From e0f4c701028aa81026a17cf9ebfb36112184f4bc Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Fri, 17 May 2024 19:54:00 +0200 Subject: Add privilege dropping, AF_PACKET demo, ICMP, checksum validation, --help, and TCP reassembly Rounds out the build order in PLAN.md with six incremental additions: drop root privileges immediately after opening the capture handle; a standalone AF_PACKET/mmap ring-buffer demo (kept separate from CaptureSession, see its header comment for why); ICMPv4/ICMPv6 type and code decoding; opt-in IPv4/TCP/UDP checksum validation (-c); CLI --help; and opt-in, in-order-only TCP stream reassembly (-a) so HTTP requests/responses split across segments can be seen whole. Each addition is unit-tested and, where it touches live traffic behavior, verified against real captured packets - see PLAN.md's Decisions section for the verification notes on each. --- include/wireframe/summarize.hpp | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) (limited to 'include/wireframe/summarize.hpp') diff --git a/include/wireframe/summarize.hpp b/include/wireframe/summarize.hpp index 59aa621..e7e9ae3 100644 --- a/include/wireframe/summarize.hpp +++ b/include/wireframe/summarize.hpp @@ -13,6 +13,7 @@ #include "wireframe/l7/http.hpp" #include "wireframe/l7/tls.hpp" #include "wireframe/net/ethernet.hpp" +#include "wireframe/net/icmp.hpp" #include "wireframe/net/ipv4.hpp" #include "wireframe/net/ipv6.hpp" #include "wireframe/net/tcp.hpp" @@ -122,8 +123,24 @@ inline std::string summarize_transport_and_above(const IpInfo& info) { out += " | " + *l7; } } + } else if (info.proto == net::kProtoIcmp) { + if (auto icmp = net::parse_icmpv4(info.payload)) { + out += " | ICMP " + net::icmpv4_type_name(icmp->type); + if (icmp->identifier) { + out += " id=" + std::to_string(*icmp->identifier) + + " seq=" + std::to_string(*icmp->sequence); + } + } } else if (info.proto == net::kNextHeaderIcmpv6) { - out += " | ICMPv6"; + if (auto icmp = net::parse_icmpv6(info.payload)) { + out += " | ICMPv6 " + net::icmpv6_type_name(icmp->type); + if (icmp->identifier) { + out += " id=" + std::to_string(*icmp->identifier) + + " seq=" + std::to_string(*icmp->sequence); + } + } else { + out += " | ICMPv6"; // truncated: at least say what it is + } } return out; } -- cgit v1.2.3