srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/include/wireframe/net/tcp.hpp
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2024-05-14 01:42:00 +0200
committersrdusr <[email protected]>2024-05-14 01:42:00 +0200
commit08332a4195956611db80a2cfe3710d760cbd6acf (patch)
tree0cb5cdf9fdcfdd8dc8c129a33575ad9b182d5c01 /include/wireframe/net/tcp.hpp
downloadpacketeer-08332a4195956611db80a2cfe3710d760cbd6acf.tar.gz
packeteer-08332a4195956611db80a2cfe3710d760cbd6acf.zip
Initial commit: wireframe packet capture/analysis tool
Terminal packet capture and analysis tool built to learn the C++ memory model (byte layout, alignment, endianness, std::span over unowned buffers) via a real capture pipeline. - Hand-rolled L2-L4 decoders (Ethernet, IPv4, IPv6 with extension header walking, TCP, UDP) over std::span, no struct-casting - L7 dissector interface with DNS, HTTP, and TLS SNI implementations - pcapng read/write for Wireshark-compatible capture files - Bounded capture queue: drop-on-backpressure for live capture, blocking push for faithful file replay - Kernel-level BPF filtering (-f) and a separate display-only search (-g / interactive) that doesn't touch what's captured - Replay mode (-r) reads a saved pcapng file back through the same pipeline as live capture, no root or live device needed - pcap_stats() surfaces kernel/interface drops invisible to the capture queue's own counter - Three frontends sharing one CaptureSession setup path: CLI, TUI (FTXUI, primary), GUI (Dear ImGui + SDL3, secondary) - 89 unit tests (doctest) plus 9 libFuzzer harnesses covering every hand-rolled parser; fuzzing found and fixed a real OOM in the pcapng reader (unbounded allocation from an untrusted length field)
Diffstat (limited to 'include/wireframe/net/tcp.hpp')
-rw-r--r--include/wireframe/net/tcp.hpp54
1 files changed, 54 insertions, 0 deletions
diff --git a/include/wireframe/net/tcp.hpp b/include/wireframe/net/tcp.hpp
new file mode 100644
index 0000000..f691a7f
--- /dev/null
+++ b/include/wireframe/net/tcp.hpp
@@ -0,0 +1,54 @@
+#pragma once
+
+#include <cstdint>
+#include <optional>
+#include <span>
+
+#include "wireframe/byteio.hpp"
+
+namespace wireframe::net {
+
+// Lower 6 bits of the flags byte: URG ACK PSH RST SYN FIN. CWR/ECE (the
+// top 2 bits) are masked off - not needed for now.
+inline constexpr std::uint8_t kTcpFin = 0x01;
+inline constexpr std::uint8_t kTcpSyn = 0x02;
+inline constexpr std::uint8_t kTcpRst = 0x04;
+inline constexpr std::uint8_t kTcpPsh = 0x08;
+inline constexpr std::uint8_t kTcpAck = 0x10;
+inline constexpr std::uint8_t kTcpUrg = 0x20;
+
+struct TcpHeader {
+ std::uint16_t src_port;
+ std::uint16_t dst_port;
+ std::uint32_t seq;
+ std::uint32_t ack;
+ std::uint8_t data_offset; // header length in 32-bit words
+ std::uint8_t flags;
+ std::uint16_t window;
+};
+
+struct TcpSegment {
+ TcpHeader header;
+ std::span<const unsigned char> payload;
+};
+
+inline std::optional<TcpSegment> parse_tcp(std::span<const unsigned char> bytes) {
+ if (bytes.size() < 20) return std::nullopt;
+
+ std::uint8_t data_offset = static_cast<std::uint8_t>(bytes[12] >> 4);
+ std::size_t header_len = static_cast<std::size_t>(data_offset) * 4;
+ if (header_len < 20 || bytes.size() < header_len) return std::nullopt;
+
+ TcpHeader header{};
+ header.src_port = read_be16(bytes, 0);
+ header.dst_port = read_be16(bytes, 2);
+ header.seq = read_be32(bytes, 4);
+ header.ack = read_be32(bytes, 8);
+ header.data_offset = data_offset;
+ header.flags = bytes[13] & 0x3F;
+ header.window = read_be16(bytes, 14);
+
+ return TcpSegment{header, bytes.subspan(header_len)};
+}
+
+} // namespace wireframe::net