srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/NAMES.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2024-05-27 22:00:00 +0200
committersrdusr <[email protected]>2024-05-27 22:00:00 +0200
commitb565d7d9c47ca1ec5af0effd828431ee96027d60 (patch)
treefbe0c9c897e78f507443507354d5b1d8fb851099 /NAMES.md
parentfbedc55d5aa861c381701c9f913b34ee7ab57ec4 (diff)
downloadpacketeer-b565d7d9c47ca1ec5af0effd828431ee96027d60.tar.gz
packeteer-b565d7d9c47ca1ec5af0effd828431ee96027d60.zip
Rename project from wireframe to packeteer
Decided on the name after weighing alternatives in NAMES.md: packeteer (packet + -eer, "one who wields packets") fit the project's actual scope better than the wire/frame pun once it had grown into full L2-L7 dissection, reassembly, checksums, privilege dropping, and dual TUI/GUI frontends. No existing packet-capture project uses the name; the one real-world collision (Packeteer, Inc., a networking company acquired and folded into Blue Coat/Symantec by 2008) is long defunct. Mechanical rename throughout: CMake project/target names, the wireframe:: namespace and include/wireframe/ directory (git mv, history preserved), every #include path, CLI/GUI help text, and the project's own working directory. NAMES.md rewritten to record the decision instead of leaving stale self-referential etymology behind from the blind rename pass. Verified after every step: full rebuild (all four targets, no warnings) and the full test suite (128/128 cases, 366/366 assertions) both from a fresh reconfigure and again after the directory move.
Diffstat (limited to 'NAMES.md')
-rw-r--r--NAMES.md148
1 files changed, 64 insertions, 84 deletions
diff --git a/NAMES.md b/NAMES.md
index b07af22..d5cf43e 100644
--- a/NAMES.md
+++ b/NAMES.md
@@ -1,8 +1,21 @@
-# Naming - alternatives to "wireframe"
-
-Current name: **wireframe** - wire (network) + frame (Ethernet/IP frame,
-also doubles as a UI "wireframe"). Already a decent pun, kept here as the
-baseline to beat.
+# Naming
+
+**Decided: packeteer.** packet + `-eer` (the agent-noun suffix in
+*engineer*, *puppeteer*, *musketeer*, *auctioneer* - "one who wields the
+thing"), landing on a practitioner/character feel rather than a plain
+descriptive tool name. Checked before committing: no existing
+open-source packet-capture/analysis project uses it. Two known,
+non-blocking collisions worth remembering if this ever comes up -
+**Packeteer, Inc.** (1996-2008, NASDAQ: PKTR) was a real networking
+company that made *PacketShaper*, a WAN traffic-shaping appliance,
+acquired by Blue Coat Systems and fully absorbed since - defunct, no
+live trademark, but it'll surface in searches; and the bare
+`packeteer` username/org on GitHub is already held by an unrelated
+individual, so the repo lives under this project's own namespace
+rather than as a top-level org name.
+
+The rest of this file is the brainstorm that led here, kept for the
+record rather than pruned.
Landscape checked for collisions / conventions: tcpdump, Wireshark, tshark,
termshark, ngrep, ettercap, etherape, snoop, bmon, iftop, nethogs,
@@ -19,8 +32,20 @@ bandwhich, trippy, gping, dog, ntap, netwatch.
itself. This is the modern Rust-CLI convention.
- **Portmanteau of domain nouns**: etherape (ether + ape), snoop, ettercap
(etter + cap, Italian "hetter" + capture).
+- **Agent-noun branding**: packeteer (packet + -eer, "one who wields
+ packets") - the convention this project's name actually landed on;
+ not represented in the landscape checked above, which leaned
+ Unix-terse/portmanteau/plain-word instead.
+
+## Names considered along the way (not chosen)
-## Candidates
+### Wire/frame lineage (the project's working name for most of its build)
+`wireframe` - wire (network) + frame (Ethernet/IP frame, also a UI
+"wireframe" pun) - was the working name up to this point. Dropped in
+favor of packeteer once the project had grown well past "one narrow
+decoder" into full L2-L7 dissection, reassembly, checksums, privilege
+dropping, and dual frontends - packeteer's agent-noun framing fit
+that breadth better than a still-literal wire/frame pun.
### Unix-style short (syscall/tool-terse)
- `pktap` - packet + tap
@@ -39,6 +64,14 @@ bandwhich, trippy, gping, dog, ntap, netwatch.
- `netframe`
- `packframe`
- `framewire`
+- `layershark` / `stackshark` - added later, once L2-L7 were all decoded
+- `wirehawk` - same wire+animal cadence as Wireshark, swapping the
+ predator for "hawk-eyed" (keen observation) instead
+- `wirespider` - a spider senses everything through vibrations along
+ silk threads, a close metaphor for sensing traffic on a wire;
+ arguably the tightest metaphor fit in this whole lineage
+- `orca` - orcas are one of the few animals that hunt sharks; considered
+ as a way to "supersede" the Wireshark pun rather than extend it
### Evocative single word (bandwhich/trippy/dog convention - plain word, no jargon)
- `peek`
@@ -49,95 +82,42 @@ bandwhich, trippy, gping, dog, ntap, netwatch.
- `snare`
- `prowl`
- `siphon`
+- `dissect` - plain, describes exactly what the tool does at every
+ layer; risk is it's a generic verb likely to collide with something
### References `std::span` directly (the project's actual technical hook)
- `spancap`
- `spanview`
- `bytespan`
- `octospan`
+- `netspan`
-### Playful / punny
-- `Framed` - "you've been framed" (packet frames)
-- `Packeteer`
-- `Sniffy`
-
-## Recommendation
-
-If staying close to the current identity: **frameshark** or **spanshark** -
-same wire/frame pun as `wireframe`, but the `-shark` suffix signals
-"Wireshark-family tool" the way `tshark`/`termshark` do, which is the
-convention someone browsing packet tools will actually recognize.
-
-If going for the modern terse-CLI convention instead: **peek** or **probe**
-- short, typeable, no collision found in the tools checked above.
-
-`spantap`/`spancap` are worth considering only if you want the name itself
-to advertise the `std::span`-over-raw-buffers learning goal from PLAN.md -
-more of an in-joke for yourself than a discoverable tool name.
-
-## More candidates (added after building the L2-L4 decoders)
-
-Building `include/wireframe/net/{ethernet,ipv4,tcp,udp}.hpp` surfaced a
-few more angles - the decoders read one **octet** at a time by hand (no
-struct-casting, per PLAN.md's alignment/UB concerns), and the live output
-is fundamentally a **packet list view**, which is its own naming lane.
-
-- `octet` - the actual networking term for a byte; short, real word,
- precise, and nobody else in the landscape checked above uses it.
+### Byte/octet lane (surfaced once the L2-L4 decoders read one octet at a time by hand)
+- `octet` - the actual networking term for a byte; precise, unclaimed
+ in the landscape checked
- `octetap`
- `byteframe`
- `framecap`
- `tapframe`
- `pcapview`
-- `netspan` - pairs "span" (the `std::span` hook) with "net" instead of
- a -tap/-cap suffix
-- `wiretap` - plain-word option in the bandwhich/trippy lane; flag: it's
- a common enough English/legal term that it may already be taken
- somewhere, worth a quick search before committing
-- `flagship` - pun on TCP flags (SYN/ACK/FIN etc. decoded in
- `tcp.hpp`); cute but arguably too cute / unclear at a glance that it's
- a network tool
-
-No changes to the recommendation above - `frameshark`/`spanshark` (brand
-lineage) or `peek`/`probe` (terse-CLI lane) are still the strongest picks.
-`octet` is the one addition here worth weighing seriously: it's the most
-precise single word for what the tool actually operates on.
-
-## More candidates (added after TCP reassembly, checksums, privilege
-## dropping, and a wider L7 protocol set - DNS/mDNS/HTTP/TLS SNI/SSH/ICMP)
-
-The project has since grown two angles the earlier lists didn't have
-anything for: **stitching segments back into a stream** (TCP
-reassembly, wireframe/net/tcp_reassembly.hpp) and **actively dropping
-root** the moment the capture handle is open (wireframe/privileges.hpp)
-rather than just capturing passively.
-- `flowtap` - "flow" is the actual industry term for what
- TcpReassembler tracks (a 4-tuple's worth of state across many
- packets), not just "stream"
-- `stitchtap` - literal, describes reassembly specifically; maybe too
- literal/cute
-- `reflow` - re- (reassemble) + flow; short, but collides conceptually
- with CSS/text "reflow", possibly confusing
-- `dropcap` - pun on dropping root/CAP_NET_RAW after opening the
- capture handle, which doubles as an actual typography term ("drop
- cap": an oversized first letter) - two real meanings landing on the
- same word is rare enough to be worth serious consideration
-- `polytap` - poly- (many protocols: DNS/HTTP/TLS/mDNS/SSH/ICMP) + tap,
- keeps the -tap suffix family from the first list
-- `layershark` / `stackshark` - extends the -shark lineage with the
- OSI-layer angle (L2 through L7 all decoded by hand now)
-- `dissect` - plain English word, no jargon, describes exactly what
- the tool does at every layer; downside is it's a very generic verb,
- likely to collide with something already using it
+### Reassembly/privilege-dropping lane (surfaced once those features landed)
+- `flowtap` - "flow" is the real industry term for a TCP 4-tuple's
+ worth of tracked state, more precise than "stream"
+- `stitchtap` - literal description of reassembly
+- `reflow` - collides conceptually with CSS/text "reflow"
+- `dropcap` - pun on dropping root/CAP_NET_RAW right after opening the
+ capture handle, which also happens to be a real typography term (an
+ oversized first letter) - two genuine meanings on one word, the
+ strongest pun found in this whole search
+- `polytap` - poly- (the many protocols dissected: DNS/HTTP/TLS/mDNS/
+ SSH/ICMP) + tap
-## Current standing recommendation
-
-Given how much the project now actually does - full L2-L7 decode
-(including reassembly), pcapng, filtering, checksum verification,
-privilege dropping, dual TUI/GUI frontends - a name that still reads
-as "one narrow tool" undersells it less than it used to when this list
-started. `frameshark` remains the strongest brand-lineage pick;
-`dropcap` is the strongest new candidate from this round, on the
-strength of its double meaning actually being true of the tool's own
-behavior rather than a stretch.
+### Playful / punny
+- `Framed` - "you've been framed" (packet frames)
+- `Packeteer` - **chosen**, see top of file
+- `Sniffy`
+- `wiretap` - plain-word option; flagged as possibly already taken
+ somewhere given how common the word is, never fully checked
+- `flagship` - pun on TCP flags (SYN/ACK/FIN); cute but unclear at a
+ glance that it's a network tool