From nobody@FreeBSD.org  Mon Jan 28 09:09:29 2013
Return-Path: <nobody@FreeBSD.org>
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1])
	by hub.freebsd.org (Postfix) with ESMTP id 0E677DB7
	for <freebsd-gnats-submit@FreeBSD.org>; Mon, 28 Jan 2013 09:09:29 +0000 (UTC)
	(envelope-from nobody@FreeBSD.org)
Received: from red.freebsd.org (red.freebsd.org [IPv6:2001:4f8:fff6::22])
	by mx1.freebsd.org (Postfix) with ESMTP id DB70C2F4
	for <freebsd-gnats-submit@FreeBSD.org>; Mon, 28 Jan 2013 09:09:28 +0000 (UTC)
Received: from red.freebsd.org (localhost [127.0.0.1])
	by red.freebsd.org (8.14.5/8.14.5) with ESMTP id r0S99RBs002545
	for <freebsd-gnats-submit@FreeBSD.org>; Mon, 28 Jan 2013 09:09:27 GMT
	(envelope-from nobody@red.freebsd.org)
Received: (from nobody@localhost)
	by red.freebsd.org (8.14.5/8.14.5/Submit) id r0S99RVD002544;
	Mon, 28 Jan 2013 09:09:27 GMT
	(envelope-from nobody)
Message-Id: <201301280909.r0S99RVD002544@red.freebsd.org>
Date: Mon, 28 Jan 2013 09:09:27 GMT
From: Dmitry Dvoinikov <dmitry@targeted.org>
To: freebsd-gnats-submit@FreeBSD.org
Subject: tcpdump incorrectly decodes pflog'ged UDP packet as ATALK
X-Send-Pr-Version: www-3.1
X-GNATS-Notify:

>Number:         175645
>Category:       bin
>Synopsis:       tcpdump(1) incorrectly decodes pflog'ged UDP packet as ATALK
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    glebius
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Mon Jan 28 09:10:00 UTC 2013
>Closed-Date:    
>Last-Modified:  Thu Feb 07 09:10:09 UTC 2013
>Originator:     Dmitry Dvoinikov
>Release:        8.3
>Organization:
www.infosysco.ru
>Environment:
FreeBSD foo 8.3-RELEASE-p5 FreeBSD 8.3-RELEASE-p5 #1: Wed Dec 12 23:29:24 YEKT 2012     admin@foo:/opt/obj/opt/src/sys/FOO  i386
>Description:
Some UDP packet, saved by pflog, is decoded incorrectly as ATALK.

tcpdump output:

# tcpdump -r packet.pcap 
reading from file packet.pcap, link-type PFLOG (OpenBSD pflog file)
11:22:11.296532 IP 115.61.0.254 > 143.12.228.91: at-#100 5

whereas the (presumably correct) wireshark output:

Frame 1: 110 bytes on wire (880 bits), 110 bytes captured (880 bits)
PF Log IPv4 pass on ifc by rule 0
Internet Protocol Version 4, Src: 172.30.0.11 (172.30.0.11), Dst: 193.120.212.22 (193.120.212.22)
User Datagram Protocol, Src Port: 55573 (55573), Dst Port: 16605 (16605)
Data (18 bytes)


>How-To-Repeat:
openssl base64 -d > packet.pcap << EOF
1MOyoQIABAAAAAAAAAAAAHQAAAB1AAAAAwsGUVSGBABuAAAAbgAAAD0CAABpZmMA
AAAAAAAAAAAAAAAAYW5jaG9yX25hbWUAAAAAAAAAABwAAAAC/////6CGAQAAAAAA
ggUAAAEAAABFAAAuAABAAEAR+QasHgALwXjUFtkVQN0AGrhGUxUCmI8Mcz3kAFv+
ZGyAi27Z
EOF

tcpdump -r packet.pcap
>Fix:


>Release-Note:
>Audit-Trail:

From: Gleb Smirnoff <glebius@FreeBSD.org>
To: Dmitry Dvoinikov <dmitry@targeted.org>
Cc: freebsd-gnats-submit@FreeBSD.org
Subject: Re: misc/175645: tcpdump incorrectly decodes pflog'ged UDP packet as
 ATALK
Date: Wed, 30 Jan 2013 14:15:11 +0400

 Was this packet recorded on FreeBSD or on OpenBSD system?
 
 -- 
 Totus tuus, Glebius.

From: Dmitry Dvoinikov <dmitry@targeted.org>
To: Gleb Smirnoff <glebius@FreeBSD.org>
Cc: freebsd-gnats-submit@FreeBSD.org
Subject: Re: misc/175645: tcpdump incorrectly decodes pflog'ged UDP packet
 as ATALK
Date: Sat, 2 Feb 2013 13:01:46 +0600

 > Was this packet recorded on FreeBSD or on OpenBSD system?
 > 
 > -- 
 > Totus tuus, Glebius.
 
 It's all on the same machine, FreeBSD 8.3 as per uname.
Responsible-Changed-From-To: freebsd-bugs->glebius 
Responsible-Changed-By: glebius 
Responsible-Changed-When: Thu Feb 7 09:09:50 UTC 2013 
Responsible-Changed-Why:  
I'll look at this once I have time. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=175645 
>Unformatted:
