Wireshark 4.7.0
The Wireshark network protocol analyzer
Loading...
Searching...
No Matches
epan.h
Go to the documentation of this file.
1
10#ifndef __EPAN_H__
11#define __EPAN_H__
12
13#include <wsutil/feature_list.h>
14#include <epan/tvbuff.h>
15#include <epan/prefs.h>
16#include <epan/frame_data.h>
17#include <epan/register.h>
19
20#ifdef __cplusplus
21extern "C" {
22#endif /* __cplusplus */
23
28extern bool wireshark_abort_on_too_many_items;
29
36WS_DLL_PUBLIC void ws_dissector_bug(const char *format, ...)
37 G_GNUC_PRINTF(1,2);
38
45#define ws_dissector_oops(_fmt, ...) ws_dissector_bug("OOPS: " _fmt, __VA_ARGS__)
46
54
55struct epan_dfilter;
56struct epan_column_info;
57
65
73 const nstime_t *(*get_frame_ts)(struct packet_provider_data *prov, uint32_t frame_num);
74 const nstime_t *(*get_start_ts)(struct packet_provider_data *prov);
75 const char *(*get_interface_name)(struct packet_provider_data *prov, uint32_t interface_id, unsigned section_number);
76 const char *(*get_interface_description)(struct packet_provider_data *prov, uint32_t interface_id, unsigned section_number);
77 wtap_block_t (*get_modified_block)(struct packet_provider_data *prov, const frame_data *fd);
78 int32_t(*get_process_id)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number);
79 const char *(*get_process_name)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number);
80 const uint8_t *(*get_process_uuid)(struct packet_provider_data *prov, uint32_t process_info_id, unsigned section_number, size_t *uuid_size);
81};
82
90/*
91Ref 1
92Epan
93Enhanced Packet ANalyzer, aka the packet analyzing engine. Source code can be found in the epan directory.
94
95Protocol-Tree - Keep data of the capture file protocol information.
96
97Dissectors - The various protocol dissectors in epan/dissectors.
98
99Plugins - Some of the protocol dissectors are implemented as plugins. Source code can be found at plugins.
100
101Display-Filters - the display filter engine at epan/dfilter
102
103*/
104
116WS_DLL_PUBLIC
117bool epan_init(register_cb cb, void *client_data, bool load_plugins);
118
124WS_DLL_PUBLIC
126
133WS_DLL_PUBLIC
134void epan_cleanup(void);
135
136
137typedef struct {
138 void (*init)(void); /* Called before proto_init() */
139 void (*post_init)(void); /* Called at the end of epan_init() */
140 void (*dissect_init)(epan_dissect_t *);
141 void (*dissect_cleanup)(epan_dissect_t *);
142 void (*cleanup)(void);
143 void (*register_all_protocols)(register_cb, void *);
144 void (*register_all_handoffs)(register_cb, void *);
145 void (*register_all_tap_listeners)(void);
147
160WS_DLL_PUBLIC void epan_register_plugin(const epan_plugin *plugin);
161
170WS_DLL_PUBLIC int epan_plugins_supported(void);
171
179void epan_conversation_init(void);
180
181
182typedef struct epan_session epan_t;
193typedef struct epan_session epan_t;
194
208WS_DLL_PUBLIC epan_t *epan_new(struct packet_provider_data *prov,
209 const struct packet_provider_funcs *funcs);
210
223WS_DLL_PUBLIC wtap_block_t epan_get_modified_block(const epan_t *session, const frame_data *fd);
224
240WS_DLL_PUBLIC const char *epan_get_interface_name(const epan_t *session, uint32_t interface_id, unsigned section_number);
241
256WS_DLL_PUBLIC const char *epan_get_interface_description(const epan_t *session, uint32_t interface_id, unsigned section_number);
257
274WS_DLL_PUBLIC int32_t epan_get_process_id(const epan_t *session, uint32_t process_info_id, unsigned section_number);
275
292WS_DLL_PUBLIC const char *epan_get_process_name(const epan_t *session, uint32_t process_info_id, unsigned section_number);
293
311WS_DLL_PUBLIC const uint8_t *epan_get_process_uuid(const epan_t *session, uint32_t process_info_id, unsigned section_number, size_t *uuid_size);
312
325const nstime_t *epan_get_frame_ts(const epan_t *session, uint32_t frame_num);
326
337const nstime_t *epan_get_start_ts(const epan_t *session);
338
348WS_DLL_PUBLIC void epan_free(epan_t *session);
349
360WS_DLL_PUBLIC const char* epan_get_version(void);
361
375WS_DLL_PUBLIC void epan_get_version_number(int *major, int *minor, int *micro);
376
391WS_DLL_PUBLIC
392void epan_set_always_visible(bool force);
393
402WS_DLL_PUBLIC
403void
404epan_dissect_init(epan_dissect_t *edt, epan_t *session, const bool create_proto_tree, const bool proto_tree_visible);
405
418WS_DLL_PUBLIC
420epan_dissect_new(epan_t *session, const bool create_proto_tree, const bool proto_tree_visible);
421
431WS_DLL_PUBLIC
432void
434
441WS_DLL_PUBLIC
442void
443epan_dissect_fake_protocols(epan_dissect_t *edt, const bool fake_protocols);
444
458WS_DLL_PUBLIC
459void
460epan_dissect_run(epan_dissect_t *edt, int file_type_subtype,
461 wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo);
462
479WS_DLL_PUBLIC
480void
481epan_dissect_run_with_taps(epan_dissect_t *edt, int file_type_subtype,
482 wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo);
483
499WS_DLL_PUBLIC
500void
502 frame_data *fd, struct epan_column_info *cinfo);
503
520WS_DLL_PUBLIC
521void
523 frame_data *fd, struct epan_column_info *cinfo);
524
541WS_DLL_PUBLIC
542void
544
558WS_DLL_PUBLIC
559void
561
575WS_DLL_PUBLIC
576void
578
592WS_DLL_PUBLIC
593void
595
608WS_DLL_PUBLIC
609void
610epan_dissect_fill_in_columns(epan_dissect_t *edt, const bool fill_col_exprs, const bool fill_fd_colums);
611
627WS_DLL_PUBLIC
628bool
630 const char *field_name);
631
645WS_DLL_PUBLIC
646void
648
659WS_DLL_PUBLIC
660void
662
680const char *
681epan_custom_set(epan_dissect_t *edt, GSList *ids, int occurrence, bool display_details,
682 char *result, char *expr, const int size);
683
689WS_DLL_PUBLIC
690void
691epan_gather_compile_info(feature_list l);
692
698WS_DLL_PUBLIC
699void
700epan_gather_runtime_info(feature_list l);
701
702#ifdef __cplusplus
703}
704#endif /* __cplusplus */
705
706#endif /* __EPAN_H__ */
WS_DLL_PUBLIC void epan_dissect_init(epan_dissect_t *edt, epan_t *session, const bool create_proto_tree, const bool proto_tree_visible)
Initialize an existing single packet dissection.
Definition epan.c:624
WS_DLL_PUBLIC void epan_dissect_fake_protocols(epan_dissect_t *edt, const bool fake_protocols)
Indicate whether protocols should be faked during dissection.
Definition epan.c:695
WS_DLL_PUBLIC int32_t epan_get_process_id(const epan_t *session, uint32_t process_info_id, unsigned section_number)
Retrieve the process ID associated with a given process info record.
Definition epan.c:556
void epan_conversation_init(void)
Initialize the table of conversations.
Definition epan.c:603
WS_DLL_PUBLIC void epan_dissect_file_run(epan_dissect_t *edt, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a dissection of file-based packet data.
Definition epan.c:732
bool wireshark_abort_on_dissector_bug
Definition epan.c:118
WS_DLL_PUBLIC void epan_gather_compile_info(feature_list l)
Get compile-time information for libraries used by libwireshark.
Definition epan.c:865
WS_DLL_PUBLIC void epan_dissect_cleanup(epan_dissect_t *edt)
Release resources associated with a packet dissection context.
Definition epan.c:759
WS_DLL_PUBLIC const char * epan_get_process_name(const epan_t *session, uint32_t process_info_id, unsigned section_number)
Retrieve the name of a process associated with a given process info record.
Definition epan.c:574
WS_DLL_PUBLIC epan_t * epan_new(struct packet_provider_data *prov, const struct packet_provider_funcs *funcs)
Create a new epan dissection session.
Definition epan.c:483
WS_DLL_PUBLIC const char * epan_get_interface_description(const epan_t *session, uint32_t interface_id, unsigned section_number)
Retrieve the description of a network interface.
Definition epan.c:516
WS_DLL_PUBLIC e_prefs * epan_load_settings(void)
Load all settings from the current profile that affect epan.
Definition epan.c:384
WS_DLL_PUBLIC void epan_free(epan_t *session)
Free an epan dissection session.
Definition epan.c:592
WS_DLL_PUBLIC void epan_dissect_prime_with_hfid(epan_dissect_t *edt, int hfid)
Prime a dissection context's protocol tree with a specific field or protocol.
Definition epan.c:808
WS_DLL_PUBLIC void epan_dissect_reset(epan_dissect_t *edt)
Reset a dissection context for reuse.
Definition epan.c:653
WS_DLL_PUBLIC bool epan_init(register_cb cb, void *client_data, bool load_plugins)
Initialize the entire epan module.
Definition epan.c:256
WS_DLL_PUBLIC int epan_plugins_supported(void)
Check plugin support status for libwireshark components.
Definition epan.c:239
WS_DLL_PUBLIC void epan_cleanup(void)
Clean up the entire epan module.
Definition epan.c:403
WS_DLL_PUBLIC void epan_dissect_free(epan_dissect_t *edt)
Free a single packet dissection context.
Definition epan.c:789
WS_DLL_PUBLIC void epan_dissect_fill_in_columns(epan_dissect_t *edt, const bool fill_col_exprs, const bool fill_fd_colums)
Populate packet list columns with dissection output.
Definition epan.c:836
WS_DLL_PUBLIC void epan_get_version_number(int *major, int *minor, int *micro)
Retrieve the version number of the epan library.
Definition epan.c:148
WS_DLL_PUBLIC wtap_block_t epan_get_modified_block(const epan_t *session, const frame_data *fd)
Retrieve a modified capture block associated with a specific frame.
Definition epan.c:498
WS_DLL_PUBLIC void ws_dissector_bug(const char *format,...) G_GNUC_PRINTF(1
Report a dissector bug (and optionally abort).
WS_DLL_PUBLIC bool epan_dissect_packet_contains_field(epan_dissect_t *edt, const char *field_name)
Check whether a dissected packet contains a specific named field.
Definition epan.c:843
const nstime_t * epan_get_frame_ts(const epan_t *session, uint32_t frame_num)
Retrieve the timestamp of a specific frame.
Definition epan.c:525
WS_DLL_PUBLIC void epan_dissect_prime_with_dfilter(epan_dissect_t *edt, const struct epan_dfilter *dfcode)
Prime a dissection context's protocol tree using a display filter.
WS_DLL_PUBLIC const uint8_t * epan_get_process_uuid(const epan_t *session, uint32_t process_info_id, unsigned section_number, size_t *uuid_size)
Retrieve the UUID of a process associated with a given process info record.
Definition epan.c:583
const nstime_t * epan_get_start_ts(const epan_t *session)
Retrieve the start timestamp of the capture session.
Definition epan.c:540
WS_DLL_PUBLIC void epan_dissect_run(epan_dissect_t *edt, int file_type_subtype, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a single packet dissection.
Definition epan.c:702
WS_DLL_PUBLIC void epan_gather_runtime_info(feature_list l)
Get runtime information for libraries used by libwireshark.
Definition epan.c:974
WS_DLL_PUBLIC void epan_dissect_prime_with_hfid_array(epan_dissect_t *edt, GArray *hfids)
Prime a dissection context's protocol tree with a set of fields or protocols.
Definition epan.c:814
WS_DLL_PUBLIC const char * epan_get_version(void)
Retrieve the epan library's version as a string.
Definition epan.c:143
WS_DLL_PUBLIC epan_dissect_t * epan_dissect_new(epan_t *session, const bool create_proto_tree, const bool proto_tree_visible)
Create a new single packet dissection.
Definition epan.c:684
WS_DLL_PUBLIC void epan_dissect_prime_with_dfilter_print(epan_dissect_t *edt, const struct epan_dfilter *dfcode)
Prime a dissection context's protocol tree using a display filter, marking fields for print output.
WS_DLL_PUBLIC void epan_dissect_file_run_with_taps(epan_dissect_t *edt, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a dissection of file-based packet data and invoke tap listeners.
Definition epan.c:746
WS_DLL_PUBLIC void epan_set_always_visible(bool force)
Set or unset the tree to always be visible when epan_dissect_init() is called.
Definition epan.c:615
WS_DLL_PUBLIC void epan_dissect_run_with_taps(epan_dissect_t *edt, int file_type_subtype, wtap_rec *rec, frame_data *fd, struct epan_column_info *cinfo)
Run a single packet dissection and invoke tap listeners.
Definition epan.c:719
const char * epan_custom_set(epan_dissect_t *edt, GSList *ids, int occurrence, bool display_details, char *result, char *expr, const int size)
Set the value of a custom column based on specified fields and expression.
Definition epan.c:826
WS_DLL_PUBLIC void epan_register_plugin(const epan_plugin *plugin)
Register an epan plugin with the dissection engine.
WS_DLL_PUBLIC const char * epan_get_interface_name(const epan_t *session, uint32_t interface_id, unsigned section_number)
Retrieve the name of a network interface.
Definition epan.c:507
void register_all_protocols(register_cb cb, void *client_data)
Definition register.c:65
Definition prefs.h:174
Definition plugins.c:29
Definition column-info.h:62
Definition dfilter-int.h:35
Definition epan_dissect.h:28
Definition epan.h:137
Definition epan.c:477
Definition nstime.h:26
Definition cfile.h:58
Structure containing pointers to functions supplied by the user of libwireshark.
Definition epan.h:72
Definition wtap_opttypes.h:272
Definition wtap.h:1425