diff options
Diffstat (limited to 'include/wireframe/pcapng/writer.hpp')
| -rw-r--r-- | include/wireframe/pcapng/writer.hpp | 94 |
1 files changed, 94 insertions, 0 deletions
diff --git a/include/wireframe/pcapng/writer.hpp b/include/wireframe/pcapng/writer.hpp new file mode 100644 index 0000000..18f6022 --- /dev/null +++ b/include/wireframe/pcapng/writer.hpp @@ -0,0 +1,94 @@ +#pragma once + +#include <algorithm> +#include <cstdint> +#include <cstdio> +#include <span> +#include <vector> + +// Minimal pcapng writer: one Section Header Block, one Interface +// Description Block, then an Enhanced Packet Block per captured packet. +// Per-block Options are skipped entirely - they're optional in the +// spec, and a block with none simply omits that section, so this stays +// a valid, Wireshark-readable file without needing to hand-encode TLVs. +// +// Multi-byte fields are written little-endian by hand (matching the +// 0x1A2B3C4D byte-order magic below) rather than via struct-casting, +// for the same alignment/UB reasons as the src/wireframe/net decoders. +namespace wireframe::pcapng { + +inline constexpr std::uint32_t kBlockTypeShb = 0x0A0D0D0A; +inline constexpr std::uint32_t kBlockTypeIdb = 0x00000001; +inline constexpr std::uint32_t kBlockTypeEpb = 0x00000006; +inline constexpr std::uint32_t kByteOrderMagic = 0x1A2B3C4D; +inline constexpr std::uint16_t kLinkTypeEthernet = 1; + +class Writer { +public: + explicit Writer(std::FILE* file) : file_(file) {} + + void write_section_header() { + std::uint8_t body[16]; + put_u32(body + 0, kByteOrderMagic); + put_u16(body + 4, 1); // major version + put_u16(body + 6, 0); // minor version + put_u64(body + 8, 0xFFFFFFFFFFFFFFFFULL); // section length: unknown + write_block(kBlockTypeShb, {body, sizeof(body)}); + } + + void write_interface_description(std::uint32_t snaplen, std::uint16_t link_type) { + std::uint8_t body[8]; + put_u16(body + 0, link_type); + put_u16(body + 2, 0); // reserved + put_u32(body + 4, snaplen); + write_block(kBlockTypeIdb, {body, sizeof(body)}); + } + + void write_packet(std::uint32_t interface_id, std::uint32_t ts_sec, std::uint32_t ts_usec, + std::span<const unsigned char> data, std::uint32_t original_len) { + std::uint64_t ts_us = static_cast<std::uint64_t>(ts_sec) * 1'000'000ULL + ts_usec; + std::uint32_t ts_high = static_cast<std::uint32_t>(ts_us >> 32); + std::uint32_t ts_low = static_cast<std::uint32_t>(ts_us & 0xFFFFFFFFULL); + + std::size_t padded_len = (data.size() + 3) & ~std::size_t(3); + std::vector<std::uint8_t> body(20 + padded_len, 0); // tail is padding, stays zero + put_u32(body.data() + 0, interface_id); + put_u32(body.data() + 4, ts_high); + put_u32(body.data() + 8, ts_low); + put_u32(body.data() + 12, static_cast<std::uint32_t>(data.size())); + put_u32(body.data() + 16, original_len); + std::copy(data.begin(), data.end(), body.begin() + 20); + + write_block(kBlockTypeEpb, body); + } + +private: + static void put_u16(std::uint8_t* p, std::uint16_t v) { + p[0] = static_cast<std::uint8_t>(v & 0xFF); + p[1] = static_cast<std::uint8_t>((v >> 8) & 0xFF); + } + + static void put_u32(std::uint8_t* p, std::uint32_t v) { + for (int i = 0; i < 4; ++i) p[i] = static_cast<std::uint8_t>((v >> (8 * i)) & 0xFF); + } + + static void put_u64(std::uint8_t* p, std::uint64_t v) { + for (int i = 0; i < 8; ++i) p[i] = static_cast<std::uint8_t>((v >> (8 * i)) & 0xFF); + } + + void write_block(std::uint32_t type, std::span<const std::uint8_t> body) { + std::uint32_t total_len = static_cast<std::uint32_t>(8 + body.size() + 4); + std::uint8_t type_buf[4]; + std::uint8_t len_buf[4]; + put_u32(type_buf, type); + put_u32(len_buf, total_len); + std::fwrite(type_buf, 1, 4, file_); + std::fwrite(len_buf, 1, 4, file_); + std::fwrite(body.data(), 1, body.size(), file_); + std::fwrite(len_buf, 1, 4, file_); + } + + std::FILE* file_; +}; + +} // namespace wireframe::pcapng |