From 407249eb5d654b5a951c43bc1722fd397d5d922c Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Tue, 1 Jul 2025 00:40:00 +0200 Subject: Add FTP, SMTP, TFTP, and IGMP; fix an IGMPv3 group-address misparse FTP and SMTP share HTTP's line-based response-code-or-command shape but keep their own command vocabularies in separate files rather than sharing a parser. FTP passwords are shown as-is, not redacted - FTP sends them in the clear regardless, matching Wireshark's own behavior. TFTP is a small binary opcode protocol (RFC 1350) instead. IGMP sits directly on IP like ICMP, so it's dispatched by protocol number rather than through the port-keyed L7Registry the other three use. Live-verified: FTP/SMTP against minimal real TCP servers written for this (nothing installed locally), a full command/response exchange decoded correctly in both directions. TFTP against a real atftpd server and atftp client - the RRQ decoded correctly even though the transfer itself didn't complete (an atftpd sandbox issue, not this code). IGMP against real multicast traffic on wlp1s0, including a genuine query from the actual router. That live IGMP traffic caught a real bug before it shipped further: parse_igmp() read bytes[4:8] as a group address for every message type, but IGMPv3 reports use those bytes for Reserved+RecordCount instead - a real V3 report showed "group=0.0.0.1" (0 reserved, 1 record, misread as an IP). Fixed by only populating group for the types where it's genuinely an address; re-verified against the same live traffic, and a regression test locks in the exact pattern. --- tests/test_igmp.cpp | 51 +++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 tests/test_igmp.cpp (limited to 'tests/test_igmp.cpp') diff --git a/tests/test_igmp.cpp b/tests/test_igmp.cpp new file mode 100644 index 0000000..b87d88d --- /dev/null +++ b/tests/test_igmp.cpp @@ -0,0 +1,51 @@ +#include + +#include +#include + +#include "packeteer/net/igmp.hpp" + +using namespace packeteer::net; + +TEST_CASE("parse_igmp decodes a general membership query with an all-zero group") { + std::vector bytes = {0x11, 0x64, 0x00, 0x00, 0, 0, 0, 0}; + auto igmp = parse_igmp(bytes); + REQUIRE(igmp.has_value()); + CHECK(igmp->type == kIgmpMembershipQuery); + REQUIRE(igmp->group.has_value()); + CHECK(igmp->group->bytes == std::array{0, 0, 0, 0}); +} + +TEST_CASE("parse_igmp decodes a v2 membership report with a real group address") { + std::vector bytes = {0x16, 0x00, 0x00, 0x00, 239, 255, 255, 250}; + auto igmp = parse_igmp(bytes); + REQUIRE(igmp.has_value()); + CHECK(igmp->type == kIgmpV2MembershipReport); + REQUIRE(igmp->group.has_value()); + CHECK(igmp->group->bytes == std::array{239, 255, 255, 250}); +} + +TEST_CASE("parse_igmp rejects a payload shorter than the fixed header") { + std::vector bytes(4, 0); + CHECK_FALSE(parse_igmp(bytes).has_value()); +} + +TEST_CASE("parse_igmp leaves group unset for a v3 report, whose bytes[4:8] aren't an address") { + // Real capture from this exact bug: bytes[4:8] here are Reserved + // (2 bytes, zero) + Number of Group Records (2 bytes, = 1) -- + // reading that as an IPv4 address produced the nonsense + // "group=0.0.0.1" before this was fixed. IGMPv3's actual group + // address(es) live inside the group records that follow, which + // this dissector doesn't decode (see the header comment). + std::vector bytes = {0x22, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}; + auto igmp = parse_igmp(bytes); + REQUIRE(igmp.has_value()); + CHECK(igmp->type == kIgmpV3MembershipReport); + CHECK_FALSE(igmp->group.has_value()); +} + +TEST_CASE("igmp_type_name names known types and falls back to hex for unknown ones") { + CHECK(igmp_type_name(kIgmpMembershipQuery) == "Membership Query"); + CHECK(igmp_type_name(kIgmpLeaveGroup) == "Leave Group"); + CHECK(igmp_type_name(0x99) == "type=0x99"); +} -- cgit v1.2.3