2 * This program is free software; you can redistribute it and/or modify
3 * it under the terms of the GNU General Public License as published by
4 * the Free Software Foundation; either version 2 of the License, or
5 * (at your option) any later version.
7 * This program is distributed in the hope that it will be useful,
8 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10 * GNU General Public License for more details.
12 * You should have received a copy of the GNU General Public License
13 * along with this program; if not, write to the Free Software
14 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
22 * Author : Boris Mikhailenko <stg34@stg.dp.ua>
27 $Date: 2009/03/24 11:20:15 $
31 #include <sys/types.h>
33 #include <sys/socket.h>
35 #include <sys/ioctl.h>
40 #include <netinet/in.h>
41 #include <arpa/inet.h>
51 #include "stg/common.h"
52 #include "stg/raw_ip_packet.h"
53 #include "stg/traffcounter.h"
54 #include "stg/plugin_creator.h"
56 #include "ether_cap.h"
60 //-----------------------------------------------------------------------------
61 //-----------------------------------------------------------------------------
62 //-----------------------------------------------------------------------------
65 PLUGIN_CREATOR<BPF_CAP> bcc;
68 extern "C" PLUGIN * GetPlugin();
69 //-----------------------------------------------------------------------------
70 //-----------------------------------------------------------------------------
71 //-----------------------------------------------------------------------------
74 return bcc.GetPlugin();
76 //-----------------------------------------------------------------------------
77 //-----------------------------------------------------------------------------
78 //-----------------------------------------------------------------------------
79 int BPF_CAP_SETTINGS::ParseSettings(const MODULE_SETTINGS & s)
81 iface.erase(iface.begin(), iface.end());
83 if (s.moduleParams.empty())
85 errorStr = "Parameter \'iface\' not found.";
86 printfd(__FILE__, "Parameter 'iface' not found\n");
90 for (unsigned i = 0; i < s.moduleParams.size(); i++)
92 if (s.moduleParams[i].param != "iface")
94 errorStr = "Parameter \'" + s.moduleParams[i].param + "\' unrecognized.";
95 printfd(__FILE__, "Invalid parameter: '%s'\n", s.moduleParams[i].param.c_str());
98 for (unsigned j = 0; j < s.moduleParams[i].value.size(); j++)
100 iface.push_back(s.moduleParams[i].value[j]);
106 //-----------------------------------------------------------------------------
107 std::string BPF_CAP_SETTINGS::GetIface(unsigned int num)
109 if (num >= iface.size())
115 //-----------------------------------------------------------------------------
116 //-----------------------------------------------------------------------------
117 //-----------------------------------------------------------------------------
118 std::string BPF_CAP::GetVersion() const
120 return "cap_bpf v.1.0";
122 //-----------------------------------------------------------------------------
134 logger(GetPluginLogger(GetStgLogger(), "cap_bpf"))
137 //-----------------------------------------------------------------------------
138 int BPF_CAP::ParseSettings()
140 int ret = capSettings.ParseSettings(settings);
143 errorStr = capSettings.GetStrError();
148 //-----------------------------------------------------------------------------
154 if (BPFCapOpen() < 0)
156 //errorStr = "Cannot open bpf device!";
162 if (pthread_create(&thread, NULL, Run, this))
164 errorStr = "Cannot create thread.";
165 logger("Cannot create thread.");
166 printfd(__FILE__, "Cannot create thread\n");
172 //-----------------------------------------------------------------------------
182 //5 seconds to thread stops itself
184 for (i = 0; i < 25; i++)
189 struct timespec ts = {0, 200000000};
190 nanosleep(&ts, NULL);
193 //after 5 seconds waiting thread still running. now killing it
196 //TODO pthread_cancel()
197 if (pthread_kill(thread, SIGINT))
199 errorStr = "Cannot kill thread.";
200 logger("Cannot send signal to thread.");
201 printfd(__FILE__, "Cannot kill thread\n");
208 //-----------------------------------------------------------------------------
209 void * BPF_CAP::Run(void * d)
212 sigfillset(&signalSet);
213 pthread_sigmask(SIG_BLOCK, &signalSet, NULL);
215 BPF_CAP * dc = static_cast<BPF_CAP *>(d);
216 dc->isRunning = true;
218 uint8_t hdr[96]; //68 + 14 + 4(size) + 9(SYS_IFACE) + 1(align to 4) = 96
220 RAW_PACKET * rpp = (RAW_PACKET *)&hdr[14];
221 memset(hdr, 0, sizeof(hdr));
228 if (dc->BPFCapRead((char*)&hdr, 68 + 14, &iface))
231 if (!(hdr[12] == 0x8 && hdr[13] == 0x0))
234 dc->traffCnt->Process(*rpp);
237 dc->isRunning = false;
240 //-----------------------------------------------------------------------------
241 int BPF_CAP::BPFCapOpen()
247 while ((bd.iface = capSettings.GetIface(i)) != "")
249 bpfData.push_back(bd);
250 if (BPFCapOpen(&bpfData[i]) < 0)
256 pd.fd = bpfData[i].fd;
263 //-----------------------------------------------------------------------------
264 int BPF_CAP::BPFCapOpen(BPF_DATA * bd)
274 sprintf(devbpf, "/dev/bpf%d", i);
276 bd->fd = open(devbpf, O_RDONLY);
277 } while(bd->fd < 0 && errno == EBUSY);
281 errorStr = "Can't capture packets. Open bpf device for " + bd->iface + " error.";
282 logger("Cannot open device for interface '%s': %s", bd->iface.c_str(), strerror(errno));
283 printfd(__FILE__, "Cannot open BPF device\n");
287 strncpy(ifr.ifr_name, bd->iface.c_str(), sizeof(ifr.ifr_name));
289 if (ioctl(bd->fd, BIOCSBLEN, (caddr_t)&l) < 0)
291 errorStr = bd->iface + " BIOCSBLEN " + std::string(strerror(errno));
292 logger("ioctl (BIOCSBLEN) error for interface '%s': %s", bd->iface.c_str(), strerror(errno));
293 printfd(__FILE__, "ioctl failed: '%s'\n", errorStr.c_str());
297 if (ioctl(bd->fd, BIOCSETIF, (caddr_t)&ifr) < 0)
299 errorStr = bd->iface + " BIOCSETIF " + std::string(strerror(errno));
300 logger("ioctl (BIOCSETIF) error for interface '%s': %s", bd->iface.c_str(), strerror(errno));
301 printfd(__FILE__, "ioctl failed: '%s'\n", errorStr.c_str());
305 if (ioctl(bd->fd, BIOCIMMEDIATE, &im) < 0)
307 errorStr = bd->iface + " BIOCIMMEDIATE " + std::string(strerror(errno));
308 logger("ioctl (BIOCIMMEDIATE) error for interface '%s': %s", bd->iface.c_str(), strerror(errno));
309 printfd(__FILE__, "ioctl failed: '%s'\n", errorStr.c_str());
315 //-----------------------------------------------------------------------------
316 int BPF_CAP::BPFCapClose()
318 for (unsigned int i = 0; i < bpfData.size(); i++)
319 close(bpfData[i].fd);
322 //-----------------------------------------------------------------------------
323 int BPF_CAP::BPFCapRead(char * buffer, int blen, char ** capIface)
325 poll(&polld[0], polld.size(), -1);
327 for (unsigned int i = 0; i < polld.size(); i++)
329 if (polld[i].revents & POLLIN)
331 if (BPFCapRead(buffer, blen, capIface, &bpfData[i]))
333 polld[i].revents = 0;
336 polld[i].revents = 0;
342 //-----------------------------------------------------------------------------
343 int BPF_CAP::BPFCapRead(char * buffer, int blen, char **, BPF_DATA * bd)
347 bd->r = read(bd->fd, bd->buffer, BUFF_LEN);
350 logger("read error: %s", strerror(errno));
351 struct timespec ts = {0, 20000000};
352 nanosleep(&ts, NULL);
357 bd->bh = (struct bpf_hdr*)bd->p;
363 memcpy(buffer, (char*)(bd->p) + bd->bh->bh_hdrlen, blen);
365 bd->sum += BPF_WORDALIGN(bd->bh->bh_hdrlen + bd->bh->bh_caplen);
366 bd->p = bd->p + BPF_WORDALIGN(bd->bh->bh_hdrlen + bd->bh->bh_caplen);
367 bd->bh = (struct bpf_hdr*)bd->p;
378 //-----------------------------------------------------------------------------