srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/include/wireframe/net/ipv4.hpp
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2024-05-14 01:42:00 +0200
committersrdusr <[email protected]>2024-05-14 01:42:00 +0200
commit08332a4195956611db80a2cfe3710d760cbd6acf (patch)
tree0cb5cdf9fdcfdd8dc8c129a33575ad9b182d5c01 /include/wireframe/net/ipv4.hpp
downloadpacketeer-08332a4195956611db80a2cfe3710d760cbd6acf.tar.gz
packeteer-08332a4195956611db80a2cfe3710d760cbd6acf.zip
Initial commit: wireframe packet capture/analysis tool
Terminal packet capture and analysis tool built to learn the C++ memory model (byte layout, alignment, endianness, std::span over unowned buffers) via a real capture pipeline. - Hand-rolled L2-L4 decoders (Ethernet, IPv4, IPv6 with extension header walking, TCP, UDP) over std::span, no struct-casting - L7 dissector interface with DNS, HTTP, and TLS SNI implementations - pcapng read/write for Wireshark-compatible capture files - Bounded capture queue: drop-on-backpressure for live capture, blocking push for faithful file replay - Kernel-level BPF filtering (-f) and a separate display-only search (-g / interactive) that doesn't touch what's captured - Replay mode (-r) reads a saved pcapng file back through the same pipeline as live capture, no root or live device needed - pcap_stats() surfaces kernel/interface drops invisible to the capture queue's own counter - Three frontends sharing one CaptureSession setup path: CLI, TUI (FTXUI, primary), GUI (Dear ImGui + SDL3, secondary) - 89 unit tests (doctest) plus 9 libFuzzer harnesses covering every hand-rolled parser; fuzzing found and fixed a real OOM in the pcapng reader (unbounded allocation from an untrusted length field)
Diffstat (limited to 'include/wireframe/net/ipv4.hpp')
-rw-r--r--include/wireframe/net/ipv4.hpp56
1 files changed, 56 insertions, 0 deletions
diff --git a/include/wireframe/net/ipv4.hpp b/include/wireframe/net/ipv4.hpp
new file mode 100644
index 0000000..f53b4f2
--- /dev/null
+++ b/include/wireframe/net/ipv4.hpp
@@ -0,0 +1,56 @@
+#pragma once
+
+#include <algorithm>
+#include <array>
+#include <cstdint>
+#include <optional>
+#include <span>
+
+#include "wireframe/byteio.hpp"
+
+namespace wireframe::net {
+
+inline constexpr std::uint8_t kProtoIcmp = 1;
+inline constexpr std::uint8_t kProtoTcp = 6;
+inline constexpr std::uint8_t kProtoUdp = 17;
+
+struct Ipv4Address {
+ std::array<unsigned char, 4> bytes;
+};
+
+struct Ipv4Header {
+ std::uint8_t version;
+ std::uint8_t ihl; // header length in 32-bit words
+ std::uint16_t total_length;
+ std::uint8_t ttl;
+ std::uint8_t protocol;
+ Ipv4Address src;
+ Ipv4Address dst;
+};
+
+struct Ipv4Packet {
+ Ipv4Header header;
+ std::span<const unsigned char> payload;
+};
+
+inline std::optional<Ipv4Packet> parse_ipv4(std::span<const unsigned char> bytes) {
+ if (bytes.size() < 20) return std::nullopt;
+
+ std::uint8_t version = static_cast<std::uint8_t>(bytes[0] >> 4);
+ std::uint8_t ihl = bytes[0] & 0x0F;
+ std::size_t header_len = static_cast<std::size_t>(ihl) * 4;
+ if (version != 4 || header_len < 20 || bytes.size() < header_len) return std::nullopt;
+
+ Ipv4Header header{};
+ header.version = version;
+ header.ihl = ihl;
+ header.total_length = read_be16(bytes, 2);
+ header.ttl = bytes[8];
+ header.protocol = bytes[9];
+ std::copy_n(bytes.begin() + 12, 4, header.src.bytes.begin());
+ std::copy_n(bytes.begin() + 16, 4, header.dst.bytes.begin());
+
+ return Ipv4Packet{header, bytes.subspan(header_len)};
+}
+
+} // namespace wireframe::net