From 407249eb5d654b5a951c43bc1722fd397d5d922c Mon Sep 17 00:00:00 2001 From: srdusr <99972264+srdusr@users.noreply.github.com> Date: Tue, 1 Jul 2025 00:40:00 +0200 Subject: Add FTP, SMTP, TFTP, and IGMP; fix an IGMPv3 group-address misparse FTP and SMTP share HTTP's line-based response-code-or-command shape but keep their own command vocabularies in separate files rather than sharing a parser. FTP passwords are shown as-is, not redacted - FTP sends them in the clear regardless, matching Wireshark's own behavior. TFTP is a small binary opcode protocol (RFC 1350) instead. IGMP sits directly on IP like ICMP, so it's dispatched by protocol number rather than through the port-keyed L7Registry the other three use. Live-verified: FTP/SMTP against minimal real TCP servers written for this (nothing installed locally), a full command/response exchange decoded correctly in both directions. TFTP against a real atftpd server and atftp client - the RRQ decoded correctly even though the transfer itself didn't complete (an atftpd sandbox issue, not this code). IGMP against real multicast traffic on wlp1s0, including a genuine query from the actual router. That live IGMP traffic caught a real bug before it shipped further: parse_igmp() read bytes[4:8] as a group address for every message type, but IGMPv3 reports use those bytes for Reserved+RecordCount instead - a real V3 report showed "group=0.0.0.1" (0 reserved, 1 record, misread as an IP). Fixed by only populating group for the types where it's genuinely an address; re-verified against the same live traffic, and a regression test locks in the exact pattern. --- tests/test_tftp.cpp | 85 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 85 insertions(+) create mode 100644 tests/test_tftp.cpp (limited to 'tests/test_tftp.cpp') diff --git a/tests/test_tftp.cpp b/tests/test_tftp.cpp new file mode 100644 index 0000000..2955537 --- /dev/null +++ b/tests/test_tftp.cpp @@ -0,0 +1,85 @@ +#include + +#include + +#include "packeteer/l7/tftp.hpp" + +using namespace packeteer::net; + +namespace { + +std::vector build_rrq(const std::string& filename, const std::string& mode) { + std::vector bytes = {0x00, 0x01}; // opcode RRQ + bytes.insert(bytes.end(), filename.begin(), filename.end()); + bytes.push_back(0); + bytes.insert(bytes.end(), mode.begin(), mode.end()); + bytes.push_back(0); + return bytes; +} + +} // namespace + +TEST_CASE("parse_tftp decodes an RRQ with filename and mode") { + auto msg = parse_tftp(build_rrq("boot.img", "octet")); + REQUIRE(msg.has_value()); + CHECK(msg->opcode == kTftpRrq); + REQUIRE(msg->filename.has_value()); + CHECK(*msg->filename == "boot.img"); + REQUIRE(msg->mode.has_value()); + CHECK(*msg->mode == "octet"); +} + +TEST_CASE("parse_tftp decodes a DATA block number") { + std::vector bytes = {0x00, 0x03, 0x00, 0x07, 'h', 'i'}; + auto msg = parse_tftp(bytes); + REQUIRE(msg.has_value()); + CHECK(msg->opcode == kTftpData); + REQUIRE(msg->block.has_value()); + CHECK(*msg->block == 7); +} + +TEST_CASE("parse_tftp decodes an ACK block number") { + std::vector bytes = {0x00, 0x04, 0x00, 0x07}; + auto msg = parse_tftp(bytes); + REQUIRE(msg.has_value()); + CHECK(msg->opcode == kTftpAck); + REQUIRE(msg->block.has_value()); + CHECK(*msg->block == 7); +} + +TEST_CASE("parse_tftp decodes an ERROR code and message") { + std::vector bytes = {0x00, 0x05, 0x00, 0x01}; + std::string message = "File not found"; + bytes.insert(bytes.end(), message.begin(), message.end()); + bytes.push_back(0); + + auto msg = parse_tftp(bytes); + REQUIRE(msg.has_value()); + CHECK(msg->opcode == kTftpError); + REQUIRE(msg->error_code.has_value()); + CHECK(*msg->error_code == 1); + REQUIRE(msg->error_message.has_value()); + CHECK(*msg->error_message == "File not found"); +} + +TEST_CASE("parse_tftp rejects an opcode outside the known range") { + std::vector bytes = {0x00, 0x99}; + CHECK_FALSE(parse_tftp(bytes).has_value()); +} + +TEST_CASE("parse_tftp handles an RRQ with a truncated filename gracefully") { + std::vector bytes = {0x00, 0x01, 'a', 'b'}; // no null terminator + auto msg = parse_tftp(bytes); + REQUIRE(msg.has_value()); + CHECK(msg->opcode == kTftpRrq); + CHECK_FALSE(msg->filename.has_value()); +} + +TEST_CASE("TftpDissector claims port 69 and formats an RRQ") { + TftpDissector dissector; + CHECK(dissector.port() == kTftpPort); + + auto summary = dissector.summarize(build_rrq("boot.img", "octet")); + REQUIRE(summary.has_value()); + CHECK(*summary == "TFTP RRQ boot.img (octet)"); +} -- cgit v1.2.3