diff options
| author | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2024-05-27 22:00:00 +0200 |
| commit | b565d7d9c47ca1ec5af0effd828431ee96027d60 (patch) | |
| tree | fbe0c9c897e78f507443507354d5b1d8fb851099 | |
| parent | fbedc55d5aa861c381701c9f913b34ee7ab57ec4 (diff) | |
| download | packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.tar.gz packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.zip | |
Rename project from wireframe to packeteer
Decided on the name after weighing alternatives in NAMES.md: packeteer
(packet + -eer, "one who wields packets") fit the project's actual
scope better than the wire/frame pun once it had grown into full
L2-L7 dissection, reassembly, checksums, privilege dropping, and dual
TUI/GUI frontends. No existing packet-capture project uses the name;
the one real-world collision (Packeteer, Inc., a networking company
acquired and folded into Blue Coat/Symantec by 2008) is long defunct.
Mechanical rename throughout: CMake project/target names, the
wireframe:: namespace and include/wireframe/ directory (git mv,
history preserved), every #include path, CLI/GUI help text, and the
project's own working directory. NAMES.md rewritten to record the
decision instead of leaving stale self-referential etymology behind
from the blind rename pass.
Verified after every step: full rebuild (all four targets, no
warnings) and the full test suite (128/128 cases, 366/366 assertions)
both from a fresh reconfigure and again after the directory move.
| -rw-r--r-- | CMakeLists.txt | 60 | ||||
| -rw-r--r-- | NAMES.md | 148 | ||||
| -rw-r--r-- | PLAN.md | 42 | ||||
| -rw-r--r-- | fuzz/fuzz_checksum.cpp | 6 | ||||
| -rw-r--r-- | fuzz/fuzz_dns.cpp | 6 | ||||
| -rw-r--r-- | fuzz/fuzz_ethernet.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_http.cpp | 6 | ||||
| -rw-r--r-- | fuzz/fuzz_ipv4.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_ipv6.cpp | 10 | ||||
| -rw-r--r-- | fuzz/fuzz_pcapng_reader.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_summarize.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_tcp.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_tcp_reassembly.cpp | 4 | ||||
| -rw-r--r-- | fuzz/fuzz_tls.cpp | 6 | ||||
| -rw-r--r-- | fuzz/fuzz_udp.cpp | 4 | ||||
| -rw-r--r-- | include/packeteer/byteio.hpp (renamed from include/wireframe/byteio.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/capture_queue.hpp (renamed from include/wireframe/capture_queue.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/capture_session.hpp (renamed from include/wireframe/capture_session.hpp) | 14 | ||||
| -rw-r--r-- | include/packeteer/filter.hpp (renamed from include/wireframe/filter.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/l7/dissector.hpp (renamed from include/wireframe/l7/dissector.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/l7/dns.hpp (renamed from include/wireframe/l7/dns.hpp) | 8 | ||||
| -rw-r--r-- | include/packeteer/l7/http.hpp (renamed from include/wireframe/l7/http.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/l7/mdns.hpp (renamed from include/wireframe/l7/mdns.hpp) | 8 | ||||
| -rw-r--r-- | include/packeteer/l7/ssh.hpp (renamed from include/wireframe/l7/ssh.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/l7/tls.hpp (renamed from include/wireframe/l7/tls.hpp) | 8 | ||||
| -rw-r--r-- | include/packeteer/net/checksum.hpp (renamed from include/wireframe/net/checksum.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/ethernet.hpp (renamed from include/wireframe/net/ethernet.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/icmp.hpp (renamed from include/wireframe/net/icmp.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/ipv4.hpp (renamed from include/wireframe/net/ipv4.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/ipv6.hpp (renamed from include/wireframe/net/ipv6.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/tcp.hpp (renamed from include/wireframe/net/tcp.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/net/tcp_reassembly.hpp (renamed from include/wireframe/net/tcp_reassembly.hpp) | 8 | ||||
| -rw-r--r-- | include/packeteer/net/udp.hpp (renamed from include/wireframe/net/udp.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/packet_diagnostics.hpp (renamed from include/wireframe/packet_diagnostics.hpp) | 20 | ||||
| -rw-r--r-- | include/packeteer/pcapng/reader.hpp (renamed from include/wireframe/pcapng/reader.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/pcapng/writer.hpp (renamed from include/wireframe/pcapng/writer.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/privileges.hpp (renamed from include/wireframe/privileges.hpp) | 4 | ||||
| -rw-r--r-- | include/packeteer/search.hpp (renamed from include/wireframe/search.hpp) | 6 | ||||
| -rw-r--r-- | include/packeteer/summarize.hpp (renamed from include/wireframe/summarize.hpp) | 30 | ||||
| -rw-r--r-- | src/afpacket_capture.cpp | 10 | ||||
| -rw-r--r-- | src/gui_main.cpp | 40 | ||||
| -rw-r--r-- | src/main.cpp | 56 | ||||
| -rw-r--r-- | tests/test_byteio.cpp | 4 | ||||
| -rw-r--r-- | tests/test_capture_queue.cpp | 4 | ||||
| -rw-r--r-- | tests/test_capture_session.cpp | 8 | ||||
| -rw-r--r-- | tests/test_checksum.cpp | 4 | ||||
| -rw-r--r-- | tests/test_dns.cpp | 4 | ||||
| -rw-r--r-- | tests/test_filter.cpp | 12 | ||||
| -rw-r--r-- | tests/test_http.cpp | 8 | ||||
| -rw-r--r-- | tests/test_icmp.cpp | 4 | ||||
| -rw-r--r-- | tests/test_ipv6.cpp | 6 | ||||
| -rw-r--r-- | tests/test_mdns.cpp | 4 | ||||
| -rw-r--r-- | tests/test_net.cpp | 10 | ||||
| -rw-r--r-- | tests/test_pcapng.cpp | 6 | ||||
| -rw-r--r-- | tests/test_privileges.cpp | 4 | ||||
| -rw-r--r-- | tests/test_search.cpp | 4 | ||||
| -rw-r--r-- | tests/test_ssh.cpp | 4 | ||||
| -rw-r--r-- | tests/test_summarize.cpp | 26 | ||||
| -rw-r--r-- | tests/test_tcp_reassembly.cpp | 8 | ||||
| -rw-r--r-- | tests/test_tls.cpp | 8 |
60 files changed, 356 insertions, 376 deletions
diff --git a/CMakeLists.txt b/CMakeLists.txt index 264fcc4..0db3e85 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -1,5 +1,5 @@ cmake_minimum_required(VERSION 3.20) -project(wireframe CXX) +project(packeteer CXX) set(CMAKE_CXX_STANDARD 20) set(CMAKE_CXX_STANDARD_REQUIRED ON) @@ -22,9 +22,9 @@ FetchContent_Declare( ) FetchContent_MakeAvailable(ftxui) -add_executable(wireframe src/main.cpp) -target_include_directories(wireframe PRIVATE include) -target_link_libraries(wireframe PRIVATE +add_executable(packeteer src/main.cpp) +target_include_directories(packeteer PRIVATE include) +target_link_libraries(packeteer PRIVATE pcap Threads::Threads ftxui::component @@ -37,9 +37,9 @@ target_link_libraries(wireframe PRIVATE # Linux-specific socket family, unlike the portable libpcap path the # rest of this project uses - only built on Linux. if(CMAKE_SYSTEM_NAME STREQUAL "Linux") - add_executable(wireframe_afpacket_demo src/afpacket_capture.cpp) - target_include_directories(wireframe_afpacket_demo PRIVATE include) - target_link_libraries(wireframe_afpacket_demo PRIVATE pcap) + add_executable(packeteer_afpacket_demo src/afpacket_capture.cpp) + target_include_directories(packeteer_afpacket_demo PRIVATE include) + target_link_libraries(packeteer_afpacket_demo PRIVATE pcap) endif() # GUI (secondary to the TUI - see PLAN.md Decisions). Dear ImGui + @@ -79,9 +79,9 @@ add_library(imgui STATIC target_include_directories(imgui PUBLIC ${imgui_SOURCE_DIR} ${imgui_SOURCE_DIR}/backends) target_link_libraries(imgui PUBLIC SDL3::SDL3) -add_executable(wireframe_gui src/gui_main.cpp) -target_include_directories(wireframe_gui PRIVATE include) -target_link_libraries(wireframe_gui PRIVATE pcap Threads::Threads imgui SDL3::SDL3) +add_executable(packeteer_gui src/gui_main.cpp) +target_include_directories(packeteer_gui PRIVATE include) +target_link_libraries(packeteer_gui PRIVATE pcap Threads::Threads imgui SDL3::SDL3) enable_testing() @@ -93,7 +93,7 @@ FetchContent_Declare( ) FetchContent_MakeAvailable(doctest) -add_executable(wireframe_tests +add_executable(packeteer_tests tests/main.cpp tests/test_byteio.cpp tests/test_net.cpp @@ -114,24 +114,24 @@ add_executable(wireframe_tests tests/test_checksum.cpp tests/test_tcp_reassembly.cpp ) -target_include_directories(wireframe_tests PRIVATE include) -target_link_libraries(wireframe_tests PRIVATE doctest::doctest Threads::Threads pcap) +target_include_directories(packeteer_tests PRIVATE include) +target_link_libraries(packeteer_tests PRIVATE doctest::doctest Threads::Threads pcap) -add_test(NAME wireframe_tests COMMAND wireframe_tests) +add_test(NAME packeteer_tests COMMAND packeteer_tests) # libFuzzer harnesses for the hand-rolled decoders - the actual point # of this project (byte layout/alignment/UB) makes these the highest- # value tests in the repo, not an afterthought. Opt-in and clang-only # (libFuzzer is a clang/compiler-rt feature) so a normal `cmake --build` # with the default compiler is unaffected. -option(WIREFRAME_ENABLE_FUZZING "Build libFuzzer harnesses (requires clang)" OFF) -if(WIREFRAME_ENABLE_FUZZING) +option(PACKETEER_ENABLE_FUZZING "Build libFuzzer harnesses (requires clang)" OFF) +if(PACKETEER_ENABLE_FUZZING) if(NOT CMAKE_CXX_COMPILER_ID STREQUAL "Clang") - message(FATAL_ERROR "WIREFRAME_ENABLE_FUZZING requires clang (libFuzzer); " + message(FATAL_ERROR "PACKETEER_ENABLE_FUZZING requires clang (libFuzzer); " "reconfigure with -DCMAKE_CXX_COMPILER=clang++") endif() - function(add_wireframe_fuzz_target name) + function(add_packeteer_fuzz_target name) add_executable(${name} fuzz/${name}.cpp) target_include_directories(${name} PRIVATE include) target_link_libraries(${name} PRIVATE pcap) @@ -139,16 +139,16 @@ if(WIREFRAME_ENABLE_FUZZING) target_link_options(${name} PRIVATE -fsanitize=fuzzer,address,undefined) endfunction() - add_wireframe_fuzz_target(fuzz_ethernet) - add_wireframe_fuzz_target(fuzz_ipv4) - add_wireframe_fuzz_target(fuzz_ipv6) - add_wireframe_fuzz_target(fuzz_tcp) - add_wireframe_fuzz_target(fuzz_udp) - add_wireframe_fuzz_target(fuzz_dns) - add_wireframe_fuzz_target(fuzz_http) - add_wireframe_fuzz_target(fuzz_tls) - add_wireframe_fuzz_target(fuzz_pcapng_reader) - add_wireframe_fuzz_target(fuzz_summarize) - add_wireframe_fuzz_target(fuzz_checksum) - add_wireframe_fuzz_target(fuzz_tcp_reassembly) + add_packeteer_fuzz_target(fuzz_ethernet) + add_packeteer_fuzz_target(fuzz_ipv4) + add_packeteer_fuzz_target(fuzz_ipv6) + add_packeteer_fuzz_target(fuzz_tcp) + add_packeteer_fuzz_target(fuzz_udp) + add_packeteer_fuzz_target(fuzz_dns) + add_packeteer_fuzz_target(fuzz_http) + add_packeteer_fuzz_target(fuzz_tls) + add_packeteer_fuzz_target(fuzz_pcapng_reader) + add_packeteer_fuzz_target(fuzz_summarize) + add_packeteer_fuzz_target(fuzz_checksum) + add_packeteer_fuzz_target(fuzz_tcp_reassembly) endif() @@ -1,8 +1,21 @@ -# Naming - alternatives to "wireframe" - -Current name: **wireframe** - wire (network) + frame (Ethernet/IP frame, -also doubles as a UI "wireframe"). Already a decent pun, kept here as the -baseline to beat. +# Naming + +**Decided: packeteer.** packet + `-eer` (the agent-noun suffix in +*engineer*, *puppeteer*, *musketeer*, *auctioneer* - "one who wields the +thing"), landing on a practitioner/character feel rather than a plain +descriptive tool name. Checked before committing: no existing +open-source packet-capture/analysis project uses it. Two known, +non-blocking collisions worth remembering if this ever comes up - +**Packeteer, Inc.** (1996-2008, NASDAQ: PKTR) was a real networking +company that made *PacketShaper*, a WAN traffic-shaping appliance, +acquired by Blue Coat Systems and fully absorbed since - defunct, no +live trademark, but it'll surface in searches; and the bare +`packeteer` username/org on GitHub is already held by an unrelated +individual, so the repo lives under this project's own namespace +rather than as a top-level org name. + +The rest of this file is the brainstorm that led here, kept for the +record rather than pruned. Landscape checked for collisions / conventions: tcpdump, Wireshark, tshark, termshark, ngrep, ettercap, etherape, snoop, bmon, iftop, nethogs, @@ -19,8 +32,20 @@ bandwhich, trippy, gping, dog, ntap, netwatch. itself. This is the modern Rust-CLI convention. - **Portmanteau of domain nouns**: etherape (ether + ape), snoop, ettercap (etter + cap, Italian "hetter" + capture). +- **Agent-noun branding**: packeteer (packet + -eer, "one who wields + packets") - the convention this project's name actually landed on; + not represented in the landscape checked above, which leaned + Unix-terse/portmanteau/plain-word instead. + +## Names considered along the way (not chosen) -## Candidates +### Wire/frame lineage (the project's working name for most of its build) +`wireframe` - wire (network) + frame (Ethernet/IP frame, also a UI +"wireframe" pun) - was the working name up to this point. Dropped in +favor of packeteer once the project had grown well past "one narrow +decoder" into full L2-L7 dissection, reassembly, checksums, privilege +dropping, and dual frontends - packeteer's agent-noun framing fit +that breadth better than a still-literal wire/frame pun. ### Unix-style short (syscall/tool-terse) - `pktap` - packet + tap @@ -39,6 +64,14 @@ bandwhich, trippy, gping, dog, ntap, netwatch. - `netframe` - `packframe` - `framewire` +- `layershark` / `stackshark` - added later, once L2-L7 were all decoded +- `wirehawk` - same wire+animal cadence as Wireshark, swapping the + predator for "hawk-eyed" (keen observation) instead +- `wirespider` - a spider senses everything through vibrations along + silk threads, a close metaphor for sensing traffic on a wire; + arguably the tightest metaphor fit in this whole lineage +- `orca` - orcas are one of the few animals that hunt sharks; considered + as a way to "supersede" the Wireshark pun rather than extend it ### Evocative single word (bandwhich/trippy/dog convention - plain word, no jargon) - `peek` @@ -49,95 +82,42 @@ bandwhich, trippy, gping, dog, ntap, netwatch. - `snare` - `prowl` - `siphon` +- `dissect` - plain, describes exactly what the tool does at every + layer; risk is it's a generic verb likely to collide with something ### References `std::span` directly (the project's actual technical hook) - `spancap` - `spanview` - `bytespan` - `octospan` +- `netspan` -### Playful / punny -- `Framed` - "you've been framed" (packet frames) -- `Packeteer` -- `Sniffy` - -## Recommendation - -If staying close to the current identity: **frameshark** or **spanshark** - -same wire/frame pun as `wireframe`, but the `-shark` suffix signals -"Wireshark-family tool" the way `tshark`/`termshark` do, which is the -convention someone browsing packet tools will actually recognize. - -If going for the modern terse-CLI convention instead: **peek** or **probe** -- short, typeable, no collision found in the tools checked above. - -`spantap`/`spancap` are worth considering only if you want the name itself -to advertise the `std::span`-over-raw-buffers learning goal from PLAN.md - -more of an in-joke for yourself than a discoverable tool name. - -## More candidates (added after building the L2-L4 decoders) - -Building `include/wireframe/net/{ethernet,ipv4,tcp,udp}.hpp` surfaced a -few more angles - the decoders read one **octet** at a time by hand (no -struct-casting, per PLAN.md's alignment/UB concerns), and the live output -is fundamentally a **packet list view**, which is its own naming lane. - -- `octet` - the actual networking term for a byte; short, real word, - precise, and nobody else in the landscape checked above uses it. +### Byte/octet lane (surfaced once the L2-L4 decoders read one octet at a time by hand) +- `octet` - the actual networking term for a byte; precise, unclaimed + in the landscape checked - `octetap` - `byteframe` - `framecap` - `tapframe` - `pcapview` -- `netspan` - pairs "span" (the `std::span` hook) with "net" instead of - a -tap/-cap suffix -- `wiretap` - plain-word option in the bandwhich/trippy lane; flag: it's - a common enough English/legal term that it may already be taken - somewhere, worth a quick search before committing -- `flagship` - pun on TCP flags (SYN/ACK/FIN etc. decoded in - `tcp.hpp`); cute but arguably too cute / unclear at a glance that it's - a network tool - -No changes to the recommendation above - `frameshark`/`spanshark` (brand -lineage) or `peek`/`probe` (terse-CLI lane) are still the strongest picks. -`octet` is the one addition here worth weighing seriously: it's the most -precise single word for what the tool actually operates on. - -## More candidates (added after TCP reassembly, checksums, privilege -## dropping, and a wider L7 protocol set - DNS/mDNS/HTTP/TLS SNI/SSH/ICMP) - -The project has since grown two angles the earlier lists didn't have -anything for: **stitching segments back into a stream** (TCP -reassembly, wireframe/net/tcp_reassembly.hpp) and **actively dropping -root** the moment the capture handle is open (wireframe/privileges.hpp) -rather than just capturing passively. -- `flowtap` - "flow" is the actual industry term for what - TcpReassembler tracks (a 4-tuple's worth of state across many - packets), not just "stream" -- `stitchtap` - literal, describes reassembly specifically; maybe too - literal/cute -- `reflow` - re- (reassemble) + flow; short, but collides conceptually - with CSS/text "reflow", possibly confusing -- `dropcap` - pun on dropping root/CAP_NET_RAW after opening the - capture handle, which doubles as an actual typography term ("drop - cap": an oversized first letter) - two real meanings landing on the - same word is rare enough to be worth serious consideration -- `polytap` - poly- (many protocols: DNS/HTTP/TLS/mDNS/SSH/ICMP) + tap, - keeps the -tap suffix family from the first list -- `layershark` / `stackshark` - extends the -shark lineage with the - OSI-layer angle (L2 through L7 all decoded by hand now) -- `dissect` - plain English word, no jargon, describes exactly what - the tool does at every layer; downside is it's a very generic verb, - likely to collide with something already using it +### Reassembly/privilege-dropping lane (surfaced once those features landed) +- `flowtap` - "flow" is the real industry term for a TCP 4-tuple's + worth of tracked state, more precise than "stream" +- `stitchtap` - literal description of reassembly +- `reflow` - collides conceptually with CSS/text "reflow" +- `dropcap` - pun on dropping root/CAP_NET_RAW right after opening the + capture handle, which also happens to be a real typography term (an + oversized first letter) - two genuine meanings on one word, the + strongest pun found in this whole search +- `polytap` - poly- (the many protocols dissected: DNS/HTTP/TLS/mDNS/ + SSH/ICMP) + tap -## Current standing recommendation - -Given how much the project now actually does - full L2-L7 decode -(including reassembly), pcapng, filtering, checksum verification, -privilege dropping, dual TUI/GUI frontends - a name that still reads -as "one narrow tool" undersells it less than it used to when this list -started. `frameshark` remains the strongest brand-lineage pick; -`dropcap` is the strongest new candidate from this round, on the -strength of its double meaning actually being true of the tool's own -behavior rather than a stretch. +### Playful / punny +- `Framed` - "you've been framed" (packet frames) +- `Packeteer` - **chosen**, see top of file +- `Sniffy` +- `wiretap` - plain-word option; flagged as possibly already taken + somewhere given how common the word is, never fully checked +- `flagship` - pun on TCP flags (SYN/ACK/FIN); cute but unclear at a + glance that it's a network tool @@ -1,4 +1,4 @@ -# wireframe - Packet Analyzer / Network TUI +# packeteer - Packet Analyzer / Network TUI ## Overview Terminal packet capture and analysis tool. Primary goal: learn the C++ @@ -31,7 +31,7 @@ unowned buffers) via a real-world capture pipeline. 4. [done] Bounded channel + drop-on-backpressure between capture and render 5. [in progress] L7 dissector interface, add protocols incrementally -- interface + DNS + HTTP + TLS SNI + mDNS + SSH banner done - (wireframe/l7/); more protocols can still be added incrementally, + (packeteer/l7/); more protocols can still be added incrementally, by design 6. [done] Filtering (-f <expr>, libpcap's own BPF compiler - see Decisions) 7. [done] Drop privileges after opening the capture handle (see Decisions) @@ -55,20 +55,20 @@ None currently open. OpenGL3 - avoids needing a separate GL function loader as another dependency, which matters more here than raw rendering performance does. src/gui_main.cpp; parity with the CLI/TUI is structural, not - incidental - all three go through the same wireframe::CaptureSession - (wireframe/capture_session.hpp) for device-open/datalink-validate/ + incidental - all three go through the same packeteer::CaptureSession + (packeteer/capture_session.hpp) for device-open/datalink-validate/ filter/pcapng/signal-handler setup, so the GUI can't silently skip a step (e.g. the DLT_RAW check) the way two hand-copied setups would eventually drift. -- Tests: doctest (v2.5.3, FetchContent), tests/ mirrors include/wireframe/. +- Tests: doctest (v2.5.3, FetchContent), tests/ mirrors include/packeteer/. Every module gets unit tests as it's built, not backfilled later -- - `cmake --build build && ./build/wireframe_tests` (or `ctest`) should + `cmake --build build && ./build/packeteer_tests` (or `ctest`) should stay green at every commit. - Filtering: libpcap's own pcap_compile()/pcap_setfilter() (tcpdump syntax, kernel-level via BPF), not a hand-rolled parser - the parser/compiler already exists, is correct, and reimplementing it has no bearing on this project's actual goal (the C++ memory model). - wireframe/filter.hpp wraps compilation; testable without root via + packeteer/filter.hpp wraps compilation; testable without root via pcap_open_dead(). Verified live: -f "tcp port N" and -f icmp each correctly suppressed non-matching traffic that was actually present. - pcap_stats(): CaptureSession::stats() surfaces kernel/interface-level @@ -79,7 +79,7 @@ None currently open. kernel had already received but that were never dispatched to our callback before shutdown, with queue-side drops at 0 throughout. - Fuzzing: libFuzzer harnesses (fuzz/, clang + ASan/UBSan, opt-in via - -DWIREFRAME_ENABLE_FUZZING=ON -DCMAKE_CXX_COMPILER=clang++, separate + -DPACKETEER_ENABLE_FUZZING=ON -DCMAKE_CXX_COMPILER=clang++, separate build-fuzz/ dir) for every hand-rolled decoder plus the pcapng reader and the full summarize_packet() pipeline - the highest-value tests in the repo given the project's actual goal (byte layout/alignment/ @@ -93,7 +93,7 @@ None currently open. in with both a unit test and a passing re-fuzz of the exact crashing input. ~23M total fuzz executions across all 8 harnesses this session, one bug found and fixed, zero remaining crashes. -- HTTP L7 dissector (wireframe/l7/http.hpp): best-effort single-segment +- HTTP L7 dissector (packeteer/l7/http.hpp): best-effort single-segment request/status-line parse (+ Host: header for requests), same scope DNS already has - no TCP stream reassembly, so a message split across packets is only partially visible. This is the first @@ -106,7 +106,7 @@ None currently open. (fuzz_http.cpp, 5.3M runs, no crashes) since the string_view request- line/header scanning is new hand-rolled logic distinct from anything fuzz_summarize's binary-format parsers already cover. -- TLS SNI L7 dissector (wireframe/l7/tls.hpp): parses a ClientHello's +- TLS SNI L7 dissector (packeteer/l7/tls.hpp): parses a ClientHello's record/handshake/extensions structure (nested TLVs, every length bounds-checked against attacker-influenced fields at every level -- the most structurally complex hand-rolled parser in the project) to @@ -134,7 +134,7 @@ None currently open. (extended fuzz_ipv6.cpp, 6.3M runs; fuzz_summarize.cpp indirectly covers it too, 4.3M more) - no crashes. This was the last item on the known-gaps list; none remain. -- Post-capture search: wireframe/search.hpp's matches_search() is a +- Post-capture search: packeteer/search.hpp's matches_search() is a display filter, deliberately distinct from -f's capture filter -- -f decides what's captured (and written to -w); search decides what's shown, without touching either, same distinction Wireshark draws @@ -189,7 +189,7 @@ None currently open. now-static list, and 'q' closes it; Xvfb confirmed the same for the GUI, including a live process check across a multi-second wait to rule out a delayed auto-close. -- Privilege dropping (wireframe/privileges.hpp): after pcap_open_live() +- Privilege dropping (packeteer/privileges.hpp): after pcap_open_live() succeeds - the only operation that actually needs CAP_NET_RAW - and before the datalink check or a -w file is even created, drop from root to the invoking user via sudo's SUDO_UID/SUDO_GID. setuid() to a @@ -213,7 +213,7 @@ None currently open. whole point of "drop after open"). Separately verified the setcap-without-sudo path works with zero privilege escalation at any point in the process's life. -- AF_PACKET/mmap ring buffer (src/afpacket_capture.cpp, wireframe_afpacket_demo, +- AF_PACKET/mmap ring buffer (src/afpacket_capture.cpp, packeteer_afpacket_demo, Linux-only): PLAN.md's originally-listed alternative capture backend, built as a standalone artifact rather than swapped into CaptureSession - the existing pipeline has real, tested value riding on libpcap's @@ -232,7 +232,7 @@ None currently open. ICMPv6 all decoded correctly across a large volume of genuine traffic, no crashes, no leaked sockets/mappings after exit, tests and the rest of the build entirely unaffected by its addition. -- ICMP decoding (wireframe/net/icmp.hpp): previously every ICMPv4 +- ICMP decoding (packeteer/net/icmp.hpp): previously every ICMPv4 packet just showed "proto=1" with nothing further - no dissector existed at all - despite ICMP being most of this session's own test traffic (every ping). ICMPv6 was labeled but not decoded either. @@ -248,12 +248,12 @@ None currently open. and ::1 (proto=58) - request/reply pairs decoded correctly on both, including matching identifier/sequence numbers between each request and its reply. -- -h/--help: both wireframe and wireframe_gui now print real usage +- -h/--help: both packeteer and packeteer_gui now print real usage text (each binary's actual flag set - the GUI never had -x/-t/-g, so its help doesn't claim it does) and exit 0 before touching a device or any privilege at all. Previously -x -t -w -f -g -r all existed with zero discoverability outside reading the source. -- Checksum validation (wireframe/net/checksum.hpp): RFC 1071 Internet +- Checksum validation (packeteer/net/checksum.hpp): RFC 1071 Internet checksum, plus IPv4-header/TCP/UDP verification built on it (IPv6 checksums use a different pseudo-header and different optionality rules - not done here, a reasonable follow-on if wanted). UDP's @@ -279,7 +279,7 @@ None currently open. hardware, not a gap in the reasoning: most real NICs ship tx-checksum offload on by default, which is exactly the scenario -c's opt-in-ness is meant to keep from reading as false positives. -- TCP stream reassembly (wireframe/net/tcp_reassembly.hpp): in-order-only +- TCP stream reassembly (packeteer/net/tcp_reassembly.hpp): in-order-only - out-of-order segments and retransmissions are dropped, not buffered for later reordering. A real limitation, but an honest one for a learning tool captured directly on an endpoint (lo/wlp1s0/tailscale0, @@ -295,7 +295,7 @@ None currently open. TcpReassembler instance lives in main(), and render_packet() does its own minimal Ethernet/IPv4/TCP walk (mirroring checksum_status()) to feed segments in and, when new contiguous bytes come back, re-runs - parse_http() (wireframe/l7/http.hpp) against the joined stream and + parse_http() (packeteer/l7/http.hpp) against the joined stream and prints the result as a distinct "[reassembled ...]" line, not folded into the per-packet summary. Deliberately calls parse_http() directly rather than going through L7Registry, so it isn't gated to port 80 the @@ -315,8 +315,8 @@ None currently open. bounded memory use. - GUI parity for -c/-a: checksum_status() and reassembled_http_status() moved out of main.cpp into a new shared header - (wireframe/packet_diagnostics.hpp) rather than duplicated into - gui_main.cpp - the same reasoning wireframe::CaptureSession exists + (packeteer/packet_diagnostics.hpp) rather than duplicated into + gui_main.cpp - the same reasoning packeteer::CaptureSession exists for at the setup layer, applied here to the diagnostics layer. GUI's hex dump was already always-on for the selected row (no -x-equivalent flag needed); checksum status is computed lazily when a row is @@ -336,7 +336,7 @@ None currently open. a bug - Linux's loopback receive path typically never computes a real TCP checksum at all (CHECKSUM_UNNECESSARY), which is exactly the false-positive scenario -c's opt-in-ness exists to guard against. -- mDNS (wireframe/l7/mdns.hpp) and SSH banner (wireframe/l7/ssh.hpp) +- mDNS (packeteer/l7/mdns.hpp) and SSH banner (packeteer/l7/ssh.hpp) dissectors, registered alongside DNS/HTTP/TLS in l7_registry(). mDNS reuses parse_dns() outright - RFC 6762 keeps DNS's exact wire format, just over UDP 5353 instead of 53 - and deliberately omits diff --git a/fuzz/fuzz_checksum.cpp b/fuzz/fuzz_checksum.cpp index f490d1c..b6127c3 100644 --- a/fuzz/fuzz_checksum.cpp +++ b/fuzz/fuzz_checksum.cpp @@ -1,10 +1,10 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/checksum.hpp" -#include "wireframe/net/ipv4.hpp" +#include "packeteer/net/checksum.hpp" +#include "packeteer/net/ipv4.hpp" -using namespace wireframe::net; +using namespace packeteer::net; // internet_checksum() itself takes arbitrary bytes directly. The // verify_*_checksum_ipv4() wrappers additionally need two addresses, diff --git a/fuzz/fuzz_dns.cpp b/fuzz/fuzz_dns.cpp index 136c8f0..da6f5f1 100644 --- a/fuzz/fuzz_dns.cpp +++ b/fuzz/fuzz_dns.cpp @@ -1,15 +1,15 @@ #include <cstddef> #include <cstdint> -#include "wireframe/l7/dns.hpp" +#include "packeteer/l7/dns.hpp" // DNS name decoding (length-prefixed labels, a historically bug-prone // area in real-world parsers) is the main risk here - fuzz both the // raw parser and the dissector wrapper main.cpp actually calls. extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_dns({data, size}); + packeteer::net::parse_dns({data, size}); - wireframe::net::DnsDissector dissector; + packeteer::net::DnsDissector dissector; dissector.summarize({data, size}); return 0; } diff --git a/fuzz/fuzz_ethernet.cpp b/fuzz/fuzz_ethernet.cpp index 91aa6d5..1153be7 100644 --- a/fuzz/fuzz_ethernet.cpp +++ b/fuzz/fuzz_ethernet.cpp @@ -1,9 +1,9 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/ethernet.hpp" +#include "packeteer/net/ethernet.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_ethernet({data, size}); + packeteer::net::parse_ethernet({data, size}); return 0; } diff --git a/fuzz/fuzz_http.cpp b/fuzz/fuzz_http.cpp index 18a9f69..47029f1 100644 --- a/fuzz/fuzz_http.cpp +++ b/fuzz/fuzz_http.cpp @@ -1,15 +1,15 @@ #include <cstddef> #include <cstdint> -#include "wireframe/l7/http.hpp" +#include "packeteer/l7/http.hpp" // Hand-rolled string_view scanning (request-line split, Host: header // search) is new, bug-prone-by-nature logic - worth fuzzing on its own, // separate from fuzz_summarize's full-pipeline coverage. extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_http({data, size}); + packeteer::net::parse_http({data, size}); - wireframe::net::HttpDissector dissector; + packeteer::net::HttpDissector dissector; dissector.summarize({data, size}); return 0; } diff --git a/fuzz/fuzz_ipv4.cpp b/fuzz/fuzz_ipv4.cpp index 10b6530..2250998 100644 --- a/fuzz/fuzz_ipv4.cpp +++ b/fuzz/fuzz_ipv4.cpp @@ -1,9 +1,9 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/ipv4.hpp" +#include "packeteer/net/ipv4.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_ipv4({data, size}); + packeteer::net::parse_ipv4({data, size}); return 0; } diff --git a/fuzz/fuzz_ipv6.cpp b/fuzz/fuzz_ipv6.cpp index 1cae072..eded2a2 100644 --- a/fuzz/fuzz_ipv6.cpp +++ b/fuzz/fuzz_ipv6.cpp @@ -1,16 +1,16 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/ipv6.hpp" +#include "packeteer/net/ipv6.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - auto packet = wireframe::net::parse_ipv6({data, size}); + auto packet = packeteer::net::parse_ipv6({data, size}); if (packet) { // Also exercise the RFC 5952 address formatter - it does its // own byte manipulation (zero-run detection) independent of // parse_ipv6, worth fuzzing on whatever bytes made it through. - wireframe::net::ipv6_to_string(packet->header.src); - wireframe::net::ipv6_to_string(packet->header.dst); + packeteer::net::ipv6_to_string(packet->header.src); + packeteer::net::ipv6_to_string(packet->header.dst); // Extension-header walking: a loop that repeatedly trusts an // attacker-controlled length field to advance through the @@ -18,7 +18,7 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { // most worth fuzzing. header.next_header seeds which branch of // the walker runs first; the walker's own logic picks whatever // comes after based on each header's own next_header byte. - wireframe::net::walk_ipv6_extension_headers(packet->header.next_header, packet->payload); + packeteer::net::walk_ipv6_extension_headers(packet->header.next_header, packet->payload); } return 0; } diff --git a/fuzz/fuzz_pcapng_reader.cpp b/fuzz/fuzz_pcapng_reader.cpp index e27675b..d62fff5 100644 --- a/fuzz/fuzz_pcapng_reader.cpp +++ b/fuzz/fuzz_pcapng_reader.cpp @@ -2,7 +2,7 @@ #include <cstdint> #include <cstdio> -#include "wireframe/pcapng/reader.hpp" +#include "packeteer/pcapng/reader.hpp" // Reader parses file/network data that isn't necessarily our own // writer's output - a user could point it at any file. fmemopen() @@ -11,7 +11,7 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { FILE* file = fmemopen(const_cast<uint8_t*>(data), size, "rb"); if (file == nullptr) return 0; - wireframe::pcapng::Reader reader(file); + packeteer::pcapng::Reader reader(file); while (reader.next_packet()) { // keep draining until EOF/malformed-block termination } diff --git a/fuzz/fuzz_summarize.cpp b/fuzz/fuzz_summarize.cpp index c1872fd..f887f92 100644 --- a/fuzz/fuzz_summarize.cpp +++ b/fuzz/fuzz_summarize.cpp @@ -2,7 +2,7 @@ #include <cstdint> #include <pcap.h> -#include "wireframe/summarize.hpp" +#include "packeteer/summarize.hpp" // Fuzzes the full decode chain together (Ethernet/RAW -> IPv4/IPv6 -> // TCP/UDP -> L7), not just each layer in isolation - catches bugs @@ -13,6 +13,6 @@ extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { if (size < 1) return 0; int datalink = (data[0] % 2 == 0) ? DLT_EN10MB : DLT_RAW; - wireframe::summarize_packet({data + 1, size - 1}, datalink); + packeteer::summarize_packet({data + 1, size - 1}, datalink); return 0; } diff --git a/fuzz/fuzz_tcp.cpp b/fuzz/fuzz_tcp.cpp index c06a3dc..4035af4 100644 --- a/fuzz/fuzz_tcp.cpp +++ b/fuzz/fuzz_tcp.cpp @@ -1,9 +1,9 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/tcp.hpp" +#include "packeteer/net/tcp.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_tcp({data, size}); + packeteer::net::parse_tcp({data, size}); return 0; } diff --git a/fuzz/fuzz_tcp_reassembly.cpp b/fuzz/fuzz_tcp_reassembly.cpp index 78ca91c..26389d8 100644 --- a/fuzz/fuzz_tcp_reassembly.cpp +++ b/fuzz/fuzz_tcp_reassembly.cpp @@ -1,9 +1,9 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/tcp_reassembly.hpp" +#include "packeteer/net/tcp_reassembly.hpp" -using namespace wireframe::net; +using namespace packeteer::net; // Unlike the other fuzz harnesses, this drives *one* TcpReassembler // with a whole sequence of segments parsed out of a single input -- diff --git a/fuzz/fuzz_tls.cpp b/fuzz/fuzz_tls.cpp index 7860426..dbe98aa 100644 --- a/fuzz/fuzz_tls.cpp +++ b/fuzz/fuzz_tls.cpp @@ -1,7 +1,7 @@ #include <cstddef> #include <cstdint> -#include "wireframe/l7/tls.hpp" +#include "packeteer/l7/tls.hpp" // The nested TLV walk (record -> handshake -> extensions -> SNI, each // level bounds-checked against attacker-influenced length fields) is @@ -9,9 +9,9 @@ // far - exactly the kind of code most likely to have an off-by-one or // an unchecked length feeding a read past the buffer. extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_tls_client_hello({data, size}); + packeteer::net::parse_tls_client_hello({data, size}); - wireframe::net::TlsSniDissector dissector; + packeteer::net::TlsSniDissector dissector; dissector.summarize({data, size}); return 0; } diff --git a/fuzz/fuzz_udp.cpp b/fuzz/fuzz_udp.cpp index f2433f5..557a3fb 100644 --- a/fuzz/fuzz_udp.cpp +++ b/fuzz/fuzz_udp.cpp @@ -1,9 +1,9 @@ #include <cstddef> #include <cstdint> -#include "wireframe/net/udp.hpp" +#include "packeteer/net/udp.hpp" extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) { - wireframe::net::parse_udp({data, size}); + packeteer::net::parse_udp({data, size}); return 0; } diff --git a/include/wireframe/byteio.hpp b/include/packeteer/byteio.hpp index c37c29e..cf0cb19 100644 --- a/include/wireframe/byteio.hpp +++ b/include/packeteer/byteio.hpp @@ -6,7 +6,7 @@ // Manual big-endian reads instead of reinterpret_cast onto a packed // struct: network buffers from pcap aren't guaranteed aligned for // multi-byte integer types, so casting would be undefined behavior. -namespace wireframe { +namespace packeteer { inline std::uint16_t read_be16(std::span<const unsigned char> bytes, std::size_t offset) { return static_cast<std::uint16_t>((bytes[offset] << 8) | bytes[offset + 1]); @@ -19,4 +19,4 @@ inline std::uint32_t read_be32(std::span<const unsigned char> bytes, std::size_t static_cast<std::uint32_t>(bytes[offset + 3]); } -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/capture_queue.hpp b/include/packeteer/capture_queue.hpp index 14794ba..cce254c 100644 --- a/include/wireframe/capture_queue.hpp +++ b/include/packeteer/capture_queue.hpp @@ -11,7 +11,7 @@ // thread (PLAN.md's architecture sketch). Owns a copy of each packet's // bytes since the buffer libpcap hands the callback is only valid for // the duration of that call. -namespace wireframe { +namespace packeteer { struct CapturedPacket { std::uint32_t ts_sec; @@ -95,4 +95,4 @@ private: std::uint64_t dropped_ = 0; }; -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/capture_session.hpp b/include/packeteer/capture_session.hpp index 2e3b05a..cc8ac27 100644 --- a/include/wireframe/capture_session.hpp +++ b/include/packeteer/capture_session.hpp @@ -10,11 +10,11 @@ #include <string> #include <thread> -#include "wireframe/capture_queue.hpp" -#include "wireframe/filter.hpp" -#include "wireframe/pcapng/reader.hpp" -#include "wireframe/pcapng/writer.hpp" -#include "wireframe/privileges.hpp" +#include "packeteer/capture_queue.hpp" +#include "packeteer/filter.hpp" +#include "packeteer/pcapng/reader.hpp" +#include "packeteer/pcapng/writer.hpp" +#include "packeteer/privileges.hpp" // Device-open -> datalink-validate -> filter/pcapng-setup -> signal-hook // pipeline, shared by every frontend (CLI, TUI, GUI). Centralized so a @@ -30,7 +30,7 @@ // needing a second code path. The render/consumer side only ever talks // to a CaptureQueue - it has no way to tell whether packets are // arriving from a live pcap_loop or being read back from disk. -namespace wireframe { +namespace packeteer { namespace detail { inline pcap_t* g_capture_handle = nullptr; @@ -309,4 +309,4 @@ private: std::atomic<bool> replay_stop_requested_{false}; }; -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/filter.hpp b/include/packeteer/filter.hpp index 49fa4ab..1cfcd88 100644 --- a/include/wireframe/filter.hpp +++ b/include/packeteer/filter.hpp @@ -11,7 +11,7 @@ // hand-rolling a second one would be a large, separate project with no // bearing on this one's actual goal (the C++ memory model), so this // wraps the existing implementation instead of reinventing it. -namespace wireframe { +namespace packeteer { // Compiles `expression` against `handle`'s linktype/snaplen into // `out`. `handle` can be a real, already-open capture handle, or a @@ -33,4 +33,4 @@ inline std::optional<std::string> compile_filter(pcap_t* handle, const std::stri return std::nullopt; } -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/l7/dissector.hpp b/include/packeteer/l7/dissector.hpp index 9b2cc32..e918baf 100644 --- a/include/wireframe/l7/dissector.hpp +++ b/include/packeteer/l7/dissector.hpp @@ -9,7 +9,7 @@ // Small interface/vtable for L7 dissectors (PLAN.md's architecture // sketch), so protocols can be registered and added incrementally // without touching the L2-L4 decode path or main.cpp's dispatch logic. -namespace wireframe::net { +namespace packeteer::net { class L7Dissector { public: @@ -42,4 +42,4 @@ private: std::vector<const L7Dissector*> dissectors_; }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/l7/dns.hpp b/include/packeteer/l7/dns.hpp index 5c1ab36..2626887 100644 --- a/include/wireframe/l7/dns.hpp +++ b/include/packeteer/l7/dns.hpp @@ -6,8 +6,8 @@ #include <string> #include <utility> -#include "wireframe/byteio.hpp" -#include "wireframe/l7/dissector.hpp" +#include "packeteer/byteio.hpp" +#include "packeteer/l7/dissector.hpp" // Hand-rolled DNS message parsing: header + the first question record. // Answer/authority/additional records aren't decoded (not needed for a @@ -15,7 +15,7 @@ // followed - a pointer in the question section itself is rejected // rather than chased, keeping this a pure forward scan with no risk of // a pointer loop. -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint16_t kDnsPort = 53; @@ -105,4 +105,4 @@ public: } }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/l7/http.hpp b/include/packeteer/l7/http.hpp index 4780b23..f42bf9f 100644 --- a/include/wireframe/l7/http.hpp +++ b/include/packeteer/l7/http.hpp @@ -6,14 +6,14 @@ #include <string> #include <string_view> -#include "wireframe/l7/dissector.hpp" +#include "packeteer/l7/dissector.hpp" // Best-effort, single-segment HTTP/1.x request/status-line parsing (plus // the Host: header for requests). No TCP stream reassembly, so a // message split across multiple packets is only partially visible here // - the same scope DNS already has (single UDP datagram, no // reassembly). Good enough for a one-line summary, not a full dissector. -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint16_t kHttpPort = 80; @@ -110,4 +110,4 @@ public: } }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/l7/mdns.hpp b/include/packeteer/l7/mdns.hpp index 887d811..b7a8529 100644 --- a/include/wireframe/l7/mdns.hpp +++ b/include/packeteer/l7/mdns.hpp @@ -5,8 +5,8 @@ #include <span> #include <string> -#include "wireframe/l7/dissector.hpp" -#include "wireframe/l7/dns.hpp" +#include "packeteer/l7/dissector.hpp" +#include "packeteer/l7/dns.hpp" // mDNS (RFC 6762) reuses DNS's exact wire format - same header layout, // same question/name encoding - just over a different port (5353, @@ -16,7 +16,7 @@ // here too; the only real difference worth a label is which protocol // this traffic actually is, so real-world capture output doesn't read // "DNS" for traffic that never touched a resolver. -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint16_t kMdnsPort = 5353; @@ -41,4 +41,4 @@ public: } }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/l7/ssh.hpp b/include/packeteer/l7/ssh.hpp index efa471f..261b8e1 100644 --- a/include/wireframe/l7/ssh.hpp +++ b/include/packeteer/l7/ssh.hpp @@ -6,7 +6,7 @@ #include <string> #include <string_view> -#include "wireframe/l7/dissector.hpp" +#include "packeteer/l7/dissector.hpp" // SSH's identification exchange (RFC 4253 section 4.2) is the one part // of an SSH connection sent in the clear, before key exchange starts @@ -16,7 +16,7 @@ // dissector already uses). Only that first line is ever readable -- // everything after key exchange is opaque, so this dissector only ever // has one line to look at, on either side of the connection. -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint16_t kSshPort = 22; @@ -62,4 +62,4 @@ public: } }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/l7/tls.hpp b/include/packeteer/l7/tls.hpp index 1c6dc57..40893fc 100644 --- a/include/wireframe/l7/tls.hpp +++ b/include/packeteer/l7/tls.hpp @@ -5,8 +5,8 @@ #include <span> #include <string> -#include "wireframe/byteio.hpp" -#include "wireframe/l7/dissector.hpp" +#include "packeteer/byteio.hpp" +#include "packeteer/l7/dissector.hpp" // TLS ClientHello -> SNI extension parsing. Most web traffic is TLS // today, so HTTP alone covers a shrinking fraction of it - SNI is what @@ -23,7 +23,7 @@ // the buffer before use - this is exactly the kind of nested, // attacker-influenced TLV structure the project's decoders are meant // to get right. -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint16_t kTlsPort = 443; inline constexpr std::uint8_t kTlsContentTypeHandshake = 0x16; @@ -136,4 +136,4 @@ public: } }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/checksum.hpp b/include/packeteer/net/checksum.hpp index 97e5254..522d90a 100644 --- a/include/wireframe/net/checksum.hpp +++ b/include/packeteer/net/checksum.hpp @@ -4,7 +4,7 @@ #include <span> #include <vector> -#include "wireframe/net/ipv4.hpp" +#include "packeteer/net/ipv4.hpp" // RFC 1071 Internet checksum, and the IPv4/TCP/UDP verification built // on it. Not wired into summarize_packet(): on loopback, and for many @@ -16,7 +16,7 @@ // exactly the interfaces this project has been tested against all // session (lo, tailscale0). Wireshark makes this opt-in for the same // reason; so does this (CLI's -c flag calls these directly). -namespace wireframe::net { +namespace packeteer::net { // One's-complement sum of 16-bit big-endian words, folded back into 16 // bits, then complemented. Used identically by IPv4's header checksum @@ -88,4 +88,4 @@ inline ChecksumResult verify_udp_checksum_ipv4(const Ipv4Address& src, const Ipv return internet_checksum(buf) == 0 ? ChecksumResult::kValid : ChecksumResult::kInvalid; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/ethernet.hpp b/include/packeteer/net/ethernet.hpp index 2da4cc8..5b851bc 100644 --- a/include/wireframe/net/ethernet.hpp +++ b/include/packeteer/net/ethernet.hpp @@ -6,9 +6,9 @@ #include <optional> #include <span> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::size_t kEthernetHeaderLen = 14; inline constexpr std::uint16_t kEthertypeIPv4 = 0x0800; @@ -41,4 +41,4 @@ inline std::optional<EthernetFrame> parse_ethernet(std::span<const unsigned char return EthernetFrame{header, bytes.subspan(kEthernetHeaderLen)}; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/icmp.hpp b/include/packeteer/net/icmp.hpp index af83916..d2613a2 100644 --- a/include/wireframe/net/icmp.hpp +++ b/include/packeteer/net/icmp.hpp @@ -5,7 +5,7 @@ #include <span> #include <string> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" // ICMPv4 (RFC 792) and ICMPv6 (RFC 4443) share the same first-4-byte // shape (Type, Code, Checksum) but a completely different type @@ -14,7 +14,7 @@ // tables, sharing only the header struct shape. Neither protocol has // ports, so this doesn't fit L7Registry's port-keyed dispatch at all; // it's handled directly by protocol number in summarize.hpp instead. -namespace wireframe::net { +namespace packeteer::net { struct IcmpHeader { std::uint8_t type; @@ -81,4 +81,4 @@ inline std::string icmpv6_type_name(std::uint8_t type) { } } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/ipv4.hpp b/include/packeteer/net/ipv4.hpp index f53b4f2..ee77c17 100644 --- a/include/wireframe/net/ipv4.hpp +++ b/include/packeteer/net/ipv4.hpp @@ -6,9 +6,9 @@ #include <optional> #include <span> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::uint8_t kProtoIcmp = 1; inline constexpr std::uint8_t kProtoTcp = 6; @@ -53,4 +53,4 @@ inline std::optional<Ipv4Packet> parse_ipv4(std::span<const unsigned char> bytes return Ipv4Packet{header, bytes.subspan(header_len)}; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/ipv6.hpp b/include/packeteer/net/ipv6.hpp index 4b6b28a..8c048e8 100644 --- a/include/wireframe/net/ipv6.hpp +++ b/include/packeteer/net/ipv6.hpp @@ -8,9 +8,9 @@ #include <span> #include <string> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::size_t kIpv6HeaderLen = 40; inline constexpr std::uint8_t kNextHeaderHopByHop = 0; @@ -170,4 +170,4 @@ inline std::string ipv6_to_string(const Ipv6Address& addr) { return out; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/tcp.hpp b/include/packeteer/net/tcp.hpp index f691a7f..e3d9670 100644 --- a/include/wireframe/net/tcp.hpp +++ b/include/packeteer/net/tcp.hpp @@ -4,9 +4,9 @@ #include <optional> #include <span> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -namespace wireframe::net { +namespace packeteer::net { // Lower 6 bits of the flags byte: URG ACK PSH RST SYN FIN. CWR/ECE (the // top 2 bits) are masked off - not needed for now. @@ -51,4 +51,4 @@ inline std::optional<TcpSegment> parse_tcp(std::span<const unsigned char> bytes) return TcpSegment{header, bytes.subspan(header_len)}; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/tcp_reassembly.hpp b/include/packeteer/net/tcp_reassembly.hpp index 90824a4..3dbf04f 100644 --- a/include/wireframe/net/tcp_reassembly.hpp +++ b/include/packeteer/net/tcp_reassembly.hpp @@ -7,7 +7,7 @@ #include <tuple> #include <vector> -#include "wireframe/net/ipv4.hpp" +#include "packeteer/net/ipv4.hpp" // Minimal, in-order-only TCP stream reassembly: tracks each flow's two // directions separately, accumulating payload bytes as segments arrive @@ -19,13 +19,13 @@ // arrive in order. A capture point far from either endpoint (e.g. a // middlebox) would need real out-of-order buffering this doesn't do. // -// The point: HTTP's dissector (wireframe/l7/http.hpp) only ever sees +// The point: HTTP's dissector (packeteer/l7/http.hpp) only ever sees // one segment at a time, so a request/response split across TCP // segments - a Host: header landing in the second packet of a // request, say - is invisible to it. Feeding the *reassembled* stream // back through the same parse_http() lets it see what single-segment // dissection structurally can't. -namespace wireframe::net { +namespace packeteer::net { struct FlowKey { Ipv4Address ip_a; @@ -122,4 +122,4 @@ private: std::size_t max_flows_; }; -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/net/udp.hpp b/include/packeteer/net/udp.hpp index 07664c2..6602b96 100644 --- a/include/wireframe/net/udp.hpp +++ b/include/packeteer/net/udp.hpp @@ -4,9 +4,9 @@ #include <optional> #include <span> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -namespace wireframe::net { +namespace packeteer::net { inline constexpr std::size_t kUdpHeaderLen = 8; @@ -32,4 +32,4 @@ inline std::optional<UdpDatagram> parse_udp(std::span<const unsigned char> bytes return UdpDatagram{header, bytes.subspan(kUdpHeaderLen)}; } -} // namespace wireframe::net +} // namespace packeteer::net diff --git a/include/wireframe/packet_diagnostics.hpp b/include/packeteer/packet_diagnostics.hpp index 4b9b0c6..f1edeef 100644 --- a/include/wireframe/packet_diagnostics.hpp +++ b/include/packeteer/packet_diagnostics.hpp @@ -5,22 +5,22 @@ #include <span> #include <string> -#include "wireframe/l7/http.hpp" -#include "wireframe/net/checksum.hpp" -#include "wireframe/net/ethernet.hpp" -#include "wireframe/net/ipv4.hpp" -#include "wireframe/net/tcp.hpp" -#include "wireframe/net/tcp_reassembly.hpp" +#include "packeteer/l7/http.hpp" +#include "packeteer/net/checksum.hpp" +#include "packeteer/net/ethernet.hpp" +#include "packeteer/net/ipv4.hpp" +#include "packeteer/net/tcp.hpp" +#include "packeteer/net/tcp_reassembly.hpp" // Checksum validation and TCP stream reassembly are both deliberately // kept out of summarize_packet()'s shared per-packet output - see -// wireframe/net/checksum.hpp and wireframe/net/tcp_reassembly.hpp for +// packeteer/net/checksum.hpp and packeteer/net/tcp_reassembly.hpp for // why each is opt-in (checksum offload false positives; reassembly's // per-flow state and extra per-packet work). Shared between the CLI // (-c/-a) and GUI frontends so they don't hand-roll two separate // Ethernet/IPv4/TCP walks down to the same byte spans - the same -// reasoning wireframe::CaptureSession exists for at the setup layer. -namespace wireframe { +// reasoning packeteer::CaptureSession exists for at the setup layer. +namespace packeteer { inline std::string checksum_status(std::span<const unsigned char> bytes, int datalink) { std::span<const unsigned char> ip_bytes; @@ -89,4 +89,4 @@ inline std::optional<std::string> reassembled_http_status(std::span<const unsign return out; } -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/pcapng/reader.hpp b/include/packeteer/pcapng/reader.hpp index d01b431..264c276 100644 --- a/include/wireframe/pcapng/reader.hpp +++ b/include/packeteer/pcapng/reader.hpp @@ -16,7 +16,7 @@ // writer.hpp emits and what pcapng writers on this class of hardware // (tcpdump, dumpcap) produce. A big-endian file is out of scope - this // pairs with our own writer, not general pcapng interop. -namespace wireframe::pcapng { +namespace packeteer::pcapng { struct PacketRecord { std::uint32_t interface_id; @@ -120,4 +120,4 @@ private: std::optional<std::uint16_t> link_type_; }; -} // namespace wireframe::pcapng +} // namespace packeteer::pcapng diff --git a/include/wireframe/pcapng/writer.hpp b/include/packeteer/pcapng/writer.hpp index 18f6022..59e3c42 100644 --- a/include/wireframe/pcapng/writer.hpp +++ b/include/packeteer/pcapng/writer.hpp @@ -14,8 +14,8 @@ // // Multi-byte fields are written little-endian by hand (matching the // 0x1A2B3C4D byte-order magic below) rather than via struct-casting, -// for the same alignment/UB reasons as the src/wireframe/net decoders. -namespace wireframe::pcapng { +// for the same alignment/UB reasons as the src/packeteer/net decoders. +namespace packeteer::pcapng { inline constexpr std::uint32_t kBlockTypeShb = 0x0A0D0D0A; inline constexpr std::uint32_t kBlockTypeIdb = 0x00000001; @@ -91,4 +91,4 @@ private: std::FILE* file_; }; -} // namespace wireframe::pcapng +} // namespace packeteer::pcapng diff --git a/include/wireframe/privileges.hpp b/include/packeteer/privileges.hpp index 69df725..7c7be7b 100644 --- a/include/wireframe/privileges.hpp +++ b/include/packeteer/privileges.hpp @@ -28,7 +28,7 @@ // straight back to the invoking user immediately, so the rest of the // process's lifetime - including any -w output file, which then ends // up owned by that user instead of root - runs unprivileged either way. -namespace wireframe { +namespace packeteer { // Drops from root to the user who actually invoked the program, via // sudo's SUDO_UID/SUDO_GID (which sudo always sets). A no-op if not @@ -84,4 +84,4 @@ inline std::optional<std::string> drop_privileges_if_root() { #endif } -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/search.hpp b/include/packeteer/search.hpp index 4cb9203..826f184 100644 --- a/include/wireframe/search.hpp +++ b/include/packeteer/search.hpp @@ -4,7 +4,7 @@ #include <cctype> #include <string> -// A display filter, distinct from -f's capture filter (wireframe/filter.hpp): +// A display filter, distinct from -f's capture filter (packeteer/filter.hpp): // -f decides what's captured - and, combined with -w, what's written to // disk. This decides what's shown, without touching either. Same // distinction Wireshark draws between a capture filter and a display @@ -12,7 +12,7 @@ // plain case-insensitive substring match over the packet's summary line // is enough for "find the packets mentioning this host/port", which is // the actual use case. -namespace wireframe { +namespace packeteer { inline bool matches_search(const std::string& haystack, const std::string& needle) { if (needle.empty()) return true; @@ -23,4 +23,4 @@ inline bool matches_search(const std::string& haystack, const std::string& needl return it != haystack.end(); } -} // namespace wireframe +} // namespace packeteer diff --git a/include/wireframe/summarize.hpp b/include/packeteer/summarize.hpp index 840ddf9..77d9ec3 100644 --- a/include/wireframe/summarize.hpp +++ b/include/packeteer/summarize.hpp @@ -8,23 +8,23 @@ #include <pcap.h> -#include "wireframe/l7/dissector.hpp" -#include "wireframe/l7/dns.hpp" -#include "wireframe/l7/http.hpp" -#include "wireframe/l7/mdns.hpp" -#include "wireframe/l7/ssh.hpp" -#include "wireframe/l7/tls.hpp" -#include "wireframe/net/ethernet.hpp" -#include "wireframe/net/icmp.hpp" -#include "wireframe/net/ipv4.hpp" -#include "wireframe/net/ipv6.hpp" -#include "wireframe/net/tcp.hpp" -#include "wireframe/net/udp.hpp" +#include "packeteer/l7/dissector.hpp" +#include "packeteer/l7/dns.hpp" +#include "packeteer/l7/http.hpp" +#include "packeteer/l7/mdns.hpp" +#include "packeteer/l7/ssh.hpp" +#include "packeteer/l7/tls.hpp" +#include "packeteer/net/ethernet.hpp" +#include "packeteer/net/icmp.hpp" +#include "packeteer/net/ipv4.hpp" +#include "packeteer/net/ipv6.hpp" +#include "packeteer/net/tcp.hpp" +#include "packeteer/net/udp.hpp" // Packet -> human-readable summary. Shared by every frontend (plain // CLI, TUI, GUI) so they can't drift apart on what a given packet // decodes to - one source of truth, not three copies to keep in sync. -namespace wireframe { +namespace packeteer { inline std::string mac_to_string(const net::MacAddress& mac) { char buf[18]; @@ -53,7 +53,7 @@ inline std::string tcp_flags_to_string(std::uint8_t flags) { } // Registered once. DNS (UDP) was the first L7 dissector, proving the -// interface (wireframe/l7/dissector.hpp) is enough to add a protocol +// interface (packeteer/l7/dissector.hpp) is enough to add a protocol // without touching the L2-L4 decode path; HTTP (TCP) is the second, // and the first to actually exercise L7Registry's TCP-payload path -- // DNS alone never did, since it only ever runs over UDP port 53. TLS @@ -272,4 +272,4 @@ inline std::vector<std::string> hex_dump_lines(std::span<const unsigned char> by return lines; } -} // namespace wireframe +} // namespace packeteer diff --git a/src/afpacket_capture.cpp b/src/afpacket_capture.cpp index 877bc88..0b5696f 100644 --- a/src/afpacket_capture.cpp +++ b/src/afpacket_capture.cpp @@ -36,8 +36,8 @@ #include <cstring> #include <span> -#include "wireframe/privileges.hpp" -#include "wireframe/summarize.hpp" +#include "packeteer/privileges.hpp" +#include "packeteer/summarize.hpp" namespace { @@ -130,8 +130,8 @@ int main(int argc, char** argv) { // Everything CAP_NET_RAW was needed for is done: socket created, // ring mapped, bound to the interface. Same drop-after-open - // principle as CaptureSession (wireframe/privileges.hpp). - if (auto err = wireframe::drop_privileges_if_root()) { + // principle as CaptureSession (packeteer/privileges.hpp). + if (auto err = packeteer::drop_privileges_if_root()) { std::fprintf(stderr, "failed to drop privileges: %s\n", err->c_str()); munmap(ring, ring_size); close(sock); @@ -171,7 +171,7 @@ int main(int argc, char** argv) { reinterpret_cast<const unsigned char*>(header) + header->tp_mac; std::span<const unsigned char> bytes(packet_start, header->tp_snaplen); - std::printf("%s\n", wireframe::summarize_packet(bytes, DLT_EN10MB).c_str()); + std::printf("%s\n", packeteer::summarize_packet(bytes, DLT_EN10MB).c_str()); std::fflush(stdout); // Hand the slot back to the kernel so it can reuse it for a diff --git a/src/gui_main.cpp b/src/gui_main.cpp index 8a7771a..49f40dc 100644 --- a/src/gui_main.cpp +++ b/src/gui_main.cpp @@ -1,6 +1,6 @@ // GUI frontend (secondary to the TUI - see PLAN.md Decisions). Same // capture/decode/filter/pcapng pipeline as main.cpp's CLI/TUI modes, -// via wireframe::CaptureSession - not a hand-copied setup path, so it +// via packeteer::CaptureSession - not a hand-copied setup path, so it // can't drift on datalink validation, filter errors, or the // pcap_breakloop() shutdown hook the way two independent // implementations eventually would. @@ -22,11 +22,11 @@ #include <string> #include <thread> -#include "wireframe/capture_session.hpp" -#include "wireframe/net/tcp_reassembly.hpp" -#include "wireframe/packet_diagnostics.hpp" -#include "wireframe/search.hpp" -#include "wireframe/summarize.hpp" +#include "packeteer/capture_session.hpp" +#include "packeteer/net/tcp_reassembly.hpp" +#include "packeteer/packet_diagnostics.hpp" +#include "packeteer/search.hpp" +#include "packeteer/summarize.hpp" namespace { @@ -58,11 +58,11 @@ struct SharedState { std::atomic<bool> capture_alive{true}; }; -void consumer_loop(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, - SharedState& state, wireframe::net::TcpReassembler* reassembler) { +void consumer_loop(packeteer::CaptureSession& session, packeteer::CaptureQueue& queue, + SharedState& state, packeteer::net::TcpReassembler* reassembler) { while (auto packet = queue.pop()) { std::span<const unsigned char> bytes{packet->data}; - std::string summary = wireframe::summarize_packet(bytes, session.datalink()); + std::string summary = packeteer::summarize_packet(bytes, session.datalink()); if (auto* writer = session.pcapng_writer()) { writer->write_packet(/*interface_id=*/0, packet->ts_sec, packet->ts_usec, bytes, @@ -71,7 +71,7 @@ void consumer_loop(wireframe::CaptureSession& session, wireframe::CaptureQueue& std::optional<std::string> reassembled_http; if (reassembler) { - reassembled_http = wireframe::reassembled_http_status(bytes, session.datalink(), + reassembled_http = packeteer::reassembled_http_status(bytes, session.datalink(), *reassembler); } @@ -91,7 +91,7 @@ void consumer_loop(wireframe::CaptureSession& session, wireframe::CaptureQueue& void print_usage(const char* argv0) { std::printf( - "wireframe - terminal packet capture and analysis tool (GUI)\n" + "packeteer - terminal packet capture and analysis tool (GUI)\n" "\n" "Usage: %s [options] [interface]\n" "\n" @@ -127,7 +127,7 @@ int main(int argc, char** argv) { } } - wireframe::CaptureSessionOptions options; + packeteer::CaptureSessionOptions options; bool enable_checksums = false; bool enable_reassembly = false; for (int i = 1; i < argc; ++i) { @@ -146,7 +146,7 @@ int main(int argc, char** argv) { } } - wireframe::CaptureSession session; + packeteer::CaptureSession session; if (auto err = session.open(options)) { std::fprintf(stderr, "%s\n", err->c_str()); return 1; @@ -159,7 +159,7 @@ int main(int argc, char** argv) { } SDL_Window* window = - SDL_CreateWindow("wireframe", 1000, 650, SDL_WINDOW_RESIZABLE | SDL_WINDOW_HIDDEN); + SDL_CreateWindow("packeteer", 1000, 650, SDL_WINDOW_RESIZABLE | SDL_WINDOW_HIDDEN); if (window == nullptr) { std::fprintf(stderr, "SDL_CreateWindow failed: %s\n", SDL_GetError()); SDL_Quit(); @@ -181,9 +181,9 @@ int main(int argc, char** argv) { ImGui_ImplSDL3_InitForSDLRenderer(window, renderer); ImGui_ImplSDLRenderer3_Init(renderer); - wireframe::CaptureQueue queue(4096); + packeteer::CaptureQueue queue(4096); SharedState state; - wireframe::net::TcpReassembler reassembler; + packeteer::net::TcpReassembler reassembler; std::thread capture_thread = session.start_capture_thread(queue); std::thread consumer_thread(consumer_loop, std::ref(session), std::ref(queue), std::ref(state), enable_reassembly ? &reassembler : nullptr); @@ -219,7 +219,7 @@ int main(int argc, char** argv) { ImGui::SetNextWindowPos(ImVec2(0, 0)); ImGui::SetNextWindowSize(io.DisplaySize); - ImGui::Begin("wireframe", nullptr, + ImGui::Begin("packeteer", nullptr, ImGuiWindowFlags_NoTitleBar | ImGuiWindowFlags_NoResize | ImGuiWindowFlags_NoMove | ImGuiWindowFlags_NoCollapse); @@ -246,7 +246,7 @@ int main(int argc, char** argv) { { std::lock_guard<std::mutex> lock(state.mutex); for (std::size_t i = 0; i < state.rows.size(); ++i) { - if (!wireframe::matches_search(state.rows[i].summary, search_term)) continue; + if (!packeteer::matches_search(state.rows[i].summary, search_term)) continue; ++shown; // ImGui derives a widget's ID from its label text by @@ -276,7 +276,7 @@ int main(int argc, char** argv) { if (selected_row >= 0 && selected_row < static_cast<int>(state.rows.size())) { const auto& row = state.rows[selected_row]; if (enable_checksums) { - std::string status = wireframe::checksum_status(row.data, session.datalink()); + std::string status = packeteer::checksum_status(row.data, session.datalink()); if (!status.empty()) { ImGui::TextColored(ImVec4(0.6f, 0.8f, 1.0f, 1.0f), "%s", status.c_str()); } @@ -285,7 +285,7 @@ int main(int argc, char** argv) { ImGui::TextColored(ImVec4(0.6f, 1.0f, 0.6f, 1.0f), "%s", row.reassembled_http->c_str()); } - for (const auto& line : wireframe::hex_dump_lines(row.data)) { + for (const auto& line : packeteer::hex_dump_lines(row.data)) { ImGui::TextUnformatted(line.c_str()); } } else { diff --git a/src/main.cpp b/src/main.cpp index 72dd267..82b07a9 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -14,7 +14,7 @@ // packet and counts it instead. // // Stage 5: L7 dissectors register into an L7Registry keyed by port -// (wireframe/l7/dissector.hpp) and get consulted from summarize_packet +// (packeteer/l7/dissector.hpp) and get consulted from summarize_packet // once TCP/UDP decode a port number. DNS is the first one, proving the // interface against real traffic rather than synthetic bytes. // @@ -23,12 +23,12 @@ // traffic silently dropped once the decoder only handled IPv4. // // Stage 6: -f <expr> compiles a tcpdump-style BPF expression via -// libpcap's own compiler (wireframe/filter.hpp) and installs it with +// libpcap's own compiler (packeteer/filter.hpp) and installs it with // pcap_setfilter(), filtering in the kernel before packets ever reach // userspace - rather than hand-rolling a second BPF parser. // // Device-open/datalink-validate/filter/pcapng/signal-handler setup all -// goes through wireframe::CaptureSession (wireframe/capture_session.hpp) +// goes through packeteer::CaptureSession (packeteer/capture_session.hpp) // - the same one gui_main.cpp uses - so the CLI/TUI and GUI frontends // can't drift apart on that setup path. @@ -47,11 +47,11 @@ #include <ftxui/component/screen_interactive.hpp> #include <ftxui/dom/elements.hpp> -#include "wireframe/capture_session.hpp" -#include "wireframe/net/tcp_reassembly.hpp" -#include "wireframe/packet_diagnostics.hpp" -#include "wireframe/search.hpp" -#include "wireframe/summarize.hpp" +#include "packeteer/capture_session.hpp" +#include "packeteer/net/tcp_reassembly.hpp" +#include "packeteer/packet_diagnostics.hpp" +#include "packeteer/search.hpp" +#include "packeteer/summarize.hpp" namespace { @@ -62,7 +62,7 @@ namespace { constexpr std::size_t kQueueCapacity = 4096; void hex_dump(std::span<const unsigned char> bytes) { - for (const auto& line : wireframe::hex_dump_lines(bytes)) { + for (const auto& line : packeteer::hex_dump_lines(bytes)) { std::printf("%s\n", line.c_str()); } std::printf("\n"); @@ -72,15 +72,15 @@ struct RenderOptions { bool verbose_hex; bool verbose_checksums; int datalink; - wireframe::pcapng::Writer* pcapng_writer; - std::string search_term; // display filter - see wireframe/search.hpp - wireframe::net::TcpReassembler* reassembler; // -a only; nullptr means disabled + packeteer::pcapng::Writer* pcapng_writer; + std::string search_term; // display filter - see packeteer/search.hpp + packeteer::net::TcpReassembler* reassembler; // -a only; nullptr means disabled }; -void render_packet(const wireframe::CapturedPacket& packet, const RenderOptions& opts) { +void render_packet(const packeteer::CapturedPacket& packet, const RenderOptions& opts) { std::span<const unsigned char> bytes{packet.data}; - std::string line = wireframe::summarize_packet(bytes, opts.datalink); + std::string line = packeteer::summarize_packet(bytes, opts.datalink); // -g is a display filter, not a capture filter: still written to // -w regardless of whether it matches, since -w should reflect @@ -90,15 +90,15 @@ void render_packet(const wireframe::CapturedPacket& packet, const RenderOptions& packet.original_len); } - if (!wireframe::matches_search(line, opts.search_term)) return; + if (!packeteer::matches_search(line, opts.search_term)) return; if (opts.verbose_checksums) { - std::string status = wireframe::checksum_status(bytes, opts.datalink); + std::string status = packeteer::checksum_status(bytes, opts.datalink); if (!status.empty()) line += " " + status; } std::printf("%s\n", line.c_str()); if (opts.reassembler) { - if (auto status = wireframe::reassembled_http_status(bytes, opts.datalink, + if (auto status = packeteer::reassembled_http_status(bytes, opts.datalink, *opts.reassembler)) { std::printf(" [%s]\n", status->c_str()); } @@ -122,7 +122,7 @@ void render_packet(const wireframe::CapturedPacket& packet, const RenderOptions& // path as Ctrl-C, so there's one shutdown sequence, not two: breakloop // -> capture thread's pcap_loop returns -> queue.stop() -> consumer // drains and calls screen.Exit() -> screen.Loop() returns. -void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, +void run_tui(packeteer::CaptureSession& session, packeteer::CaptureQueue& queue, RenderOptions& opts) { using namespace ftxui; @@ -133,7 +133,7 @@ void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, std::uint64_t packet_count = 0; // '/' search: a display filter over `rows`, independent of the - // capture itself (wireframe/search.hpp) - typed and read only on + // capture itself (packeteer/search.hpp) - typed and read only on // the UI thread (the consumer thread never touches it), so unlike // `rows`/`packet_count` it doesn't need state_mutex. bool searching = false; @@ -145,7 +145,7 @@ void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, std::thread consumer_thread([&] { while (auto packet = queue.pop()) { std::span<const unsigned char> bytes{packet->data}; - std::string line = wireframe::summarize_packet(bytes, opts.datalink); + std::string line = packeteer::summarize_packet(bytes, opts.datalink); if (opts.pcapng_writer) { opts.pcapng_writer->write_packet(/*interface_id=*/0, packet->ts_sec, @@ -182,7 +182,7 @@ void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, Elements lines; std::size_t shown = 0; for (const auto& row : rows) { - if (!wireframe::matches_search(row, search_term)) continue; + if (!packeteer::matches_search(row, search_term)) continue; lines.push_back(text(row)); ++shown; } @@ -209,8 +209,8 @@ void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, footer.push_back(text("search: " + search_term + (searching ? "_" : "")) | color(Color::Green)); } - std::string title = session.is_replay() ? ("wireframe - replaying " + session.device()) - : "wireframe - live capture"; + std::string title = session.is_replay() ? ("packeteer - replaying " + session.device()) + : "packeteer - live capture"; return vbox({ text(title) | bold | color(Color::Cyan), separator(), @@ -266,7 +266,7 @@ void run_tui(wireframe::CaptureSession& session, wireframe::CaptureQueue& queue, void print_usage(const char* argv0) { std::printf( - "wireframe - terminal packet capture and analysis tool\n" + "packeteer - terminal packet capture and analysis tool\n" "\n" "Usage: %s [options] [interface]\n" "\n" @@ -314,7 +314,7 @@ int main(int argc, char** argv) { } } - wireframe::CaptureSessionOptions options; + packeteer::CaptureSessionOptions options; bool tui_mode = false; bool enable_reassembly = false; RenderOptions opts{.verbose_hex = false, @@ -346,7 +346,7 @@ int main(int argc, char** argv) { } } - wireframe::CaptureSession session; + packeteer::CaptureSession session; if (auto err = session.open(options)) { std::fprintf(stderr, "%s\n", err->c_str()); return 1; @@ -355,7 +355,7 @@ int main(int argc, char** argv) { opts.pcapng_writer = session.pcapng_writer(); session.install_signal_handlers(); - wireframe::net::TcpReassembler reassembler; + packeteer::net::TcpReassembler reassembler; if (enable_reassembly) opts.reassembler = &reassembler; if (!tui_mode) { @@ -368,7 +368,7 @@ int main(int argc, char** argv) { } } - wireframe::CaptureQueue queue(kQueueCapacity); + packeteer::CaptureQueue queue(kQueueCapacity); std::thread capture_thread = session.start_capture_thread(queue); if (tui_mode) { diff --git a/tests/test_byteio.cpp b/tests/test_byteio.cpp index 81fa741..3b31752 100644 --- a/tests/test_byteio.cpp +++ b/tests/test_byteio.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/byteio.hpp" +#include "packeteer/byteio.hpp" -using namespace wireframe; +using namespace packeteer; TEST_CASE("read_be16 reads a big-endian 16-bit value") { std::vector<unsigned char> bytes = {0x12, 0x34}; diff --git a/tests/test_capture_queue.cpp b/tests/test_capture_queue.cpp index da2da28..7d56fe0 100644 --- a/tests/test_capture_queue.cpp +++ b/tests/test_capture_queue.cpp @@ -4,9 +4,9 @@ #include <chrono> #include <thread> -#include "wireframe/capture_queue.hpp" +#include "packeteer/capture_queue.hpp" -using namespace wireframe; +using namespace packeteer; TEST_CASE("try_push/pop returns packets in FIFO order") { CaptureQueue queue(4); diff --git a/tests/test_capture_session.cpp b/tests/test_capture_session.cpp index 691131a..dc5f424 100644 --- a/tests/test_capture_session.cpp +++ b/tests/test_capture_session.cpp @@ -6,10 +6,10 @@ #include <string> #include <vector> -#include "wireframe/capture_session.hpp" -#include "wireframe/pcapng/writer.hpp" +#include "packeteer/capture_session.hpp" +#include "packeteer/pcapng/writer.hpp" -using namespace wireframe; +using namespace packeteer; namespace { @@ -20,7 +20,7 @@ struct TempPcapngFile { std::string path; explicit TempPcapngFile(int link_type, const std::vector<std::vector<unsigned char>>& packets) { - char path_template[] = "/tmp/wireframe_test_XXXXXX"; + char path_template[] = "/tmp/packeteer_test_XXXXXX"; int fd = mkstemp(path_template); REQUIRE(fd != -1); path = path_template; diff --git a/tests/test_checksum.cpp b/tests/test_checksum.cpp index 1295499..5ebaea6 100644 --- a/tests/test_checksum.cpp +++ b/tests/test_checksum.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/net/checksum.hpp" +#include "packeteer/net/checksum.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_dns.cpp b/tests/test_dns.cpp index 9a389bb..db5de56 100644 --- a/tests/test_dns.cpp +++ b/tests/test_dns.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/l7/dns.hpp" +#include "packeteer/l7/dns.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_filter.cpp b/tests/test_filter.cpp index 1dd9373..9a0ca69 100644 --- a/tests/test_filter.cpp +++ b/tests/test_filter.cpp @@ -1,7 +1,7 @@ #include <doctest/doctest.h> #include <pcap.h> -#include "wireframe/filter.hpp" +#include "packeteer/filter.hpp" namespace { @@ -23,7 +23,7 @@ TEST_CASE("compile_filter accepts a valid tcpdump-style expression") { REQUIRE(dead.handle != nullptr); bpf_program prog{}; - auto err = wireframe::compile_filter(dead.handle, "tcp port 80", &prog); + auto err = packeteer::compile_filter(dead.handle, "tcp port 80", &prog); CHECK_FALSE(err.has_value()); pcap_freecode(&prog); } @@ -33,7 +33,7 @@ TEST_CASE("compile_filter accepts a compound expression") { REQUIRE(dead.handle != nullptr); bpf_program prog{}; - auto err = wireframe::compile_filter(dead.handle, "host 10.0.0.1 and not icmp", &prog); + auto err = packeteer::compile_filter(dead.handle, "host 10.0.0.1 and not icmp", &prog); CHECK_FALSE(err.has_value()); pcap_freecode(&prog); } @@ -43,7 +43,7 @@ TEST_CASE("compile_filter rejects invalid syntax with an error message") { REQUIRE(dead.handle != nullptr); bpf_program prog{}; - auto err = wireframe::compile_filter(dead.handle, "this is not a valid filter !!", &prog); + auto err = packeteer::compile_filter(dead.handle, "this is not a valid filter !!", &prog); REQUIRE(err.has_value()); CHECK_FALSE(err->empty()); } @@ -53,7 +53,7 @@ TEST_CASE("compile_filter works against DLT_RAW, not just Ethernet") { REQUIRE(dead.handle != nullptr); bpf_program prog{}; - auto err = wireframe::compile_filter(dead.handle, "udp", &prog); + auto err = packeteer::compile_filter(dead.handle, "udp", &prog); CHECK_FALSE(err.has_value()); pcap_freecode(&prog); } @@ -64,6 +64,6 @@ TEST_CASE("compile_filter rejects an Ethernet-only expression against DLT_RAW") bpf_program prog{}; // "ether" primitives are meaningless without a link-layer header. - auto err = wireframe::compile_filter(dead.handle, "ether host 00:11:22:33:44:55", &prog); + auto err = packeteer::compile_filter(dead.handle, "ether host 00:11:22:33:44:55", &prog); CHECK(err.has_value()); } diff --git a/tests/test_http.cpp b/tests/test_http.cpp index 7ccc9ff..2fb532d 100644 --- a/tests/test_http.cpp +++ b/tests/test_http.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/l7/http.hpp" +#include "packeteer/l7/http.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { @@ -69,10 +69,10 @@ TEST_CASE("HttpDissector claims port 80 and its summary matches parse_http") { HttpDissector dissector; CHECK(dissector.port() == kHttpPort); - auto bytes = to_bytes("GET /path HTTP/1.1\r\nHost: wireframe.test\r\n\r\n"); + auto bytes = to_bytes("GET /path HTTP/1.1\r\nHost: packeteer.test\r\n\r\n"); auto summary = dissector.summarize(bytes); REQUIRE(summary.has_value()); CHECK(summary->substr(0, 4) == "HTTP"); CHECK(summary->find("GET /path") != std::string::npos); - CHECK(summary->find("wireframe.test") != std::string::npos); + CHECK(summary->find("packeteer.test") != std::string::npos); } diff --git a/tests/test_icmp.cpp b/tests/test_icmp.cpp index 3dd713e..520e12d 100644 --- a/tests/test_icmp.cpp +++ b/tests/test_icmp.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/net/icmp.hpp" +#include "packeteer/net/icmp.hpp" -using namespace wireframe::net; +using namespace packeteer::net; TEST_CASE("parse_icmpv4 decodes an echo request with identifier/sequence") { std::vector<unsigned char> bytes = {8, 0, 0x00, 0x00, 0x1c, 0x05, 0x00, 0x01}; diff --git a/tests/test_ipv6.cpp b/tests/test_ipv6.cpp index 438fadc..1cce85b 100644 --- a/tests/test_ipv6.cpp +++ b/tests/test_ipv6.cpp @@ -2,10 +2,10 @@ #include <vector> -#include "wireframe/net/ipv4.hpp" // for kProtoTcp -#include "wireframe/net/ipv6.hpp" +#include "packeteer/net/ipv4.hpp" // for kProtoTcp +#include "packeteer/net/ipv6.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_mdns.cpp b/tests/test_mdns.cpp index cad77e7..b095fd7 100644 --- a/tests/test_mdns.cpp +++ b/tests/test_mdns.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/l7/mdns.hpp" +#include "packeteer/l7/mdns.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_net.cpp b/tests/test_net.cpp index 09de9b0..19667da 100644 --- a/tests/test_net.cpp +++ b/tests/test_net.cpp @@ -2,12 +2,12 @@ #include <vector> -#include "wireframe/net/ethernet.hpp" -#include "wireframe/net/ipv4.hpp" -#include "wireframe/net/tcp.hpp" -#include "wireframe/net/udp.hpp" +#include "packeteer/net/ethernet.hpp" +#include "packeteer/net/ipv4.hpp" +#include "packeteer/net/tcp.hpp" +#include "packeteer/net/udp.hpp" -using namespace wireframe::net; +using namespace packeteer::net; TEST_CASE("parse_ethernet decodes header fields and leaves the right payload") { std::vector<unsigned char> bytes = { diff --git a/tests/test_pcapng.cpp b/tests/test_pcapng.cpp index f292d32..aa94167 100644 --- a/tests/test_pcapng.cpp +++ b/tests/test_pcapng.cpp @@ -3,10 +3,10 @@ #include <cstdio> #include <vector> -#include "wireframe/pcapng/reader.hpp" -#include "wireframe/pcapng/writer.hpp" +#include "packeteer/pcapng/reader.hpp" +#include "packeteer/pcapng/writer.hpp" -using namespace wireframe::pcapng; +using namespace packeteer::pcapng; TEST_CASE("pcapng writer/reader round-trip a single packet") { std::FILE* f = std::tmpfile(); diff --git a/tests/test_privileges.cpp b/tests/test_privileges.cpp index 287d654..99951b8 100644 --- a/tests/test_privileges.cpp +++ b/tests/test_privileges.cpp @@ -1,7 +1,7 @@ #include <doctest/doctest.h> #include <unistd.h> -#include "wireframe/privileges.hpp" +#include "packeteer/privileges.hpp" // The actual drop sequence (setuid/setgid) can only be meaningfully // exercised by literally running as root, which a unit test shouldn't @@ -14,5 +14,5 @@ // touch privileges it doesn't have. TEST_CASE("drop_privileges_if_root is a no-op when not running as root") { if (geteuid() == 0) return; // this test only makes sense unprivileged - CHECK_FALSE(wireframe::drop_privileges_if_root().has_value()); + CHECK_FALSE(packeteer::drop_privileges_if_root().has_value()); } diff --git a/tests/test_search.cpp b/tests/test_search.cpp index ed687e0..f1c7580 100644 --- a/tests/test_search.cpp +++ b/tests/test_search.cpp @@ -1,8 +1,8 @@ #include <doctest/doctest.h> -#include "wireframe/search.hpp" +#include "packeteer/search.hpp" -using namespace wireframe; +using namespace packeteer; TEST_CASE("matches_search finds a substring") { CHECK(matches_search("IPv4 10.0.0.1 -> 10.0.0.2 proto=6", "10.0.0.2")); diff --git a/tests/test_ssh.cpp b/tests/test_ssh.cpp index 7c4e339..7201c0e 100644 --- a/tests/test_ssh.cpp +++ b/tests/test_ssh.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/l7/ssh.hpp" +#include "packeteer/l7/ssh.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_summarize.cpp b/tests/test_summarize.cpp index d10053d..ac6f1c0 100644 --- a/tests/test_summarize.cpp +++ b/tests/test_summarize.cpp @@ -4,7 +4,7 @@ #include <string_view> #include <vector> -#include "wireframe/summarize.hpp" +#include "packeteer/summarize.hpp" namespace { @@ -28,7 +28,7 @@ std::vector<unsigned char> ethernet_ipv4_udp_dns_frame() { std::vector<unsigned char> ip(20, 0); ip[0] = 0x45; ip[8] = 64; // ttl - ip[9] = wireframe::net::kProtoUdp; // proto + ip[9] = packeteer::net::kProtoUdp; // proto ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1; // src 10.0.0.1 ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2; // dst 10.0.0.2 @@ -62,7 +62,7 @@ std::vector<unsigned char> ethernet_ipv4_tcp_http_frame() { std::vector<unsigned char> ip(20, 0); ip[0] = 0x45; ip[8] = 64; // ttl - ip[9] = wireframe::net::kProtoTcp; // proto + ip[9] = packeteer::net::kProtoTcp; // proto ip[12] = 10; ip[13] = 0; ip[14] = 0; ip[15] = 1; // src 10.0.0.1 ip[16] = 10; ip[17] = 0; ip[18] = 0; ip[19] = 2; // dst 10.0.0.2 @@ -91,7 +91,7 @@ std::vector<unsigned char> ethernet_ipv6_hopbyhop_tcp_frame() { tcp[13] = 0x02; // SYN std::vector<unsigned char> hop_by_hop = { - static_cast<unsigned char>(wireframe::net::kProtoTcp), + static_cast<unsigned char>(packeteer::net::kProtoTcp), 0x00, // hdr_ext_len = 0 -> total length (0+1)*8 = 8 bytes 0, 0, 0, 0, 0, 0, // option padding }; @@ -101,7 +101,7 @@ std::vector<unsigned char> ethernet_ipv6_hopbyhop_tcp_frame() { std::uint16_t payload_len = static_cast<std::uint16_t>(hop_by_hop.size() + tcp.size()); ip6[4] = static_cast<unsigned char>(payload_len >> 8); ip6[5] = static_cast<unsigned char>(payload_len & 0xFF); - ip6[6] = wireframe::net::kNextHeaderHopByHop; + ip6[6] = packeteer::net::kNextHeaderHopByHop; ip6[7] = 64; // hop_limit ip6[23] = 0x01; // src = ::1 ip6[39] = 0x01; // dst = ::1 @@ -122,7 +122,7 @@ std::vector<unsigned char> ethernet_ipv6_hopbyhop_tcp_frame() { } // namespace TEST_CASE("summarize_packet walks a Hop-by-Hop extension header to reach TCP") { - auto line = wireframe::summarize_packet(ethernet_ipv6_hopbyhop_tcp_frame(), DLT_EN10MB); + auto line = packeteer::summarize_packet(ethernet_ipv6_hopbyhop_tcp_frame(), DLT_EN10MB); CHECK(line == "ETH aa:bb:cc:dd:ee:ff -> 11:22:33:44:55:66 ethertype=0x86dd" " | IPv6 ::1 -> ::1 ttl=64 proto=6" @@ -130,7 +130,7 @@ TEST_CASE("summarize_packet walks a Hop-by-Hop extension header to reach TCP") { } TEST_CASE("summarize_packet decodes a full Ethernet/IPv4/TCP/HTTP frame end to end") { - auto line = wireframe::summarize_packet(ethernet_ipv4_tcp_http_frame(), DLT_EN10MB); + auto line = packeteer::summarize_packet(ethernet_ipv4_tcp_http_frame(), DLT_EN10MB); CHECK(line == "ETH aa:bb:cc:dd:ee:ff -> 11:22:33:44:55:66 ethertype=0x0800" " | IPv4 10.0.0.1 -> 10.0.0.2 ttl=64 proto=6" @@ -139,7 +139,7 @@ TEST_CASE("summarize_packet decodes a full Ethernet/IPv4/TCP/HTTP frame end to e } TEST_CASE("summarize_packet decodes a full Ethernet/IPv4/UDP/DNS frame end to end") { - auto line = wireframe::summarize_packet(ethernet_ipv4_udp_dns_frame(), DLT_EN10MB); + auto line = packeteer::summarize_packet(ethernet_ipv4_udp_dns_frame(), DLT_EN10MB); CHECK(line == "ETH aa:bb:cc:dd:ee:ff -> 11:22:33:44:55:66 ethertype=0x0800" " | IPv4 10.0.0.1 -> 10.0.0.2 ttl=64 proto=17" @@ -149,9 +149,9 @@ TEST_CASE("summarize_packet decodes a full Ethernet/IPv4/UDP/DNS frame end to en TEST_CASE("summarize_packet on DLT_RAW skips the Ethernet line entirely") { auto frame = ethernet_ipv4_udp_dns_frame(); - std::vector<unsigned char> raw(frame.begin() + wireframe::net::kEthernetHeaderLen, frame.end()); + std::vector<unsigned char> raw(frame.begin() + packeteer::net::kEthernetHeaderLen, frame.end()); - auto line = wireframe::summarize_packet(raw, DLT_RAW); + auto line = packeteer::summarize_packet(raw, DLT_RAW); CHECK(line.substr(0, 3) == "RAW"); CHECK(line.find("ETH") == std::string::npos); CHECK(line.find("IPv4 10.0.0.1 -> 10.0.0.2") != std::string::npos); @@ -159,7 +159,7 @@ TEST_CASE("summarize_packet on DLT_RAW skips the Ethernet line entirely") { TEST_CASE("summarize_packet reports a truncated Ethernet frame without decoding further") { std::vector<unsigned char> bytes(10, 0); // shorter than the 14-byte header - auto line = wireframe::summarize_packet(bytes, DLT_EN10MB); + auto line = packeteer::summarize_packet(bytes, DLT_EN10MB); CHECK(line == "[10 bytes] truncated ethernet frame"); } @@ -168,7 +168,7 @@ TEST_CASE("summarize_packet stops after the Ethernet line for a non-IP ethertype 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0xAA, 0xBB, 0xCC, 0xDD, 0xEE, 0xFF, 0x08, 0x06, // ARP, not IPv4/IPv6 }; - auto line = wireframe::summarize_packet(bytes, DLT_EN10MB); + auto line = packeteer::summarize_packet(bytes, DLT_EN10MB); CHECK(line == "ETH aa:bb:cc:dd:ee:ff -> 11:22:33:44:55:66 ethertype=0x0806"); } @@ -176,7 +176,7 @@ TEST_CASE("hex_dump_lines produces one line per 16 bytes, with the right byte co std::vector<unsigned char> bytes(20, 0); for (std::size_t i = 0; i < bytes.size(); ++i) bytes[i] = static_cast<unsigned char>(i); - auto lines = wireframe::hex_dump_lines(bytes); + auto lines = packeteer::hex_dump_lines(bytes); REQUIRE(lines.size() == 2); CHECK(lines[0].substr(0, 6) == "000000"); CHECK(lines[1].substr(0, 6) == "000010"); diff --git a/tests/test_tcp_reassembly.cpp b/tests/test_tcp_reassembly.cpp index b424610..192f12b 100644 --- a/tests/test_tcp_reassembly.cpp +++ b/tests/test_tcp_reassembly.cpp @@ -3,11 +3,11 @@ #include <string> #include <vector> -#include "wireframe/l7/http.hpp" -#include "wireframe/net/tcp.hpp" -#include "wireframe/net/tcp_reassembly.hpp" +#include "packeteer/l7/http.hpp" +#include "packeteer/net/tcp.hpp" +#include "packeteer/net/tcp_reassembly.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { diff --git a/tests/test_tls.cpp b/tests/test_tls.cpp index 65784a9..7a3ad27 100644 --- a/tests/test_tls.cpp +++ b/tests/test_tls.cpp @@ -2,9 +2,9 @@ #include <vector> -#include "wireframe/l7/tls.hpp" +#include "packeteer/l7/tls.hpp" -using namespace wireframe::net; +using namespace packeteer::net; namespace { @@ -124,9 +124,9 @@ TEST_CASE("TlsSniDissector claims port 443 and its summary matches parse_tls_cli TlsSniDissector dissector; CHECK(dissector.port() == kTlsPort); - auto record = build_client_hello("wireframe.test"); + auto record = build_client_hello("packeteer.test"); auto summary = dissector.summarize(record); REQUIRE(summary.has_value()); CHECK(summary->substr(0, 3) == "TLS"); - CHECK(summary->find("SNI=wireframe.test") != std::string::npos); + CHECK(summary->find("SNI=packeteer.test") != std::string::npos); } |