srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-07-01 00:40:00 +0200
committersrdusr <[email protected]>2025-07-01 00:40:00 +0200
commit407249eb5d654b5a951c43bc1722fd397d5d922c (patch)
treec367bf95c3855152d477a7eed5e709b3094a427c /tests
parent9046e6a10fd2d987cf6f6dc601ed3a75d286793f (diff)
downloadpacketeer-407249eb5d654b5a951c43bc1722fd397d5d922c.tar.gz
packeteer-407249eb5d654b5a951c43bc1722fd397d5d922c.zip
Add FTP, SMTP, TFTP, and IGMP; fix an IGMPv3 group-address misparse
FTP and SMTP share HTTP's line-based response-code-or-command shape but keep their own command vocabularies in separate files rather than sharing a parser. FTP passwords are shown as-is, not redacted - FTP sends them in the clear regardless, matching Wireshark's own behavior. TFTP is a small binary opcode protocol (RFC 1350) instead. IGMP sits directly on IP like ICMP, so it's dispatched by protocol number rather than through the port-keyed L7Registry the other three use. Live-verified: FTP/SMTP against minimal real TCP servers written for this (nothing installed locally), a full command/response exchange decoded correctly in both directions. TFTP against a real atftpd server and atftp client - the RRQ decoded correctly even though the transfer itself didn't complete (an atftpd sandbox issue, not this code). IGMP against real multicast traffic on wlp1s0, including a genuine query from the actual router. That live IGMP traffic caught a real bug before it shipped further: parse_igmp() read bytes[4:8] as a group address for every message type, but IGMPv3 reports use those bytes for Reserved+RecordCount instead - a real V3 report showed "group=0.0.0.1" (0 reserved, 1 record, misread as an IP). Fixed by only populating group for the types where it's genuinely an address; re-verified against the same live traffic, and a regression test locks in the exact pattern.
Diffstat (limited to 'tests')
-rw-r--r--tests/test_ftp.cpp51
-rw-r--r--tests/test_igmp.cpp51
-rw-r--r--tests/test_smtp.cpp51
-rw-r--r--tests/test_summarize.cpp22
-rw-r--r--tests/test_tftp.cpp85
5 files changed, 260 insertions, 0 deletions
diff --git a/tests/test_ftp.cpp b/tests/test_ftp.cpp
new file mode 100644
index 0000000..0015f42
--- /dev/null
+++ b/tests/test_ftp.cpp
@@ -0,0 +1,51 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/l7/ftp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> to_bytes(const std::string& s) {
+ return std::vector<unsigned char>(s.begin(), s.end());
+}
+
+} // namespace
+
+TEST_CASE("parse_ftp decodes a greeting response") {
+ auto msg = parse_ftp(to_bytes("220 (vsFTPd 3.0.5)\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->is_response);
+ CHECK(msg->command_or_code == "220");
+ CHECK(msg->argument == "(vsFTPd 3.0.5)");
+}
+
+TEST_CASE("parse_ftp decodes a USER command") {
+ auto msg = parse_ftp(to_bytes("USER anonymous\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK_FALSE(msg->is_response);
+ CHECK(msg->command_or_code == "USER");
+ CHECK(msg->argument == "anonymous");
+}
+
+TEST_CASE("parse_ftp decodes a command with no argument") {
+ auto msg = parse_ftp(to_bytes("PASV\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->command_or_code == "PASV");
+ CHECK(msg->argument.empty());
+}
+
+TEST_CASE("parse_ftp rejects an unrecognized command word") {
+ CHECK_FALSE(parse_ftp(to_bytes("BOGUS foo\r\n")).has_value());
+}
+
+TEST_CASE("FtpDissector claims port 21 and formats command and argument together") {
+ FtpDissector dissector;
+ CHECK(dissector.port() == kFtpPort);
+
+ auto summary = dissector.summarize(to_bytes("RETR file.txt\r\n"));
+ REQUIRE(summary.has_value());
+ CHECK(*summary == "FTP RETR file.txt");
+}
diff --git a/tests/test_igmp.cpp b/tests/test_igmp.cpp
new file mode 100644
index 0000000..b87d88d
--- /dev/null
+++ b/tests/test_igmp.cpp
@@ -0,0 +1,51 @@
+#include <doctest/doctest.h>
+
+#include <array>
+#include <vector>
+
+#include "packeteer/net/igmp.hpp"
+
+using namespace packeteer::net;
+
+TEST_CASE("parse_igmp decodes a general membership query with an all-zero group") {
+ std::vector<unsigned char> bytes = {0x11, 0x64, 0x00, 0x00, 0, 0, 0, 0};
+ auto igmp = parse_igmp(bytes);
+ REQUIRE(igmp.has_value());
+ CHECK(igmp->type == kIgmpMembershipQuery);
+ REQUIRE(igmp->group.has_value());
+ CHECK(igmp->group->bytes == std::array<unsigned char, 4>{0, 0, 0, 0});
+}
+
+TEST_CASE("parse_igmp decodes a v2 membership report with a real group address") {
+ std::vector<unsigned char> bytes = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250};
+ auto igmp = parse_igmp(bytes);
+ REQUIRE(igmp.has_value());
+ CHECK(igmp->type == kIgmpV2MembershipReport);
+ REQUIRE(igmp->group.has_value());
+ CHECK(igmp->group->bytes == std::array<unsigned char, 4>{239, 255, 255, 250});
+}
+
+TEST_CASE("parse_igmp rejects a payload shorter than the fixed header") {
+ std::vector<unsigned char> bytes(4, 0);
+ CHECK_FALSE(parse_igmp(bytes).has_value());
+}
+
+TEST_CASE("parse_igmp leaves group unset for a v3 report, whose bytes[4:8] aren't an address") {
+ // Real capture from this exact bug: bytes[4:8] here are Reserved
+ // (2 bytes, zero) + Number of Group Records (2 bytes, = 1) --
+ // reading that as an IPv4 address produced the nonsense
+ // "group=0.0.0.1" before this was fixed. IGMPv3's actual group
+ // address(es) live inside the group records that follow, which
+ // this dissector doesn't decode (see the header comment).
+ std::vector<unsigned char> bytes = {0x22, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01};
+ auto igmp = parse_igmp(bytes);
+ REQUIRE(igmp.has_value());
+ CHECK(igmp->type == kIgmpV3MembershipReport);
+ CHECK_FALSE(igmp->group.has_value());
+}
+
+TEST_CASE("igmp_type_name names known types and falls back to hex for unknown ones") {
+ CHECK(igmp_type_name(kIgmpMembershipQuery) == "Membership Query");
+ CHECK(igmp_type_name(kIgmpLeaveGroup) == "Leave Group");
+ CHECK(igmp_type_name(0x99) == "type=0x99");
+}
diff --git a/tests/test_smtp.cpp b/tests/test_smtp.cpp
new file mode 100644
index 0000000..610ed4e
--- /dev/null
+++ b/tests/test_smtp.cpp
@@ -0,0 +1,51 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/l7/smtp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> to_bytes(const std::string& s) {
+ return std::vector<unsigned char>(s.begin(), s.end());
+}
+
+} // namespace
+
+TEST_CASE("parse_smtp decodes a greeting response") {
+ auto msg = parse_smtp(to_bytes("220 mail.example.com ESMTP\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->is_response);
+ CHECK(msg->command_or_code == "220");
+ CHECK(msg->argument == "mail.example.com ESMTP");
+}
+
+TEST_CASE("parse_smtp decodes a MAIL FROM command") {
+ auto msg = parse_smtp(to_bytes("MAIL FROM:<[email protected]>\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK_FALSE(msg->is_response);
+ CHECK(msg->command_or_code == "MAIL");
+ CHECK(msg->argument == "FROM:<[email protected]>");
+}
+
+TEST_CASE("parse_smtp decodes a multi-line response's first line, dash included") {
+ auto msg = parse_smtp(to_bytes("250-mail.example.com Hello\r\n250-PIPELINING\r\n"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->command_or_code == "250");
+ CHECK(msg->argument == "mail.example.com Hello");
+}
+
+TEST_CASE("parse_smtp rejects an unrecognized command word") {
+ CHECK_FALSE(parse_smtp(to_bytes("BOGUS foo\r\n")).has_value());
+}
+
+TEST_CASE("SmtpDissector claims port 25") {
+ SmtpDissector dissector;
+ CHECK(dissector.port() == kSmtpPort);
+
+ auto summary = dissector.summarize(to_bytes("EHLO client.example.com\r\n"));
+ REQUIRE(summary.has_value());
+ CHECK(*summary == "SMTP EHLO client.example.com");
+}
diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp
index d7b223a..9eef454 100644
--- a/tests/test_summarize.cpp
+++ b/tests/test_summarize.cpp
@@ -186,6 +186,28 @@ TEST_CASE("summarize_packet decodes an ARP request end to end") {
"ARP who-has 10.0.0.2 tell 10.0.0.1 (aa:bb:cc:dd:ee:ff)");
}
+TEST_CASE("summarize_packet decodes IGMP directly on IP (not through a TCP/UDP port)") {
+ std::vector<unsigned char> igmp = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250}; // v2 report
+
+ std::vector<unsigned char> ip(20, 0);
+ ip[0] = 0x45;
+ ip[8] = 1;
+ ip[9] = packeteer::net::kProtoIgmp;
+ ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1;
+ ip[16] = 239; ip[17] = 255; ip[18] = 255; ip[19] = 250;
+
+ std::vector<unsigned char> eth = {
+ 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x00,
+ };
+
+ std::vector<unsigned char> frame = eth;
+ frame.insert(frame.end(), ip.begin(), ip.end());
+ frame.insert(frame.end(), igmp.begin(), igmp.end());
+
+ auto line = packeteer::summarize_packet(frame, DLT_EN10MB);
+ CHECK(line.find("IGMP V2 Membership Report group=239.255.255.250") != std::string::npos);
+}
+
TEST_CASE("summarize_packet unwraps a VLAN tag to reach the real ARP payload underneath") {
std::vector<unsigned char> bytes = {
0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF,
diff --git a/tests/test_tftp.cpp b/tests/test_tftp.cpp
new file mode 100644
index 0000000..2955537
--- /dev/null
+++ b/tests/test_tftp.cpp
@@ -0,0 +1,85 @@
+#include <doctest/doctest.h>
+
+#include <vector>
+
+#include "packeteer/l7/tftp.hpp"
+
+using namespace packeteer::net;
+
+namespace {
+
+std::vector<unsigned char> build_rrq(const std::string& filename, const std::string& mode) {
+ std::vector<unsigned char> bytes = {0x00, 0x01}; // opcode RRQ
+ bytes.insert(bytes.end(), filename.begin(), filename.end());
+ bytes.push_back(0);
+ bytes.insert(bytes.end(), mode.begin(), mode.end());
+ bytes.push_back(0);
+ return bytes;
+}
+
+} // namespace
+
+TEST_CASE("parse_tftp decodes an RRQ with filename and mode") {
+ auto msg = parse_tftp(build_rrq("boot.img", "octet"));
+ REQUIRE(msg.has_value());
+ CHECK(msg->opcode == kTftpRrq);
+ REQUIRE(msg->filename.has_value());
+ CHECK(*msg->filename == "boot.img");
+ REQUIRE(msg->mode.has_value());
+ CHECK(*msg->mode == "octet");
+}
+
+TEST_CASE("parse_tftp decodes a DATA block number") {
+ std::vector<unsigned char> bytes = {0x00, 0x03, 0x00, 0x07, 'h', 'i'};
+ auto msg = parse_tftp(bytes);
+ REQUIRE(msg.has_value());
+ CHECK(msg->opcode == kTftpData);
+ REQUIRE(msg->block.has_value());
+ CHECK(*msg->block == 7);
+}
+
+TEST_CASE("parse_tftp decodes an ACK block number") {
+ std::vector<unsigned char> bytes = {0x00, 0x04, 0x00, 0x07};
+ auto msg = parse_tftp(bytes);
+ REQUIRE(msg.has_value());
+ CHECK(msg->opcode == kTftpAck);
+ REQUIRE(msg->block.has_value());
+ CHECK(*msg->block == 7);
+}
+
+TEST_CASE("parse_tftp decodes an ERROR code and message") {
+ std::vector<unsigned char> bytes = {0x00, 0x05, 0x00, 0x01};
+ std::string message = "File not found";
+ bytes.insert(bytes.end(), message.begin(), message.end());
+ bytes.push_back(0);
+
+ auto msg = parse_tftp(bytes);
+ REQUIRE(msg.has_value());
+ CHECK(msg->opcode == kTftpError);
+ REQUIRE(msg->error_code.has_value());
+ CHECK(*msg->error_code == 1);
+ REQUIRE(msg->error_message.has_value());
+ CHECK(*msg->error_message == "File not found");
+}
+
+TEST_CASE("parse_tftp rejects an opcode outside the known range") {
+ std::vector<unsigned char> bytes = {0x00, 0x99};
+ CHECK_FALSE(parse_tftp(bytes).has_value());
+}
+
+TEST_CASE("parse_tftp handles an RRQ with a truncated filename gracefully") {
+ std::vector<unsigned char> bytes = {0x00, 0x01, 'a', 'b'}; // no null terminator
+ auto msg = parse_tftp(bytes);
+ REQUIRE(msg.has_value());
+ CHECK(msg->opcode == kTftpRrq);
+ CHECK_FALSE(msg->filename.has_value());
+}
+
+TEST_CASE("TftpDissector claims port 69 and formats an RRQ") {
+ TftpDissector dissector;
+ CHECK(dissector.port() == kTftpPort);
+
+ auto summary = dissector.summarize(build_rrq("boot.img", "octet"));
+ REQUIRE(summary.has_value());
+ CHECK(*summary == "TFTP RRQ boot.img (octet)");
+}