Repository navigation
fix(pcap,pcapng)!: a cut PCAP header or PCAP-NG block rebuilds as captured (#1470) - #1475
Conversation
32c84bf to
f61be1c
Compare
|
Verdict: GOOD TO GO at
One consequence to know about: a corrupted length field that overshoots the data now reads as a cut instead of raising. That is consistent with #1458. One design point needs a ruling, posted on #1470: should the visible |
|
Coverage: 89.55% (unit tier, Python 3.14,
Per-file detail: the |
f61be1c to
cb289c5
Compare
|
Verdict: GOOD TO GO at
This stays a draft until #1465, its base, merges. |
|
Still draft? |
|
No longer a draft. Its base, #1465, merged at 13:13Z, and I've marked this ready for review. It's |
…tured (#1470) - PCAP Header calls #1465's keep_short_read/replay_short_read, so a header cut short rebuilds from its info as the octets captured, not all 24. - A PCAP-NG block the capture ends inside keeps its octets as __truncated_raw__; a rebuild parses them again instead of writing the block at its declared length (which wrote zeros, or raised ProtocolError). - A cut block whose own parser refuses the zero-filled fields is kept as an UnknownBlock rather than raising. - TLS and WireGuard key logs skip a last line the capture cut, and raise FieldValueError for any other malformed line (was a bare ValueError). Adds tests/protocols/misc/test_misc_short_read_1470_runtime.py.
cb289c5 to
f078fbd
Compare
|
Verdict carried to |
make pylint,make mypy,make isort) — pylint/mypy run on the 3 files, nothing new on changed lines;tests/project/test_isort_clean.pypassesmake testpasses, and a test case covers the change — legsprotocols/misc,foundation,dumpkit;test_capture_roundtrip_runtime.py;tests/projectWhat is the purpose of your pull request?
fix— corrects a defectDescription of your pull request and other information
Closes #1470
Depends on #1465, now merged as
15d5eeca2; rebased ontomain.keep_short_read/replay_short_read.Header(raw[:4])rebuilds as 4 octets (was 24).__truncated_raw__, and a rebuild re-parses them. If the block's parser rejects the zero-filled fields, the block is kept as anUnknownBlock. TLS/WireGuard key logs skip a cut last line. Any other malformed line raisesFieldValueError(was a bareValueError).__truncated_raw__rather than__short_read__for PCAP-NG: the cut lands in a nested block schema, and a full rebuild trimmed afterwards is not byte-exact (it recomputes lengths and options from zero-filled fields), so the captured octets themselves, not a (field, count) record, have to travel with the info.!: a cut block gains__truncated_raw__, and some cut blocks now parse instead of raising.tests/protocols/misc/test_misc_short_read_1470_runtime.pycuts every PCAP header and every PCAP-NG block type at every offset, then rebuilds each frominfoand frominfo.to_dict(). Without the fix, 5320 subtests and 3 tests fail. With it, 5702 subtests pass. Dumps (json and tree) of all 22 untruncated captures are byte-identical.