Skip to content
  • Peter Wu's avatar
    wiretap: add read/write support for Decryption Secrets Block (DSB) · 52a66714
    Peter Wu authored and AndersBroman's avatar AndersBroman committed
    Support reading and writing pcapng files with DSBs. A DSB may occur
    multiple times but should appear before packets that need those
    decryption secrets (so it cannot be moved to the end like NRB). The TLS
    dissector will be updated in the future to make use of these secrets.
    pcapng spec update: https://github.com/pcapng/pcapng/pull/54
    
    As DSBs may be interleaved with packets, do not even try to read it in
    pcapng_open (as is done for IDBs). Instead process them during the
    sequential read, appending them to the 'wtap::dsbs' array.
    
    Writing is more complicated, secrets may initially not be available when
    'wtap_dumper' is created. As they may become available in 'wtap::dsbs'
    as more packets are read, allow 'wtap_dumper::dsbs_growing' to reference
    this array. This saves every user from checking/dumping DSBs.
    
    If the wtap user needs to insert extra DSBs (while preserving existing
    DSBs), they can set the 'wtap_dumper::dsbs_initial' field.
    
    The test file was creating using a patched editcap (future patch) and
    combined using mergecap (which required a change to preserve the DSBs).
    
    Change-Id: I74e4ee3171bd852a89ea0f6fbae9e0f65ed6eda9
    Ping-Bug: 15252
    Reviewed-on: https://code.wireshark.org/review/30692
    
    
    Reviewed-by: default avatarPeter Wu <peter@lekensteyn.nl>
    Petri-Dish: Peter Wu <peter@lekensteyn.nl>
    Tested-by: Petri Dish Buildbot
    Reviewed-by: default avatarAnders Broman <a.broman58@gmail.com>
    52a66714