Skip to content

fix(pcap): _make_magic ignores nanosecond with explicit endian flags; _read_protos ignores size - #1112

Merged
JarryShaw merged 1 commit into
mainfrom
fix/1096-pcap-make-magic-nanosecond
Oct 6, 2026
Merged

JarryShaw merged 1 commit into
mainfrom
fix/1096-pcap-make-magic-nanosecond

Conversation

@JarryShaw

@JarryShaw JarryShaw commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner
  • Searched for similar pull requests
  • Followed the coding style — ran pylint (W,E) and mypy on header.py directly: no messages on changed lines; make targets not run
  • make test passes, and a test case covers the change — only the modules listed below
  • Added a changelog entry — N/A, added centrally after the wave

What is the purpose of your pull request?

  • fix — corrects a defect

Description

Closes #1096. _make_magic's endian-flag branch now looks up _MAGIC_NUM[(endian, nanosecond)]. Header._read_protos now reads size bytes, like Link/Internet. It is kept rather than removed because it overrides the ProtocolBase._read_protos hook and an existing test calls it.

_make_magic(lil, big, nsec) before after
(T, F, F) 4d3cb2a1 d4c3b2a1
(F, T, T) a1b2c3d4 a1b23c4d

_read_protos(1/2) consumed 4 bytes before the fix and consumes 1/2 after it. test_header_frame_unit pinned the old (T, F, F) magic, so that assertion is corrected.

Tests: the new tests/protocols/misc/pcap/test_header_magic_protos_unit.py fails without the fix (6 subtests, 3 passed) and passes with it (3 passed, 11 subtests). test_header_frame_unit passes 6 of 6, dumpkit/test_common_unit 14, test_option_roundtrip_unit 6, and tests/project 379 passed, 1 skipped.

… _read_protos ignores size

- _make_magic: the lilendian/bigendian branch hard-coded the magic, always
  nanosecond for little-endian and microsecond for big-endian. It now looks
  up _MAGIC_NUM with the nanosecond flag, as the byteorder branch does.
- Header._read_protos: read `size` bytes instead of a fixed 4, matching
  Link._read_protos and Internet._read_protos.
- test_header_frame_unit pinned the old little-endian nanosecond magic for
  lilendian=True with nanosecond=False; corrected to d4c3b2a1.

Closes #1096
@JarryShaw JarryShaw added fix Pull requests that fix a defect (fix: subject prefix) review: running A cross-review is in flight against the current head - no verdict yet labels Oct 6, 2026
@JarryShaw

Copy link
Copy Markdown
Owner Author

Cross-review verdict on ea5e5df59: GOOD TO GO (ran on Sonnet; author Opus)

  • Correction to the issue's table: on main, the flag branch ignored nanosecond. Little-endian always produced the nanosecond magic and big-endian the microsecond one.
  • Magic numbers: on this PR all four flag combinations match libpcap: d4c3b2a1, 4d3cb2a1, a1b2c3d4 and a1b23c4d. The byteorder= path agrees with them.
  • _read_protos(size): it now reads size bytes, matching the ProtocolBase hook and the Link/Internet versions. Its only callers are tests.
  • Tests: with header.py reverted, 6 subtests fail. The edited expectation at test_header_frame_unit.py:145 is right.
  • Separate, pre-existing defect: Header(...).pack()[:4] is d4c3b2a1 for every flag combination, on main as well as here. It will be filed separately.

@JarryShaw JarryShaw added review: good-to-go Cross-review at the current head says ready; CI state is separate and removed review: running A cross-review is in flight against the current head - no verdict yet labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Coverage: 88.74% (unit tier, Python 3.14, ea5e5df59, Unit Tests run success)

Package Statements Missed Branches Partial Cover
pcapkit (top level) 104 4 20 4 93.55%
pcapkit/const 18757 1035 2342 846 90.23%
pcapkit/corekit 1874 91 578 22 94.33%
pcapkit/dumpkit 136 0 40 0 100.00%
pcapkit/foundation 2422 143 842 34 92.62%
pcapkit/interface 112 7 40 5 92.11%
pcapkit/protocols 15653 187 3942 162 98.19%
pcapkit/toolkit 487 71 144 3 84.15%
pcapkit/utilities 429 4 122 4 98.55%
pcapkit/vendor 4409 2359 1006 158 42.84%

Per-file detail: the coverage-html artifact of this run.

@JarryShaw
JarryShaw merged commit 64b49ce into main Oct 6, 2026
41 checks passed
@JarryShaw
JarryShaw deleted the fix/1096-pcap-make-magic-nanosecond branch October 6, 2026 20:31
@JarryShaw JarryShaw removed the review: good-to-go Cross-review at the current head says ready; CI state is separate label Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fix Pull requests that fix a defect (fix: subject prefix)

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

fix(pcap): _make_magic ignores nanosecond with explicit endian flags; _read_protos ignores size

1 participant