gre

package
v0.577.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jun 6, 2026 License: AGPL-3.0 Imports: 5 Imported by: 0

Documentation

Overview

Package gre decodes Generic Routing Encapsulation packets per RFC 2784 (base) + RFC 2890 (Key + Sequence Number) + RFC 2637 (PPTP Enhanced GRE, Version=1).

Wrap-vs-native judgement

Native. All three RFCs are fully public; GRE is a tight
bit-packed header with optional fields gated by flag
bits. No crypto, no compression, no varints. Operators
paste IP-payload bytes (protocol number 47 in the outer
IP header) from a `tcpdump -X proto 47` line, a
Wireshark Follow-IP-Stream view, or any GRE-emitting
tool and get the documented header plus encapsulated
protocol identification for routing into a downstream
decoder.

What this package covers

  • **4-byte mandatory header** (RFC 2784 §2):

  • byte 0: C (Checksum present, bit 7), R (Routing present — deprecated, bit 6), K (Key present, bit 5), S (Sequence Number present, bit 4), s (Strict Source Route — deprecated, bit 3), Recur (Recursion Control — deprecated, bits 0-2).

  • byte 1: Flags (5 bits) + Version (3 bits). Version 0 = standard GRE; Version 1 = PPTP Enhanced GRE.

  • bytes 2-3: Protocol Type (EtherType of the encapsulated payload). **8-entry name table**:

  • 0x0800 IPv4

  • 0x86DD IPv6

  • 0x6558 Transparent Ethernet Bridging (L2 tunnel, EoGRE)

  • 0x880B PPP (PPP-in-GRE)

  • 0x8847 MPLS unicast

  • 0x8848 MPLS multicast

  • 0x6559 Raw Frame Relay

  • 0x0806 ARP

  • **Optional fields** (gated by flag bits, in this order):

  • If C or R set: 4 bytes = 16-bit Checksum + 16-bit Offset (Offset is only meaningful when R is set; R is deprecated).

  • If K set (RFC 2890): 4 bytes Key (used to demultiplex multiple GRE tunnels between the same endpoints).

  • If S set (RFC 2890): 4 bytes Sequence Number (for in-order delivery; rarely used in practice).

  • **PPTP Enhanced GRE** (RFC 2637, Version=1) — Microsoft PPTP overloads the K bit + Key field: the 4 bytes are interpreted as PayloadLength (uint16 BE) + Call ID (uint16 BE). PPTP additionally adds an Acknowledgement Number (4 bytes) when the A bit (bit 7 of byte 1) is set. PPTP always has K=1, S is optional, A is optional.

  • **Recognised variant**: surfaces 'standard GRE (RFC 2784)' for V=0 or 'PPTP Enhanced GRE (RFC 2637)' for V=1.

  • **Encapsulated payload bytes** are surfaced as hex. When the protocol type marks the payload as IPv4 (0x0800) or IPv6 (0x86DD), the inner packet is decoded in place via internal/ipdecode, so the tunnelled flow's addresses / protocol / ports surface directly (a payload that does not parse as IP is reported with an error and left as hex). Other payload kinds (Transparent Ethernet, PPP, MPLS, …) are left as hex for the appropriate downstream decoder.

What this package does NOT cover (deliberately out of scope)

  • IP framing — feed the IP-payload bytes after the outer IPv4 / IPv6 header strip (IP protocol number 47 for GRE).

  • Inner payload decoding — operators pipe the post-GRE bytes to `ip_packet_decode` (for IPv4/IPv6 payloads), to a future Ethernet decoder (for TEB payloads), to `arp_decode` (for ARP), etc.

  • Routing field (R bit) body — the RFC 1701 routing entries are deprecated and we only surface the Checksum + Offset bytes.

  • PPP frame dissection inside PPTP — the post-Ack PPP frame is a separate Spec.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Result

type Result struct {
	Variant         string `json:"variant"`
	Version         int    `json:"version"`
	ChecksumPresent bool   `json:"checksum_present"`
	RoutingPresent  bool   `json:"routing_present"`
	KeyPresent      bool   `json:"key_present"`
	SequencePresent bool   `json:"sequence_present"`
	StrictSource    bool   `json:"strict_source_route"`
	Recur           int    `json:"recursion_control"`
	AckPresent      bool   `json:"ack_present,omitempty"`
	FlagsByte0Hex   string `json:"flags_byte0_hex"`
	FlagsByte1Hex   string `json:"flags_byte1_hex"`
	ProtocolType    int    `json:"protocol_type"`
	ProtocolTypeHex string `json:"protocol_type_hex"`
	ProtocolName    string `json:"protocol_name"`

	Checksum       *uint16 `json:"checksum,omitempty"`
	Offset         *uint16 `json:"offset,omitempty"`
	Key            *uint32 `json:"key,omitempty"`
	KeyHex         string  `json:"key_hex,omitempty"`
	SequenceNumber *uint32 `json:"sequence_number,omitempty"`
	AckNumber      *uint32 `json:"ack_number,omitempty"`

	PPTPPayloadLen *uint16 `json:"pptp_payload_length,omitempty"`
	PPTPCallID     *uint16 `json:"pptp_call_id,omitempty"`

	HeaderBytes      int              `json:"header_bytes"`
	PayloadLength    int              `json:"payload_length"`
	PayloadHex       string           `json:"payload_hex,omitempty"`
	InnerPacket      *ipdecode.Packet `json:"inner_packet,omitempty"`
	InnerDecodeError string           `json:"inner_decode_error,omitempty"`
	TotalBytes       int              `json:"total_bytes"`
	Notes            []string         `json:"notes,omitempty"`
}

Result is the top-level decoded view.

func Decode

func Decode(hexStr string) (*Result, error)

Decode parses a GRE packet from hex.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL