diff options
| author | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
| commit | b565d7d9c47ca1ec5af0effd828431ee96027d60 (patch) | |
| tree | fbe0c9c897e78f507443507354d5b1d8fb851099 /include/wireframe/l7/dns.hpp | |
| parent | fbedc55d5aa861c381701c9f913b34ee7ab57ec4 (diff) | |
| download | packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.tar.gz packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.zip | |
Rename project from wireframe to packeteer
Decided on the name after weighing alternatives in NAMES.md: packeteer
(packet + -eer, "one who wields packets") fit the project's actual
scope better than the wire/frame pun once it had grown into full
L2-L7 dissection, reassembly, checksums, privilege dropping, and dual
TUI/GUI frontends. No existing packet-capture project uses the name;
the one real-world collision (Packeteer, Inc., a networking company
acquired and folded into Blue Coat/Symantec by 2008) is long defunct.
Mechanical rename throughout: CMake project/target names, the
wireframe:: namespace and include/wireframe/ directory (git mv,
history preserved), every #include path, CLI/GUI help text, and the
project's own working directory. NAMES.md rewritten to record the
decision instead of leaving stale self-referential etymology behind
from the blind rename pass.
Verified after every step: full rebuild (all four targets, no
warnings) and the full test suite (128/128 cases, 366/366 assertions)
both from a fresh reconfigure and again after the directory move.
Diffstat (limited to 'include/wireframe/l7/dns.hpp')
| -rw-r--r-- | include/wireframe/l7/dns.hpp | 108 |
1 files changed, 0 insertions, 108 deletions
diff --git a/include/wireframe/l7/dns.hpp b/include/wireframe/l7/dns.hpp deleted file mode 100644 index 5c1ab36..0000000 --- a/include/wireframe/l7/dns.hpp +++ /dev/null @@ -1,108 +0,0 @@ -#pragma once - -#include <cstdint> -#include <optional> -#include <span> -#include <string> -#include <utility> - -#include "wireframe/byteio.hpp" -#include "wireframe/l7/dissector.hpp" - -// Hand-rolled DNS message parsing: header + the first question record. -// Answer/authority/additional records aren't decoded (not needed for a -// one-line summary), so name-compression pointers there are never -// followed - a pointer in the question section itself is rejected -// rather than chased, keeping this a pure forward scan with no risk of -// a pointer loop. -namespace wireframe::net { - -inline constexpr std::uint16_t kDnsPort = 53; - -struct DnsHeader { - std::uint16_t id; - bool is_response; - std::uint8_t opcode; - std::uint8_t rcode; - std::uint16_t qdcount; - std::uint16_t ancount; -}; - -struct DnsQuestion { - std::string name; - std::uint16_t qtype; -}; - -struct DnsMessage { - DnsHeader header; - std::optional<DnsQuestion> question; // first question only -}; - -// Reads a (possibly multi-label) dotted name starting at offset. -// Returns the name and the offset just past it, or nullopt on -// truncation or a compression pointer (0xC0 prefix - valid in -// answer/authority records, not supported here). -inline std::optional<std::pair<std::string, std::size_t>> read_dns_name( - std::span<const unsigned char> bytes, std::size_t offset) { - std::string name; - while (true) { - if (offset >= bytes.size()) return std::nullopt; - std::uint8_t len = bytes[offset]; - if (len == 0) { - ++offset; - break; - } - if ((len & 0xC0) == 0xC0) return std::nullopt; // compression pointer: unsupported - ++offset; - if (offset + len > bytes.size()) return std::nullopt; - if (!name.empty()) name += '.'; - for (std::uint8_t i = 0; i < len; ++i) name += static_cast<char>(bytes[offset + i]); - offset += len; - } - return std::make_pair(std::move(name), offset); -} - -inline std::optional<DnsMessage> parse_dns(std::span<const unsigned char> bytes) { - if (bytes.size() < 12) return std::nullopt; - - DnsHeader header{}; - header.id = read_be16(bytes, 0); - std::uint16_t flags = read_be16(bytes, 2); - header.is_response = (flags & 0x8000) != 0; - header.opcode = static_cast<std::uint8_t>((flags >> 11) & 0x0F); - header.rcode = static_cast<std::uint8_t>(flags & 0x0F); - header.qdcount = read_be16(bytes, 4); - header.ancount = read_be16(bytes, 6); - - DnsMessage msg{header, std::nullopt}; - if (header.qdcount >= 1) { - if (auto result = read_dns_name(bytes, 12)) { - auto& [name, next_offset] = *result; - if (next_offset + 4 <= bytes.size()) { - msg.question = DnsQuestion{std::move(name), read_be16(bytes, next_offset)}; - } - } - } - return msg; -} - -class DnsDissector : public L7Dissector { -public: - std::uint16_t port() const override { return kDnsPort; } - - std::optional<std::string> summarize(std::span<const unsigned char> payload) const override { - auto msg = parse_dns(payload); - if (!msg) return std::nullopt; - - std::string out = "DNS "; - out += msg->header.is_response ? "response" : "query"; - out += " id=" + std::to_string(msg->header.id); - if (msg->header.is_response) out += " ancount=" + std::to_string(msg->header.ancount); - if (msg->question) { - out += " " + msg->question->name + " type=" + std::to_string(msg->question->qtype); - } - return out; - } -}; - -} // namespace wireframe::net |