<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packeteer/tests/test_dns.cpp, branch main</title>
<subtitle>Packet capture and analysis, TUI and desktop GUI.
</subtitle>
<id>https://srdusr.com/git/packeteer/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/packeteer/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/'/>
<updated>2026-05-26T23:04:00+00:00</updated>
<entry>
<title>Decode DNS answer records (A/AAAA/CNAME) - resolved addresses, not just ancount</title>
<updated>2026-05-26T23:04:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2026-05-26T23:04:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=0122045b492f2bd41a74769b8e6a9cefc73f988b'/>
<id>urn:sha1:0122045b492f2bd41a74769b8e6a9cefc73f988b</id>
<content type='text'>
Probably the single most-wanted thing a packet analyzer shows that
this one didn't yet: responses showed ancount=N but never what a
query actually resolved to. A, AAAA, and CNAME rdata now render into
readable text; every other type is still walked correctly
(name/type/ttl/rdlength read and bounds-checked) but not rendered.

Needed a second name reader alongside the existing question-only
read_dns_name(): real answer records almost always compress their
NAME field as a 2-byte pointer back to the question, which the
original reader deliberately rejects. read_dns_name_following_pointers()
actually follows them, bounded by a maximum jump count rather than a
backward-only check - a cycle across pointers pointing at each other
would still loop forever under "must point backward", but can't
survive a hard cap on jumps followed.

Fuzzed the new pointer-chasing logic specifically before trusting it
(fuzz_dns, fuzz_summarize, ~5.1M combined runs) - exactly the kind of
attacker-influenced-offset code this project's fuzzing exists for.
Clean, no crashes or timeouts.

Live-verified extensively on wlp1s0: a direct query to 8.8.8.8 for
example.com resolved two real A records; a query for www.github.com
showed a real CNAME chain; and organic background DNS traffic from
this machine's own browser sessions showed AAAA records (including an
8-address response, all correctly listed) and DNS RR type 65 (HTTPS
records) correctly producing no answers suffix.
</content>
</entry>
<entry>
<title>Rename project from wireframe to packeteer</title>
<updated>2024-05-27T20:00:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-05-27T20:00:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=b565d7d9c47ca1ec5af0effd828431ee96027d60'/>
<id>urn:sha1:b565d7d9c47ca1ec5af0effd828431ee96027d60</id>
<content type='text'>
Decided on the name after weighing alternatives in NAMES.md: packeteer
(packet + -eer, "one who wields packets") fit the project's actual
scope better than the wire/frame pun once it had grown into full
L2-L7 dissection, reassembly, checksums, privilege dropping, and dual
TUI/GUI frontends. No existing packet-capture project uses the name;
the one real-world collision (Packeteer, Inc., a networking company
acquired and folded into Blue Coat/Symantec by 2008) is long defunct.

Mechanical rename throughout: CMake project/target names, the
wireframe:: namespace and include/wireframe/ directory (git mv,
history preserved), every #include path, CLI/GUI help text, and the
project's own working directory. NAMES.md rewritten to record the
decision instead of leaving stale self-referential etymology behind
from the blind rename pass.

Verified after every step: full rebuild (all four targets, no
warnings) and the full test suite (128/128 cases, 366/366 assertions)
both from a fresh reconfigure and again after the directory move.
</content>
</entry>
<entry>
<title>Initial commit: wireframe packet capture/analysis tool</title>
<updated>2024-05-13T23:42:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-05-13T23:42:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=08332a4195956611db80a2cfe3710d760cbd6acf'/>
<id>urn:sha1:08332a4195956611db80a2cfe3710d760cbd6acf</id>
<content type='text'>
Terminal packet capture and analysis tool built to learn the C++
memory model (byte layout, alignment, endianness, std::span over
unowned buffers) via a real capture pipeline.

- Hand-rolled L2-L4 decoders (Ethernet, IPv4, IPv6 with extension
  header walking, TCP, UDP) over std::span, no struct-casting
- L7 dissector interface with DNS, HTTP, and TLS SNI implementations
- pcapng read/write for Wireshark-compatible capture files
- Bounded capture queue: drop-on-backpressure for live capture,
  blocking push for faithful file replay
- Kernel-level BPF filtering (-f) and a separate display-only search
  (-g / interactive) that doesn't touch what's captured
- Replay mode (-r) reads a saved pcapng file back through the same
  pipeline as live capture, no root or live device needed
- pcap_stats() surfaces kernel/interface drops invisible to the
  capture queue's own counter
- Three frontends sharing one CaptureSession setup path: CLI, TUI
  (FTXUI, primary), GUI (Dear ImGui + SDL3, secondary)
- 89 unit tests (doctest) plus 9 libFuzzer harnesses covering every
  hand-rolled parser; fuzzing found and fixed a real OOM in the
  pcapng reader (unbounded allocation from an untrusted length field)
</content>
</entry>
</feed>
