Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(cli): add support for reading pcapng data from stdin using -r - #253

Merged
merged 1 commit into from
Feb 22, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,7 @@ Flags:
| -w *x.pcap* | ✅ | ✅ (without process info) |
| -w *-* | ✅ | ✅ |
| -r *x.pcapng*, -r *x.pcap* | ✅ | ✅ |
| -r *-* | ✅ | |
| -r *-* | ✅ | |
| --pid *process_id* | | ✅ |
| --pname *process_name* | | ✅ |
| --uid *user_id* | | ✅ |
Expand All @@ -343,7 +343,6 @@ Flags:
| --pod-name *pod_name.namespace* | | ✅ |
| -f, --follow-forks | | ✅ |
| -- *command [args]* | | ✅ |
| --oneline | | ✅ |
| --netns *path_to_net_ns* | | ✅ |
| --print | ✅ | ✅ |
| -c *count* | ✅ | ✅ |
Expand Down
3 changes: 1 addition & 2 deletions README.zh-CN.md
Original file line number Diff line number Diff line change
Expand Up @@ -337,15 +337,14 @@ Flags:
| -w *x.pcap* | ✅ | ✅ (without process info) |
| -w *-* | ✅ | ✅ |
| -r *x.pcapng*, -r *x.pcap* | ✅ | ✅ |
| -r *-* | ✅ | |
| -r *-* | ✅ | |
| --pid *process_id* | | ✅ |
| --pname *process_name* | | ✅ |
| --container-id *container_id* | | ✅ |
| --container-name *container_name* | | ✅ |
| --pod-name *pod_name.namespace* | | ✅ |
| -f, --follow-forks | | ✅ |
| -- *command [args]* | | ✅ |
| --oneline | | ✅ |
| --netns *path_to_net_ns* | | ✅ |
| --print | ✅ | ✅ |
| -c *count* | ✅ | ✅ |
Expand Down
45 changes: 39 additions & 6 deletions cmd/read.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ package cmd

import (
"context"
"errors"
"fmt"
"io"
"os"
Expand All @@ -10,28 +11,39 @@ import (
"github.com/mozillazg/ptcpdump/internal/log"
"github.com/mozillazg/ptcpdump/internal/metadata"
"github.com/mozillazg/ptcpdump/internal/parser"
"github.com/mozillazg/ptcpdump/internal/types"
"github.com/mozillazg/ptcpdump/internal/utils"
"github.com/mozillazg/ptcpdump/internal/writer"
)

func read(ctx context.Context, opts *Options) error {
fpath := opts.ReadPath()
log.Warnf("reading from file %s", fpath)

f, err := os.Open(fpath)
f, err := getReader(opts)
if err != nil {
return err
}
defer f.Close()
dataType, err := utils.DetectPcapDataType(f)
if err != nil {
return err
}

var p parser.Parser
pcache := metadata.NewProcessCache()
stdoutWriter := writer.NewStdoutWriter(opts.getStdout(), pcache)
opts.applyToStdoutWriter(stdoutWriter)

ext := filepath.Ext(fpath)
switch ext {
case extPcap:
pr, err := parser.NewPcapParser(f)
switch {
case ext == extPcap, dataType == types.PcapDataTypePcap:
r, ok, err := f.File()
if !ok {
if err != nil {
log.Infof("%v", err)
}
return errors.New("unsupported data source for the pcap format")
}
pr, err := parser.NewPcapParser(r)
if err != nil {
return err
}
Expand Down Expand Up @@ -68,3 +80,24 @@ func read(ctx context.Context, opts *Options) error {

return nil
}

func getReader(opts *Options) (*types.ReadBuffer, error) {
fpath := opts.ReadPath()
log.Warnf("reading from file %s", fpath)

var r *types.ReadBuffer

switch fpath {
case "-":
r = types.NewReadBuffer(io.NopCloser(os.Stdin))
break
default:
f, err := os.Open(fpath)
if err != nil {
return nil, err
}
r = types.NewReadBuffer(f)
}

return r, nil
}
14 changes: 14 additions & 0 deletions cmd/read_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,13 @@ func TestFormat(t *testing.T) {
},
expectedOutFile: "../testdata/format/tcp.pcapng.out.txt",
},
{
name: "pcapng file detect",
opts: &Options{
readFilePath: "../testdata/format/tcp.pcapng.unknown",
},
expectedOutFile: "../testdata/format/tcp.pcapng.out.txt",
},
{
name: "tcp -c",
opts: &Options{
Expand Down Expand Up @@ -117,6 +124,13 @@ func TestFormat(t *testing.T) {
},
expectedOutFile: "../testdata/format/udp.pcap.out.txt",
},
{
name: "pcap file detect",
opts: &Options{
readFilePath: "../testdata/format/udp.pcap.unknown",
},
expectedOutFile: "../testdata/format/udp.pcap.out.txt",
},
{
name: "udp dns",
opts: &Options{
Expand Down
43 changes: 43 additions & 0 deletions internal/types/io.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
package types

import (
"bufio"
"io"
"os"
)

func NewReadBuffer(r io.ReadCloser) *ReadBuffer {
return &ReadBuffer{
r: r,
buf: bufio.NewReader(r),
}
}

type ReadBuffer struct {
r io.Closer
buf *bufio.Reader
}

func (r *ReadBuffer) Read(p []byte) (int, error) {
return r.buf.Read(p)
}

func (r *ReadBuffer) Peek(n int) ([]byte, error) {
return r.buf.Peek(n)
}

func (r *ReadBuffer) Close() error {
return r.r.Close()
}

func (r *ReadBuffer) File() (*os.File, bool, error) {
f, ok := r.r.(*os.File)
if !ok {
return nil, false, nil
}
_, err := f.Seek(0, io.SeekStart)
if err != nil {
return nil, false, err
}
return f, true, nil
}
12 changes: 12 additions & 0 deletions internal/types/pcap.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
package types

type PcapDataType string

const (
PcapDataTypePcap PcapDataType = "pcap"
PcapDataTypePcapNg PcapDataType = "pcapng"

PcapMagicNumberForMicrosecond = 0xA1B2C3D4
PcapMagicNumberForNanosecond = 0xA1B23C4D
PcapNgMagicNumber = 0x0A0D0D0A
)
25 changes: 25 additions & 0 deletions internal/utils/pcap.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
package utils

import (
"encoding/binary"

"github.com/mozillazg/ptcpdump/internal/types"
)

func DetectPcapDataType(r *types.ReadBuffer) (types.PcapDataType, error) {
// read the first 4 bytes of the file
header, err := r.Peek(4)
if err != nil {
return "", err
}

magicNumber := binary.LittleEndian.Uint32(header)
switch magicNumber {
case types.PcapMagicNumberForMicrosecond, types.PcapMagicNumberForNanosecond:
return types.PcapDataTypePcap, nil
case types.PcapNgMagicNumber:
return types.PcapDataTypePcapNg, nil
}

return "", nil
}
Binary file added testdata/format/tcp.pcapng.unknown
Binary file not shown.
Binary file added testdata/format/udp.pcap.unknown
Binary file not shown.
3 changes: 3 additions & 0 deletions testdata/test_base.sh
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,9 @@ function test_ptcpdump_read() {
timeout 30s ${CMD} -v -r "${FNAME}" |tee "${RNAME}"
cat "${RNAME}" | grep '/usr/bin/curl'
cat "${RNAME}" | grep -F ' > 1.1.1.1.80: Flags [S],' # SYN

cat "${FNAME}" | ${CMD} -v -r - |grep '/usr/bin/curl'
cat "${FNAME}" | ${CMD} -v -r - |grep -F ' > 1.1.1.1.80: Flags [S],' # SYN
}

function main() {
Expand Down
Loading