +01:00
Gerald Combs d50d075f88 [Automatic update for 2021-01-24]
Update manuf, services enterprise numbers, translations, and other items.
2021-01-24 09:48:31 +00:00
Fulko Hew bc530a355d Added dissector for TP-Link SmartHome protocol 2021-01-24 08:48:06 +00:00
Stijn Last 9ba1053237 packet-vnc: resolve issues reported by check_typed_item_calls.py
./tools/check_typed_item_calls.py --commits 1 | tee item_calls_check.txt
Examining:
epan/dissectors/packet-vnc.c

epan/dissectors/packet-vnc.c:1289 proto_tree_add_item called for hf_vnc_tight_tunnel_type  -  item type is FT_UINT8 but call has len 16
epan/dissectors/packet-vnc.c:1532 proto_tree_add_item called for hf_vnc_vencrypt_auth_type  -  item type is FT_UINT8 but call has len 4
epan/dissectors/packet-vnc.c:1545 proto_tree_add_item called for hf_vnc_vencrypt_auth_type  -  item type is FT_UINT8 but call has len 4
3 issues found

As explained here:
https://github.com/rfbproto/rfbproto/blob/master/rfbproto.rst#tight-security-type

The capability consists of a code, a 4 byte vendor string and an 8 byte signature string
2021-01-23 16:07:41 +00:00
Vadim Yanitskiy 884158fd24 GSM A-bis/RSL: fix SRR bit dissection in L1 Information IE 2021-01-23 02:24:59 +01:00
Dr. Lars Völker c1527c5d22 SOME/IP: Adding support for filtering parameters
This patch allows each configured parameter to be filtered and
therefore to be used in io graphs as well.

Fixes #17122

Be aware that this patch changes the format of:
- SOMEIP_parameter_list
- SOMEIP_parameter_arrays
- SOMEIP_parameter_structs
- SOMEIP_parameter_unions
2021-01-22 15:11:20 +00:00
Alexis La Goutte 229148a168 ieee80211: Update Reduced Neighbor Report with 802.11ax (WiFi 6)
following tbtt length, there is some field (BSSID, Short SSID, BSS Parameters)
2021-01-22 14:50:26 +00:00
Stijn Last 9913b8647e packet-vnc: added support for VeNCrypt
Specification:
https://github.com/rfbproto/rfbproto/blob/master/rfbproto.rst#vencrypt

Has been tested with tigervncserver / xtigervncviewer
with several security types and combinations:

/usr/bin/tigervncserver -SecurityTypes VncAuth
/usr/bin/tigervncserver -SecurityTypes TLSVnc
/usr/bin/tigervncserver -SecurityTypes X509Plain
/usr/bin/tigervncserver -SecurityTypes TLSVnc,VncAuth
2021-01-22 10:41:28 +00:00
Pascal Quantin 1b5df467b6 E1AP: use tcp_dissect_pdus() 2021-01-22 09:03:27 +00:00