ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
pcap.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4/**
5 * @file pcap.h
6 * @brief libpcap file framing - the classic global + per-record headers, link-type agnostic.
7 *
8 * One owner for the PCAP framing shared by every capture feature (Wi-Fi promiscuous capture,
9 * CAN / bus listen-only capture, ...): each writes its frames with the matching DLT link type so
10 * the forwarded stream is a valid `.pcap` a wired Wireshark / tcpdump opens directly. Header-only
11 * and pure (little-endian byte writes, no heap, no stdlib), host-identical.
12 *
13 * @author Douglas Quigg (dstroy0)
14 * @date 2026
15 */
16
17#ifndef PROTOCORE_PCAP_H
18#define PROTOCORE_PCAP_H
19
20#include "endian/endian.h" // parva_extremitas.wr - libpcap headers are little-endian
21
22#include "protocore_config.h" // the entry point: protocore_types.h for the widths
23
24/** @brief libpcap header sizes. */
25#define PROTOCORE_PCAP_GLOBAL_HDR_LEN 24
26#define PROTOCORE_PCAP_REC_HDR_LEN 16
27
28/** @brief Common libpcap DLT link-layer types. */
29#define PROTOCORE_DLT_IEEE802_11 105 ///< raw 802.11 (Wi-Fi promiscuous capture)
30#define PROTOCORE_DLT_CAN_SOCKETCAN 227 ///< Linux SocketCAN classic/FD frames
31#define PROTOCORE_DLT_ETHERNET 1 ///< IEEE 802.3 Ethernet
32#define PROTOCORE_DLT_IEEE802_15_4_NOFCS 230 ///< raw 802.15.4 MAC frame, no FCS
33#define PROTOCORE_DLT_IEEE802_15_4_TAP 283 ///< 802.15.4 with a TAP pseudo-header (RSSI / channel TLVs)
34#define PROTOCORE_DLT_RAW 101 ///< the record starts at the IP header, with no link layer
35
36/** @brief Where a header is written, and the link type the file declares. */
37typedef struct
38{
39 uint8_t *out; ///< where the header lands
40 size_t cap; ///< how much room it has
41 uint32_t linktype; ///< the DLT_* link type of the frames that follow
42} PcapArgs;
43
44/** @brief What one captured frame's record header states. */
45typedef struct
46{
47 uint32_t ts_sec; ///< capture time, whole seconds
48 uint32_t ts_usec; ///< and microseconds within that second
49 uint32_t caplen; ///< octets actually stored
50 uint32_t origlen; ///< octets the frame had on the wire
52
53/**
54 * @brief The two libpcap headers a capture file is built from.
55 *
56 * @var PcapNs::args where a header is written, and the link type the file declares
57 * @var PcapNs::rec what one captured frame's record header states
58 * @var PcapNs::n octets written, or 0 when the buffer is too small
59 * @var PcapNs::global_header the 24-byte file header (little-endian, microsecond timestamps)
60 * @var PcapNs::record_header the 16-byte per-frame header
61 *
62 * No storage member: both headers are written into the caller's buffer.
63 */
64typedef struct
65{
68 size_t n;
69} PcapVars;
70
71/** @brief The operands and the outcome. */
72extern PcapVars PcapV;
73
74/** @brief The entries. */
75typedef struct
76{
77 void (*const global_header)(uint8_t *work);
78 void (*const record_header)(uint8_t *work);
79} PcapNs;
80
81// What the table binds, defined once in the .c and taking one parameter each: everything
82// else an entry needs is an operand in PcapV or a region of the borrow at a fixed offset.
83void protocore_pcap_global_header(uint8_t *work);
84void protocore_pcap_record_header(uint8_t *work);
85
86// `static const`, initialised HERE rather than `extern` against a definition in the .c: a
87// const object whose initializer every translation unit can see is a COMPILE-TIME FACT, so
88// `Pcap.global_header(work)` resolves to a named function and becomes a DIRECT call. An extern table
89// leaves the call indirect and the symbol live at every level, -O2 -flto included.
90static const PcapNs Pcap __attribute__((unused)) = {
92 .record_header = protocore_pcap_record_header,
93};
94
95#endif // PROTOCORE_PCAP_H
void protocore_pcap_global_header(uint8_t *work)
void protocore_pcap_record_header(uint8_t *work)
PcapVars PcapV
The operands and the outcome.
Where a header is written, and the link type the file declares.
Definition pcap.h:38
uint32_t linktype
the DLT_* link type of the frames that follow
Definition pcap.h:41
size_t cap
how much room it has
Definition pcap.h:40
uint8_t * out
where the header lands
Definition pcap.h:39
The entries.
Definition pcap.h:76
void(*const global_header)(uint8_t *work)
Definition pcap.h:77
What one captured frame's record header states.
Definition pcap.h:46
uint32_t origlen
octets the frame had on the wire
Definition pcap.h:50
uint32_t ts_sec
capture time, whole seconds
Definition pcap.h:47
uint32_t ts_usec
and microseconds within that second
Definition pcap.h:48
uint32_t caplen
octets actually stored
Definition pcap.h:49
PcapArgs args
Definition pcap.h:66
size_t n
Definition pcap.h:68
PcapRecArgs rec
Definition pcap.h:67