<feed xmlns='http://www.w3.org/2005/Atom'>
<title>packeteer/tests/test_tls.cpp, branch main</title>
<subtitle>Packet capture and analysis, TUI and desktop GUI.
</subtitle>
<id>https://srdusr.com/git/packeteer/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/packeteer/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/'/>
<updated>2026-05-26T07:16:00+00:00</updated>
<entry>
<title>Add deeper TLS (ServerHello, ALPN); fix a QUIC/TCP false-positive bug</title>
<updated>2026-05-26T07:16:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2026-05-26T07:16:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=c098f1742bb04fbe41fc6cf492cd334efef734eb'/>
<id>urn:sha1:c098f1742bb04fbe41fc6cf492cd334efef734eb</id>
<content type='text'>
TLS: ServerHello now reports the negotiated version and cipher suite
alongside the existing ClientHello SNI support, plus ClientHello's
ALPN extension. ServerHello's version prefers the supported_versions
extension over legacy_version when present - TLS 1.3 always sets
legacy_version to 0x0303 for middlebox compatibility, so reading only
that field would misreport every real TLS 1.3 connection as 1.2.
Cipher suite names are hardcoded only for TLS 1.3's five suites (a
small closed set); everything else reports as raw hex rather than a
guessed name from a "common suites" list.

Live-verifying that against a real Cloudflare TLS 1.3 handshake
surfaced a real, unrelated bug in the QUIC dissector added earlier: it was also being tried against TCP port-443 payloads
(a side effect of the earlier L7Registry port-sharing fix), and
produced false "QUIC" labels on TLS ciphertext continuation fragments
- large encrypted records split across multiple TCP segments, each
fed to the parser independently since this project doesn't reassemble
by default, so a later fragment's effectively random bytes
occasionally passed as a plausible QUIC header.

Fixed in two layers: parse_quic() now enforces RFC 9000's real 20-byte
cap on connection ID lengths, closing most of the long-header false-
positive surface; and L7Dissector gained a transport() method
(defaulting to kAny, so every other dissector's behavior is unchanged)
so QuicDissector can declare itself UDP-only - necessary because the
length cap alone can't touch QUIC's short-header form, which by design
has no structural signal beyond one bit once header protection can't
be removed without connection state.

Re-verified against the identical live scenario afterward: zero false
QUIC labels on the same Cloudflare TCP handshake, and a repeat of the
earlier real HTTP/3 capture confirmed genuine QUIC still decodes
correctly on UDP.
</content>
</entry>
<entry>
<title>Rename project from wireframe to packeteer</title>
<updated>2024-05-27T20:00:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-05-27T20:00:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=b565d7d9c47ca1ec5af0effd828431ee96027d60'/>
<id>urn:sha1:b565d7d9c47ca1ec5af0effd828431ee96027d60</id>
<content type='text'>
Decided on the name after weighing alternatives in NAMES.md: packeteer
(packet + -eer, "one who wields packets") fit the project's actual
scope better than the wire/frame pun once it had grown into full
L2-L7 dissection, reassembly, checksums, privilege dropping, and dual
TUI/GUI frontends. No existing packet-capture project uses the name;
the one real-world collision (Packeteer, Inc., a networking company
acquired and folded into Blue Coat/Symantec by 2008) is long defunct.

Mechanical rename throughout: CMake project/target names, the
wireframe:: namespace and include/wireframe/ directory (git mv,
history preserved), every #include path, CLI/GUI help text, and the
project's own working directory. NAMES.md rewritten to record the
decision instead of leaving stale self-referential etymology behind
from the blind rename pass.

Verified after every step: full rebuild (all four targets, no
warnings) and the full test suite (128/128 cases, 366/366 assertions)
both from a fresh reconfigure and again after the directory move.
</content>
</entry>
<entry>
<title>Initial commit: wireframe packet capture/analysis tool</title>
<updated>2024-05-13T23:42:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2024-05-13T23:42:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/packeteer/commit/?id=08332a4195956611db80a2cfe3710d760cbd6acf'/>
<id>urn:sha1:08332a4195956611db80a2cfe3710d760cbd6acf</id>
<content type='text'>
Terminal packet capture and analysis tool built to learn the C++
memory model (byte layout, alignment, endianness, std::span over
unowned buffers) via a real capture pipeline.

- Hand-rolled L2-L4 decoders (Ethernet, IPv4, IPv6 with extension
  header walking, TCP, UDP) over std::span, no struct-casting
- L7 dissector interface with DNS, HTTP, and TLS SNI implementations
- pcapng read/write for Wireshark-compatible capture files
- Bounded capture queue: drop-on-backpressure for live capture,
  blocking push for faithful file replay
- Kernel-level BPF filtering (-f) and a separate display-only search
  (-g / interactive) that doesn't touch what's captured
- Replay mode (-r) reads a saved pcapng file back through the same
  pipeline as live capture, no root or live device needed
- pcap_stats() surfaces kernel/interface drops invisible to the
  capture queue's own counter
- Three frontends sharing one CaptureSession setup path: CLI, TUI
  (FTXUI, primary), GUI (Dear ImGui + SDL3, secondary)
- 89 unit tests (doctest) plus 9 libFuzzer harnesses covering every
  hand-rolled parser; fuzzing found and fixed a real OOM in the
  pcapng reader (unbounded allocation from an untrusted length field)
</content>
</entry>
</feed>
