#pragma once #include #include #include #include #include "wireframe/l7/dissector.hpp" #include "wireframe/l7/dns.hpp" // mDNS (RFC 6762) reuses DNS's exact wire format - same header layout, // same question/name encoding - just over a different port (5353, // usually to/from the multicast address 224.0.0.251) and typically // with many questions/answers per packet instead of DNS's usual one. // parse_dns() already only looks at the first question, which is true // here too; the only real difference worth a label is which protocol // this traffic actually is, so real-world capture output doesn't read // "DNS" for traffic that never touched a resolver. namespace wireframe::net { inline constexpr std::uint16_t kMdnsPort = 5353; class MdnsDissector : public L7Dissector { public: std::uint16_t port() const override { return kMdnsPort; } std::optional summarize(std::span payload) const override { auto msg = parse_dns(payload); if (!msg) return std::nullopt; // No id= field here unlike DnsDissector's summary: RFC 6762 // 18.1 has multicast queries send it as zero, so printing it // would just be "id=0" noise on real traffic. std::string out = "mDNS "; out += msg->header.is_response ? "response" : "query"; if (msg->header.is_response) out += " ancount=" + std::to_string(msg->header.ancount); if (msg->question) { out += " " + msg->question->name + " type=" + std::to_string(msg->question->qtype); } return out; } }; } // namespace wireframe::net