286 return "ATM RFC1483";
292 return "IEEE 802.11";
294 return "Frame Relay";
296 return "OpenBSD Loopback";
304 return "IEEE 802.11 Prism";
306 return "IP over Fibre Channel";
310 return "IEEE 802.11 Radiotap";
312 return "ARCNET Linux";
314 return "Apple IP over IEEE 1394";
316 return "MTP2 with PHDR";
362 return "IEEE 802.11 AVS";
364 return "BACnet MS/TP";
376 return "Bluetooth HCI H4";
382 return "IEEE 802.15.4";
388 return "Bluetooth HCI H4 with PHDR";
394 return "PPP with Direction";
396 return "Cisco HDLC with Direction";
398 return "Frame Relay with Direction";
402 return "IEEE 802.15.4 NONASK PHY";
404 return "USB Linux MMAPPED";
406 return "Fibre Channel FC-2";
408 return "Fibre Channel FC-2 with Frame Delimiters";
410 return "Solaris IPNET";
412 return "CAN SocketCAN";
418 return "IEEE 802.15.4 without FCS";
426 return "STANAG 5066 D-PDU";
430 return "netANALYZER";
432 return "netANALYZER Transparent";
434 return "IP over InfiniBand";
436 return "MPEG-2 Transport Stream";
448 return "RTAC Serial";
450 return "Bluetooth LE LL";
454 return "Bluetooth Linux Monitor";
456 return "Bluetooth BR/EDR Baseband";
458 return "Bluetooth LE LL with PHDR";
460 return "PROFIBUS DL";
468 return "Z-Wave R1/R2";
472 return "WattStopper DLM";
481 throw std::invalid_argument(
"Unknown link type");
486 #define PCPP_MAX_PACKET_SIZE 65536
514 RawPacketImplType getRawPacketImplementationType(
RawPacket const& rawPacket);
526 uint8_t* m_RawData =
nullptr;
527 int m_RawDataLen = 0;
528 int m_FrameLength = 0;
529 timespec m_TimeStamp{};
530 bool m_OwnsRawData =
false;
531 bool m_RawPacketSet =
false;
534 void copyDataFrom(
const RawPacket& other,
bool allocateData =
true);
556 RawPacket(
const uint8_t* pRawData,
int rawDataLen, timeval timestamp,
bool takeOwnership,
569 RawPacket(
const uint8_t* pRawData,
int rawDataLen, timespec timestamp,
bool takeOwnership,
615 PCPP_DEPRECATED(
"Use the overload that takes bool takeOwnership parameter for explicit control.")
616 bool
setRawData(const uint8_t* pRawData,
int rawDataLen, timeval timestamp,
636 bool setRawData(const uint8_t* pRawData,
int rawDataLen,
bool takeOwnership, timeval timestamp,
654 PCPP_DEPRECATED("Use the overload that takes
bool takeOwnership parameter for explicit control.")
655 bool setRawData(const uint8_t* pRawData,
int rawDataLen, timespec timestamp,
675 bool setRawData(const uint8_t* pRawData,
int rawDataLen,
bool takeOwnership, timespec timestamp,
702 return m_LinkLayerType;
721 return m_FrameLength;
746 return m_RawPacketSet;
759 virtual void appendData(
const uint8_t* dataToAppend,
size_t dataToAppendLen);
768 virtual void insertData(
int atIndex,
const uint8_t* dataToInsert,
size_t dataToInsertLen);
776 virtual bool removeData(
int atIndex,
size_t numOfBytesToRemove);
792 return internal::RawPacketImplType::Standard;
796 virtual bool doSetRawData(
const uint8_t* pRawData,
int rawDataLen,
bool takeOwnership, timespec timestamp,
RawPacketImplType getRawPacketImplementationType(RawPacket const &rawPacket)
Get the concrete implementation type of a RawPacket instance.
Definition: RawPacket.h:802
RawPacketImplType
Type of RawPacket implementation.
Definition: RawPacket.h:499
@ WinDivert
WinDivert based RawPacket.
@ DpdkMBuf
DPDK MBuf based RawPacket.
@ Standard
Standard RawPacket.
Definition: RawPacket.h:522
virtual internal::RawPacketImplType getImplType() const
Get the type of RawPacket implementation.
Definition: RawPacket.h:790
const uint8_t * getRawData() const
Definition: RawPacket.h:693
int getRawDataLen() const
Definition: RawPacket.h:712
int getFrameLength() const
Definition: RawPacket.h:719
static bool isLinkTypeValid(int linkTypeValue)
RawPacket(const uint8_t *pRawData, int rawDataLen, timeval timestamp, bool takeOwnership, LinkLayerType layerType=LINKTYPE_ETHERNET)
virtual void insertData(int atIndex, const uint8_t *dataToInsert, size_t dataToInsertLen)
RawPacket(const RawPacket &other)
bool setRawData(const uint8_t *pRawData, int rawDataLen, timeval timestamp, LinkLayerType layerType=LINKTYPE_ETHERNET, int frameLength=-1)
timespec getPacketTimeStamp() const
Definition: RawPacket.h:725
virtual void appendData(const uint8_t *dataToAppend, size_t dataToAppendLen)
bool initWithRawData(const uint8_t *pRawData, int rawDataLen, timespec timestamp, LinkLayerType layerType=LINKTYPE_ETHERNET)
virtual uint8_t getObjectType() const
Definition: RawPacket.h:595
virtual bool removeData(int atIndex, size_t numOfBytesToRemove)
virtual ~RawPacket()
A destructor for this class. Frees the raw data if takeOwnership was set to 'true'.
RawPacket(const uint8_t *pRawData, int rawDataLen, timespec timestamp, bool takeOwnership, LinkLayerType layerType=LINKTYPE_ETHERNET)
virtual bool reallocateData(size_t newBufferLength)
bool isPacketSet() const
Definition: RawPacket.h:744
LinkLayerType getLinkLayerType() const
Definition: RawPacket.h:700
virtual bool setPacketTimeStamp(timespec timestamp)
virtual bool setPacketTimeStamp(timeval timestamp)
virtual RawPacket * clone() const
Clones the current packet. Caller is responsible for deallocation of the memory.
RawPacket & operator=(const RawPacket &other)
The main namespace for the PcapPlusPlus lib.
Definition: AssertionUtils.h:19
@ PCPP_DEPRECATED
Deprecated typo, use OsiModelSessionLayer instead.
Definition: ProtocolType.h:432
LinkLayerType
An enum describing all known link layer type. Taken from: http://www.tcpdump.org/linktypes....
Definition: RawPacket.h:23
@ LINKTYPE_NG40
Definition: RawPacket.h:207
@ LINKTYPE_PPI
Per-Packet Information information.
Definition: RawPacket.h:142
@ LINKTYPE_GPF_T
Transparent-mapped generic framing procedure.
Definition: RawPacket.h:132
@ LINKTYPE_USBPCAP
USB packets, beginning with a USBPcap header.
Definition: RawPacket.h:216
@ LINKTYPE_LOOP
OpenBSD loopback encapsulation.
Definition: RawPacket.h:59
@ LINKTYPE_BLUETOOTH_LE_LL
Bluetooth Low Energy air interface Link Layer packets.
Definition: RawPacket.h:220
@ LINKTYPE_USER15
Reserved for private use.
Definition: RawPacket.h:121
@ LINKTYPE_BLUETOOTH_LE_LL_WITH_PHDR
Bluetooth Low Energy link-layer packets.
Definition: RawPacket.h:228
@ LINKTYPE_IEEE802_15_4
IEEE 802.15.4 wireless Personal Area Network.
Definition: RawPacket.h:144
@ LINKTYPE_BLUETOOTH_BREDR_BB
Bluetooth Basic Rate and Enhanced Data Rate baseband packets.
Definition: RawPacket.h:226
@ LINKTYPE_ARCNET_BSD
ARCNET Data Packets.
Definition: RawPacket.h:33
@ LINKTYPE_USER2
Reserved for private use.
Definition: RawPacket.h:95
@ LINKTYPE_RAW
Raw IP.
Definition: RawPacket.h:51
@ LINKTYPE_MTP3
Signaling System 7 Message Transfer Part Level 3.
Definition: RawPacket.h:83
@ LINKTYPE_MTP2_WITH_PHDR
Signaling System 7 Message Transfer Part Level 2.
Definition: RawPacket.h:79
@ LINKTYPE_INVALID
Set if interface ID for a packet of a pcapng file is too high.
Definition: RawPacket.h:251
@ LINKTYPE_PROFIBUS_DL
PROFIBUS data link layer packets, as specified by IEC standard 61158-6-3.
Definition: RawPacket.h:230
@ LINKTYPE_LINUX_SLL
Linux "cooked" capture encapsulation.
Definition: RawPacket.h:61
@ LINKTYPE_SLIP
SLIP, encapsulated with a LINKTYPE_SLIP header.
Definition: RawPacket.h:35
@ LINKTYPE_LINUX_SLL2
Linux "cooked" capture encapsulation v2.
Definition: RawPacket.h:249
@ LINKTYPE_BACNET_MS_TP
BACnet MS/TP frames.
Definition: RawPacket.h:125
@ LINKTYPE_IPMI_HPM_2
IPMI trace packets, as specified by Table 3-20 "Trace Data Block Format" in the PICMG HPM....
Definition: RawPacket.h:236
@ LINKTYPE_USER7
Reserved for private use.
Definition: RawPacket.h:105
@ LINKTYPE_DOCSIS
Signaling System 7 Signalling Connection Control Part.
Definition: RawPacket.h:87
@ LINKTYPE_SCTP
SCTP packets, as defined by RFC 4960, with no lower-level protocols such as IPv4 or IPv6.
Definition: RawPacket.h:214
@ LINKTYPE_IP_OVER_FC
RFC 2625 IP-over-Fibre Channel.
Definition: RawPacket.h:69
@ LINKTYPE_BLUETOOTH_LINUX_MONITOR
Bluetooth Linux Monitor encapsulation of traffic for the BlueZ stack.
Definition: RawPacket.h:224
@ LINKTYPE_ATM_RFC1483
RFC 1483 LLC/SNAP-encapsulated ATM.
Definition: RawPacket.h:49
@ LINKTYPE_USER8
Reserved for private use.
Definition: RawPacket.h:107
@ LINKTYPE_MPEG_2_TS
MPEG-2 Transport Stream transport packets, as specified by ISO 13818-1/ITU-T Recommendation H....
Definition: RawPacket.h:204
@ LINKTYPE_FRELAY
Frame Relay.
Definition: RawPacket.h:57
@ LINKTYPE_PPP_WITH_DIR
Definition: RawPacket.h:157
@ LINKTYPE_GPRS_LLC
General Packet Radio Service Logical Link Control.
Definition: RawPacket.h:130
@ LINKTYPE_IEEE802_11_PRISM
Prism monitor mode information followed by an 802.11 header.
Definition: RawPacket.h:67
@ LINKTYPE_AX25
AX.25 packet.
Definition: RawPacket.h:29
@ LINKTYPE_EPON
Ethernet-over-passive-optical-network packets.
Definition: RawPacket.h:234
@ LINKTYPE_ETHERNET
IEEE 802.3 Ethernet.
Definition: RawPacket.h:27
@ LINKTYPE_NULL
BSD loopback encapsulation.
Definition: RawPacket.h:25
@ LINKTYPE_IEEE802_5
IEEE 802.5 Token Ring.
Definition: RawPacket.h:31
@ LINKTYPE_SITA
Various link-layer types, with a pseudo-header, for SITA.
Definition: RawPacket.h:146
@ LINKTYPE_SUNATM
ATM traffic, encapsulated as per the scheme used by SunATM devices.
Definition: RawPacket.h:71
@ LINKTYPE_IEEE802_11_RADIOTAP
Radiotap link-layer information followed by an 802.11 header.
Definition: RawPacket.h:73
@ LINKTYPE_USB_LINUX_MMAPPED
USB packets, beginning with a Linux USB header.
Definition: RawPacket.h:167
@ LINKTYPE_C_HDLC
Cisco PPP with HDLC framing.
Definition: RawPacket.h:53
@ LINKTYPE_USER12
Reserved for private use.
Definition: RawPacket.h:115
@ LINKTYPE_BLUETOOTH_HCI_H4
Bluetooth HCI UART transport layer.
Definition: RawPacket.h:138
@ LINKTYPE_RTAC_SERIAL
Serial-line packet header for the Schweitzer Engineering Laboratories "RTAC" product.
Definition: RawPacket.h:218
@ LINKTYPE_NFLOG
Linux netlink NETLINK NFLOG socket log messages.
Definition: RawPacket.h:194
@ LINKTYPE_ARCNET_LINUX
ARCNET Data Packets, as described by the ARCNET Trade Association standard ATA 878....
Definition: RawPacket.h:75
@ LINKTYPE_FC_2_WITH_FRAME_DELIMS
Fibre Channel FC-2 frames.
Definition: RawPacket.h:171
@ LINKTYPE_PFLOG
OpenBSD pflog.
Definition: RawPacket.h:65
@ LINKTYPE_FDDI
FDDI, as specified by ANSI INCITS 239-1994.
Definition: RawPacket.h:39
@ LINKTYPE_ERF
Various link-layer types, with a pseudo-header, for Endace DAG cards; encapsulates Endace ERF record.
Definition: RawPacket.h:148
@ LINKTYPE_USER5
Reserved for private use.
Definition: RawPacket.h:101
@ LINKTYPE_DLT_RAW2
Raw IP (OpenBSD)
Definition: RawPacket.h:43
@ LINKTYPE_AX25_KISS
AX.25 packet, with a 1-byte KISS header containing a type indicator.
Definition: RawPacket.h:152
@ LINKTYPE_USER13
Reserved for private use.
Definition: RawPacket.h:117
@ LINKTYPE_LINUX_IRDA
Linux-IrDA packets.
Definition: RawPacket.h:89
@ LINKTYPE_USER10
Reserved for private use.
Definition: RawPacket.h:111
@ LINKTYPE_IEEE802_15_4_NOFCS
IEEE 802.15.4 wireless Personal Area Network, without the FCS at the end of the frame.
Definition: RawPacket.h:181
@ LINKTYPE_ZWAVE_R1_R2
Per Joshua Wright jwright@hasborg.com, formats for Z-Wave RF profiles R1 and R2 captures.
Definition: RawPacket.h:238
@ LINKTYPE_FRELAY_WITH_DIR
Frame Relay.
Definition: RawPacket.h:161
@ LINKTYPE_PPP_PPPD
Definition: RawPacket.h:128
@ LINKTYPE_ZWAVE_R3
Per Joshua Wright jwright@hasborg.com, formats for Z-Wave RF profile R3 captures.
Definition: RawPacket.h:240
@ LINKTYPE_C_HDLC_WITH_DIR
Cisco PPP with HDLC framing.
Definition: RawPacket.h:159
@ LINKTYPE_APPLE_IP_OVER_IEEE1394
Apple IP-over-IEEE 1394 cooked header.
Definition: RawPacket.h:77
@ LINKTYPE_IEEE802_11
IEEE 802.11 wireless LAN.
Definition: RawPacket.h:55
@ LINKTYPE_PKTAP
Apple PKTAP capture encapsulation.
Definition: RawPacket.h:232
@ LINKTYPE_NETLINK
Linux Netlink capture encapsulation.
Definition: RawPacket.h:222
@ LINKTYPE_IPNET
Solaris ipnet pseudo-header.
Definition: RawPacket.h:173
@ LINKTYPE_IPOIB
IP-over-InfiniBand, as specified by RFC 4391 section 6.
Definition: RawPacket.h:202
@ LINKTYPE_USB_LINUX
USB packets, beginning with a Linux USB header.
Definition: RawPacket.h:140
@ LINKTYPE_USER6
Reserved for private use.
Definition: RawPacket.h:103
@ LINKTYPE_LINUX_LAPD
Link Access Procedures on the D Channel (LAPD) frames.
Definition: RawPacket.h:136
@ LINKTYPE_FC_2
Fibre Channel FC-2 frames, beginning with a Frame_Header.
Definition: RawPacket.h:169
@ LINKTYPE_INFINIBAND
Raw InfiniBand frames, starting with the Local Routing Header.
Definition: RawPacket.h:212
@ LINKTYPE_LAPD
Link Access Procedures on the D Channel (LAPD) frames.
Definition: RawPacket.h:154
@ LINKTYPE_DLT_RAW1
Raw IP.
Definition: RawPacket.h:41
@ LINKTYPE_USER4
Reserved for private use.
Definition: RawPacket.h:99
@ LINKTYPE_IPV4
Raw IPv4; the packet begins with an IPv4 header.
Definition: RawPacket.h:177
@ LINKTYPE_BLUETOOTH_HCI_H4_WITH_PHDR
Bluetooth HCI UART transport layer.
Definition: RawPacket.h:150
@ LINKTYPE_USER14
Reserved for private use.
Definition: RawPacket.h:119
@ LINKTYPE_IEEE802_15_4_NONASK_PHY
IEEE 802.15.4 wireless Personal Area Network.
Definition: RawPacket.h:165
@ LINKTYPE_NFC_LLCP
Definition: RawPacket.h:210
@ LINKTYPE_USER9
Reserved for private use.
Definition: RawPacket.h:109
@ LINKTYPE_DVB_CI
Definition: RawPacket.h:187
@ LINKTYPE_DBUS
Definition: RawPacket.h:184
@ LINKTYPE_STANAG_5066_D_PDU
Definition: RawPacket.h:192
@ LINKTYPE_GPF_F
Frame-mapped generic framing procedure.
Definition: RawPacket.h:134
@ LINKTYPE_SCCP
Signaling System 7 Signalling Connection Control Part.
Definition: RawPacket.h:85
@ LINKTYPE_MUX27010
Variant of 3GPP TS 27.010 multiplexing protocol (similar to, but not the same as, 27....
Definition: RawPacket.h:189
@ LINKTYPE_USER11
Reserved for private use.
Definition: RawPacket.h:113
@ LINKTYPE_NETANALYZER_TRANSPARENT
Definition: RawPacket.h:200
@ LINKTYPE_WATTSTOPPER_DLM
Definition: RawPacket.h:243
@ LINKTYPE_IEEE802_11_AVS
AVS monitor mode information followed by an 802.11 header.
Definition: RawPacket.h:123
@ LINKTYPE_USER3
Reserved for private use.
Definition: RawPacket.h:97
@ LINKTYPE_USER1
Reserved for private use.
Definition: RawPacket.h:93
@ LINKTYPE_CAN_SOCKETCAN
CAN (Controller Area Network) frames, with a pseudo-header as supplied by Linux SocketCAN.
Definition: RawPacket.h:175
@ LINKTYPE_PPP
PPP, as per RFC 1661 and RFC 1662.
Definition: RawPacket.h:37
@ LINKTYPE_ISO_14443
Definition: RawPacket.h:247
@ LINKTYPE_MTP2
Signaling System 7 Message Transfer Part Level 2.
Definition: RawPacket.h:81
@ LINKTYPE_PPP_HDLC
PPP in HDLC-like framing, as per RFC 1662, or Cisco PPP with HDLC framing, as per section 4....
Definition: RawPacket.h:45
@ LINKTYPE_LTALK
Apple LocalTalk.
Definition: RawPacket.h:63
@ LINKTYPE_PPP_ETHER
PPPoE.
Definition: RawPacket.h:47
@ LINKTYPE_USER0
Reserved for private use.
Definition: RawPacket.h:91
@ LINKTYPE_IPMB_LINUX
IPMB over an I2C circuit.
Definition: RawPacket.h:163
@ LINKTYPE_IPV6
Raw IPv6; the packet begins with an IPv6 header.
Definition: RawPacket.h:179
@ LINKTYPE_NETANALYZER
Definition: RawPacket.h:197
constexpr const char * linkLayerToString(LinkLayerType linkLayer)
Definition: RawPacket.h:257
@ Unknown
Unknown ARP message type.