D.9.áidl2wrs: Creating dissectors from CORBA IDL files

In an ideal world idl2wrs would be mentioned in the users guide in passing and documented in the developers guide. As the developers guide has not yet been completed it will be documented here.

D.9.1.áWhat is it?

As you have probably guessed from the name, idl2wrs takes a user specified IDL file and attempts to build a dissector that can decode the IDL traffic over GIOP. The resulting file is "C" code, that should compile okay as a Wireshark dissector.

idl2wrs basically parses the data struct given to it by the omniidl compiler, and using the GIOP API available in packet-giop.[ch], generates get_CDR_xxx calls to decode the CORBA traffic on the wire.

It consists of 4 main files.

README.idl2wrs

This document

wireshark_be.py

The main compiler backend

wireshark_gen.py

A helper class, that generates the C code.

idl2wrs

A simple shell script wrapper that the end user should use to generate the dissector from the IDL file(s).

D.9.2.áWhy do this?

It is important to understand what CORBA traffic looks like over GIOP/IIOP, and to help build a tool that can assist in troubleshooting CORBA interworking. This was especially the case after seeing a lot of discussions about how particular IDL types are represented inside an octet stream.

I have also had comments/feedback that this tool would be good for say a CORBA class when teaching students what CORBA traffic looks like "on the wire".

It is also COOL to work on a great Open Source project such as the case with "Wireshark" ( http://www.wireshark.org )

D.9.3.áHow to use idl2wrs

To use the idl2wrs to generate Wireshark dissectors, you need the following:

Prerequisites to using idl2wrs

  1. Python must be installed. See http://python.org/

  2. omniidl from the the omniORB package must be available. See http://omniorb.sourceforge.net/

  3. Of course you need Wireshark installed to compile the code and tweak it if required. idl2wrs is part of the standard Wireshark distribution

To use idl2wrs to generate an Wireshark dissector from an idl file use the following procedure:

Procedure for converting a CORBA idl file into a Wireshark dissector

  1. To write the C code to stdout.

    idl2wrs  <your file.idl>

    eg:

    idl2wrs echo.idl

  2. To write to a file, just redirect the output.

    idl2wrs echo.idl > packet-test-idl.c

    You may wish to comment out the register_giop_user_module() code and that will leave you with heuristic dissection.

If you don't want to use the shell script wrapper, then try steps 3 or 4 instead.

  1. To write the C code to stdout.

    Usage: omniidl  -p ./ -b wireshark_be <your file.idl>

    eg:

    omniidl  -p ./ -b wireshark_be echo.idl

  2. To write to a file, just redirect the output.

    omniidl  -p ./ -b wireshark_be echo.idl > packet-test-idl.c

    You may wish to comment out the register_giop_user_module() code and that will leave you with heuristic dissection.

  3. Copy the resulting C code to your Wireshark src directory, edit the two make files to include the packet-test-idl.c

    cp packet-test-idl.c /dir/where/wireshark/lives/
    edit Makefile.am
    edit Makefile.nmake
    	    

  4. Run configure

    ./configure (or ./autogen.sh)

  5. Compile the code

    make

  6. Good Luck !!

D.9.4.áTODO

  1. Exception code not generated (yet), but can be added manually.

  2. Enums not converted to symbolic values (yet), but can be added manually.

  3. Add command line options etc

  4. More I am sure :-)

D.9.5.áLimitations

See the TODO list inside packet-giop.c

D.9.6.áNotes

  1. The "-p ./" option passed to omniidl indicates that the wireshark_be.py and wireshark_gen.py are residing in the current directory. This may need tweaking if you place these files somewhere else.

  2. If it complains about being unable to find some modules (eg tempfile.py), you may want to check if PYTHONPATH is set correctly. On my Linux box, it is PYTHONPATH=/usr/lib/python2.4/