<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packeteer/tests/test_ntp.cpp, branch main</title>
<subtitle>Packet capture and analysis, TUI and desktop GUI.
</subtitle>
<id>https://srdusr.com/git/packeteer/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/packeteer/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/'/>
<updated>2025-06-25T20:11:00+00:00</updated>
<entry>
<title>Add NTP and DHCP L7 dissectors</title>
<updated>2025-06-25T20:11:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-06-25T20:11:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=d9bedcec1bce8d15de6403377702d51d1bcb862f'/>
<id>urn:sha1:d9bedcec1bce8d15de6403377702d51d1bcb862f</id>
<content type='text'>
NTP decodes the fixed header's version/mode/stratum - the timestamp
fields need NTP era/fraction fixed-point math to render meaningfully
and add nothing a one-line summary needs, so they're left alone.

DHCP decodes RFC 2131's BOOTP fixed header + magic cookie, then walks
the TLV options bounds-safely for option 53 (message type), plus
yiaddr when the server has assigned one. It's the first dissector
needing two well-known ports (67 server, 68 client) rather than one;
registering at just 67 still matches both directions since
l7_summarize() already falls back from dst_port to src_port.

Verified live: NTP against a real pool.ntp.org query on wlp1s0 (a
genuine stratum-2 reply came back). DHCP over loopback with a
synthetic-but-wire-format-real DISCOVER/OFFER exchange rather than a
real lease renewal, to avoid disrupting this machine's actual network
state - caught a test-setup mistake in the process (both packets
sent from the same ephemeral port instead of the OFFER actually
originating from port 67), not a dissector bug.
</content>
</entry>
</feed>
