-
Notifications
You must be signed in to change notification settings - Fork 13
/
packetdecoder.go
483 lines (440 loc) · 12.9 KB
/
packetdecoder.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
package sflow
import (
"encoding/binary"
"errors"
"fmt"
"io"
"github.com/circonus-labs/circonus-unified-agent/cua"
"github.com/circonus-labs/circonus-unified-agent/plugins/inputs/sflow/binaryio"
)
type PacketDecoder struct {
onPacket func(p *V5Format)
Log cua.Logger
}
func NewDecoder() *PacketDecoder {
return &PacketDecoder{}
}
func (d *PacketDecoder) debug(args ...interface{}) {
if d.Log != nil {
d.Log.Debug(args...)
}
}
func (d *PacketDecoder) OnPacket(f func(p *V5Format)) {
d.onPacket = f
}
func (d *PacketDecoder) Decode(r io.Reader) error {
var err error
var packet *V5Format
for err == nil {
packet, err = d.DecodeOnePacket(r)
if err != nil {
break
}
d.onPacket(packet)
}
if errors.Is(err, io.EOF) {
return nil
}
return err
}
type AddressType uint32 // must be uint32
const (
AddressTypeUnknown AddressType = 0
AddressTypeIPV4 AddressType = 1
AddressTypeIPV6 AddressType = 2
)
func (d *PacketDecoder) DecodeOnePacket(r io.Reader) (*V5Format, error) {
p := &V5Format{}
err := read(r, &p.Version, "version")
if err != nil {
return nil, err
}
if p.Version != 5 {
return nil, fmt.Errorf("Version %d not supported, only version 5", p.Version)
}
var addressIPType AddressType
if err = read(r, &addressIPType, "address ip type"); err != nil {
return nil, err
}
switch addressIPType {
case AddressTypeUnknown:
p.AgentAddress.IP = make([]byte, 0)
case AddressTypeIPV4:
p.AgentAddress.IP = make([]byte, 4)
case AddressTypeIPV6:
p.AgentAddress.IP = make([]byte, 16)
default:
return nil, fmt.Errorf("Unknown address IP type %d", addressIPType)
}
if err = read(r, &p.AgentAddress.IP, "Agent Address IP"); err != nil {
return nil, err
}
if err = read(r, &p.SubAgentID, "SubAgentID"); err != nil {
return nil, err
}
if err = read(r, &p.SequenceNumber, "SequenceNumber"); err != nil {
return nil, err
}
if err = read(r, &p.Uptime, "Uptime"); err != nil {
return nil, err
}
p.Samples, err = d.decodeSamples(r)
return p, err
}
func (d *PacketDecoder) decodeSamples(r io.Reader) ([]Sample, error) {
result := []Sample{}
// # of samples
var numOfSamples uint32
if err := read(r, &numOfSamples, "sample count"); err != nil {
return nil, err
}
for i := 0; i < int(numOfSamples); i++ {
sam, err := d.decodeSample(r)
if err != nil {
return result, err
}
result = append(result, sam)
}
return result, nil
}
func (d *PacketDecoder) decodeSample(r io.Reader) (Sample, error) {
var err error
sam := Sample{}
if err := read(r, &sam.SampleType, "SampleType"); err != nil {
return sam, err
}
sampleDataLen := uint32(0)
if err := read(r, &sampleDataLen, "Sample data length"); err != nil {
return sam, err
}
mr := binaryio.MinReader(r, int64(sampleDataLen))
defer mr.Close()
switch sam.SampleType {
case SampleTypeFlowSample:
sam.SampleData, err = d.decodeFlowSample(mr)
case SampleTypeFlowSampleExpanded:
sam.SampleData, err = d.decodeFlowSampleExpanded(mr)
default:
d.debug("Unknown sample type: ", sam.SampleType)
}
return sam, err
}
type InterfaceFormatType uint8 // sflow_version_5.txt line 1497
const (
InterfaceFormatTypeSingleInterface InterfaceFormatType = 0
InterfaceFormatTypePacketDiscarded InterfaceFormatType = 1
)
func (d *PacketDecoder) decodeFlowSample(r io.Reader) (t SampleDataFlowSampleExpanded, err error) {
if err := read(r, &t.SequenceNumber, "SequenceNumber"); err != nil {
return t, err
}
var sourceID uint32
if err := read(r, &sourceID, "SourceID"); err != nil { // source_id sflow_version_5.txt line: 1622
return t, err
}
// split source id to source id type and source id index
t.SourceIDIndex = sourceID & 0x00ffffff // sflow_version_5.txt line: 1468
t.SourceIDType = sourceID >> 24 // source_id_type sflow_version_5.txt Line 1465
if err := read(r, &t.SamplingRate, "SamplingRate"); err != nil {
return t, err
}
if err := read(r, &t.SamplePool, "SamplePool"); err != nil {
return t, err
}
if err := read(r, &t.Drops, "Drops"); err != nil { // sflow_version_5.txt line 1636
return t, err
}
if err := read(r, &t.InputIfIndex, "InputIfIndex"); err != nil {
return t, err
}
t.InputIfFormat = t.InputIfIndex >> 30
t.InputIfIndex &= 0x3FFFFFFF
if err := read(r, &t.OutputIfIndex, "OutputIfIndex"); err != nil {
return t, err
}
t.OutputIfFormat = t.OutputIfIndex >> 30
t.OutputIfIndex &= 0x3FFFFFFF
switch t.SourceIDIndex {
case t.OutputIfIndex:
t.SampleDirection = "egress"
case t.InputIfIndex:
t.SampleDirection = "ingress"
}
t.FlowRecords, err = d.decodeFlowRecords(r, t.SamplingRate)
return t, err
}
func (d *PacketDecoder) decodeFlowSampleExpanded(r io.Reader) (t SampleDataFlowSampleExpanded, err error) {
if err := read(r, &t.SequenceNumber, "SequenceNumber"); err != nil { // sflow_version_5.txt line 1701
return t, err
}
if err := read(r, &t.SourceIDType, "SourceIDType"); err != nil { // sflow_version_5.txt line: 1706 + 16878
return t, err
}
if err := read(r, &t.SourceIDIndex, "SourceIDIndex"); err != nil { // sflow_version_5.txt line: 1689
return t, err
}
if err := read(r, &t.SamplingRate, "SamplingRate"); err != nil { // sflow_version_5.txt line: 1707
return t, err
}
if err := read(r, &t.SamplePool, "SamplePool"); err != nil { // sflow_version_5.txt line: 1708
return t, err
}
if err := read(r, &t.Drops, "Drops"); err != nil { // sflow_version_5.txt line: 1712
return t, err
}
if err := read(r, &t.InputIfFormat, "InputIfFormat"); err != nil { // sflow_version_5.txt line: 1727
return t, err
}
if err := read(r, &t.InputIfIndex, "InputIfIndex"); err != nil {
return t, err
}
if err := read(r, &t.OutputIfFormat, "OutputIfFormat"); err != nil { // sflow_version_5.txt line: 1728
return t, err
}
if err := read(r, &t.OutputIfIndex, "OutputIfIndex"); err != nil {
return t, err
}
switch t.SourceIDIndex {
case t.OutputIfIndex:
t.SampleDirection = "egress"
case t.InputIfIndex:
t.SampleDirection = "ingress"
}
t.FlowRecords, err = d.decodeFlowRecords(r, t.SamplingRate)
return t, err
}
func (d *PacketDecoder) decodeFlowRecords(r io.Reader, samplingRate uint32) (recs []FlowRecord, err error) {
var flowDataLen uint32
var count uint32
if err := read(r, &count, "FlowRecord count"); err != nil {
return recs, err
}
for i := uint32(0); i < count; i++ {
fr := FlowRecord{}
if err := read(r, &fr.FlowFormat, "FlowFormat"); err != nil { // sflow_version_5.txt line 1597
return recs, err
}
if err := read(r, &flowDataLen, "Flow data length"); err != nil {
return recs, err
}
mr := binaryio.MinReader(r, int64(flowDataLen))
switch fr.FlowFormat {
case FlowFormatTypeRawPacketHeader: // sflow_version_5.txt line 1938
fr.FlowData, err = d.decodeRawPacketHeaderFlowData(mr, samplingRate)
default:
d.debug("Unknown flow format: ", fr.FlowFormat)
}
if err != nil {
mr.Close()
return recs, err
}
recs = append(recs, fr)
mr.Close()
}
return recs, err
}
func (d *PacketDecoder) decodeRawPacketHeaderFlowData(r io.Reader, samplingRate uint32) (h RawPacketHeaderFlowData, err error) {
if err := read(r, &h.HeaderProtocol, "HeaderProtocol"); err != nil { // sflow_version_5.txt line 1940
return h, err
}
if err := read(r, &h.FrameLength, "FrameLength"); err != nil { // sflow_version_5.txt line 1942
return h, err
}
h.Bytes = h.FrameLength * samplingRate
if err := read(r, &h.StrippedOctets, "StrippedOctets"); err != nil { // sflow_version_5.txt line 1967
return h, err
}
if err := read(r, &h.HeaderLength, "HeaderLength"); err != nil {
return h, err
}
mr := binaryio.MinReader(r, int64(h.HeaderLength))
defer mr.Close()
switch h.HeaderProtocol {
case HeaderProtocolTypeEthernetISO88023:
h.Header, err = d.decodeEthHeader(mr)
default:
d.debug("Unknown header protocol type: ", h.HeaderProtocol)
}
return h, err
}
// ethHeader answers a decode Directive that will decode an ethernet frame header
// according to https://en.wikipedia.org/wiki/Ethernet_frame
func (d *PacketDecoder) decodeEthHeader(r io.Reader) (h EthHeader, err error) {
// we may have to read out StrippedOctets bytes and throw them away first?
if err := read(r, &h.DestinationMAC, "DestinationMAC"); err != nil {
return h, err
}
if err := read(r, &h.SourceMAC, "SourceMAC"); err != nil {
return h, err
}
var tagOrEType uint16
if err := read(r, &tagOrEType, "tagOrEtype"); err != nil {
return h, err
}
switch tagOrEType {
case 0x8100: // could be?
var discard uint16
if err := read(r, &discard, "unknown"); err != nil {
return h, err
}
if err := read(r, &h.EtherTypeCode, "EtherTypeCode"); err != nil {
return h, err
}
default:
h.EtherTypeCode = tagOrEType
}
h.EtherType = ETypeMap[h.EtherTypeCode]
switch h.EtherType {
case "IPv4":
h.IPHeader, err = d.decodeIPv4Header(r)
case "IPv6":
h.IPHeader, err = d.decodeIPv6Header(r)
default:
}
if err != nil {
return h, err
}
return h, err
}
// https://en.wikipedia.org/wiki/IPv4#Header
func (d *PacketDecoder) decodeIPv4Header(r io.Reader) (h IPV4Header, err error) {
if err := read(r, &h.Version, "Version"); err != nil {
return h, err
}
h.InternetHeaderLength = h.Version & 0x0F
h.Version &= 0xF0
if err := read(r, &h.DSCP, "DSCP"); err != nil {
return h, err
}
h.ECN = h.DSCP & 0x03
h.DSCP >>= 2
if err := read(r, &h.TotalLength, "TotalLength"); err != nil {
return h, err
}
if err := read(r, &h.Identification, "Identification"); err != nil {
return h, err
}
if err := read(r, &h.FragmentOffset, "FragmentOffset"); err != nil {
return h, err
}
h.Flags = uint8(h.FragmentOffset >> 13)
h.FragmentOffset &= 0x1FFF
if err := read(r, &h.TTL, "TTL"); err != nil {
return h, err
}
if err := read(r, &h.Protocol, "Protocol"); err != nil {
return h, err
}
if err := read(r, &h.HeaderChecksum, "HeaderChecksum"); err != nil {
return h, err
}
if err := read(r, &h.SourceIP, "SourceIP"); err != nil {
return h, err
}
if err := read(r, &h.DestIP, "DestIP"); err != nil {
return h, err
}
switch h.Protocol {
case IPProtocolTCP:
h.ProtocolHeader, err = d.decodeTCPHeader(r)
case IPProtocolUDP:
h.ProtocolHeader, err = d.decodeUDPHeader(r)
default:
d.debug("Unknown IP protocol: ", h.Protocol)
}
return h, err
}
// https://en.wikipedia.org/wiki/IPv6_packet
func (d *PacketDecoder) decodeIPv6Header(r io.Reader) (h IPV6Header, err error) {
var fourByteBlock uint32
if err := read(r, &fourByteBlock, "IPv6 header octet 0"); err != nil {
return h, err
}
version := fourByteBlock >> 28
if version != 0x6 {
return h, fmt.Errorf("Unexpected IPv6 header version 0x%x", version)
}
h.DSCP = uint8((fourByteBlock & 0xFC00000) >> 22)
h.ECN = uint8((fourByteBlock & 0x300000) >> 20)
// flowLabel := fourByteBlock & 0xFFFFF // not currently being used.
if err := read(r, &h.PayloadLength, "PayloadLength"); err != nil {
return h, err
}
if err := read(r, &h.NextHeaderProto, "NextHeaderProto"); err != nil {
return h, err
}
if err := read(r, &h.HopLimit, "HopLimit"); err != nil {
return h, err
}
if err := read(r, &h.SourceIP, "SourceIP"); err != nil {
return h, err
}
if err := read(r, &h.DestIP, "DestIP"); err != nil {
return h, err
}
switch h.NextHeaderProto {
case IPProtocolTCP:
h.ProtocolHeader, err = d.decodeTCPHeader(r)
case IPProtocolUDP:
h.ProtocolHeader, err = d.decodeUDPHeader(r)
default:
// not handled
d.debug("Unknown IP protocol: ", h.NextHeaderProto)
}
return h, err
}
// https://en.wikipedia.org/wiki/Transmission_Control_Protocol#TCP_segment_structure
func (d *PacketDecoder) decodeTCPHeader(r io.Reader) (h TCPHeader, err error) {
if err := read(r, &h.SourcePort, "SourcePort"); err != nil {
return h, err
}
if err := read(r, &h.DestinationPort, "DestinationPort"); err != nil {
return h, err
}
if err := read(r, &h.Sequence, "Sequence"); err != nil {
return h, err
}
if err := read(r, &h.AckNumber, "AckNumber"); err != nil {
return h, err
}
// Next up: bit reading!
// data offset 4 bits
// reserved 3 bits
// flags 9 bits
var dataOffsetAndReservedAndFlags uint16
if err := read(r, &dataOffsetAndReservedAndFlags, "TCP Header Octet offset 12"); err != nil {
return h, err
}
h.TCPHeaderLength = uint8((dataOffsetAndReservedAndFlags >> 12) * 4)
h.Flags = dataOffsetAndReservedAndFlags & 0x1FF
// done bit reading
if err := read(r, &h.TCPWindowSize, "TCPWindowSize"); err != nil {
return h, err
}
if err := read(r, &h.Checksum, "Checksum"); err != nil {
return h, err
}
if err := read(r, &h.TCPUrgentPointer, "TCPUrgentPointer"); err != nil {
return h, err
}
return h, err
}
func (d *PacketDecoder) decodeUDPHeader(r io.Reader) (h UDPHeader, err error) {
if err := read(r, &h.SourcePort, "SourcePort"); err != nil {
return h, err
}
if err := read(r, &h.DestinationPort, "DestinationPort"); err != nil {
return h, err
}
if err := read(r, &h.UDPLength, "UDPLength"); err != nil {
return h, err
}
if err := read(r, &h.Checksum, "Checksum"); err != nil {
return h, err
}
return h, err
}
func read(r io.Reader, data interface{}, name string) error {
err := binary.Read(r, binary.BigEndian, data)
return fmt.Errorf("failed to read %s: %w", name, err)
}