srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/NAMES.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2024-05-21 22:24:00 +0200
committersrdusr <[email protected]>2024-05-21 22:24:00 +0200
commitfbedc55d5aa861c381701c9f913b34ee7ab57ec4 (patch)
treed34c3648b61d417f2a5d8690e0eb4a76bd64c943 /NAMES.md
parente0f4c701028aa81026a17cf9ebfb36112184f4bc (diff)
downloadpacketeer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.tar.gz
packeteer-fbedc55d5aa861c381701c9f913b34ee7ab57ec4.zip
Add GUI parity for -c/-a, mDNS/SSH dissectors, and two new fuzz harnesses
GUI parity: checksum_status()/reassembled_http_status() moved out of main.cpp into a shared wireframe/packet_diagnostics.hpp so the GUI can show the same -c/-a diagnostics for the selected packet without duplicating the Ethernet/IPv4/TCP walk. Visually verified under Xvfb with the same split-segment scenario used to verify -a on the CLI. Two new L7 dissectors: mDNS (reuses parse_dns outright - RFC 6762 keeps DNS's wire format, just a different port) and SSH's cleartext identification banner. Live-verified against this machine's real sshd and a real DNS-wire-format packet sent to port 5353. Two new fuzz harnesses (fuzz_checksum, fuzz_tcp_reassembly) covering code added here that the original nine harnesses never touched. All 12 run clean across ~90M executions with no crashes. NAMES.md and PLAN.md updated with this round's decisions and naming candidates.
Diffstat (limited to 'NAMES.md')
-rw-r--r--NAMES.md39
1 files changed, 39 insertions, 0 deletions
diff --git a/NAMES.md b/NAMES.md
index ae0e1e6..b07af22 100644
--- a/NAMES.md
+++ b/NAMES.md
@@ -102,3 +102,42 @@ No changes to the recommendation above - `frameshark`/`spanshark` (brand
lineage) or `peek`/`probe` (terse-CLI lane) are still the strongest picks.
`octet` is the one addition here worth weighing seriously: it's the most
precise single word for what the tool actually operates on.
+
+## More candidates (added after TCP reassembly, checksums, privilege
+## dropping, and a wider L7 protocol set - DNS/mDNS/HTTP/TLS SNI/SSH/ICMP)
+
+The project has since grown two angles the earlier lists didn't have
+anything for: **stitching segments back into a stream** (TCP
+reassembly, wireframe/net/tcp_reassembly.hpp) and **actively dropping
+root** the moment the capture handle is open (wireframe/privileges.hpp)
+rather than just capturing passively.
+
+- `flowtap` - "flow" is the actual industry term for what
+ TcpReassembler tracks (a 4-tuple's worth of state across many
+ packets), not just "stream"
+- `stitchtap` - literal, describes reassembly specifically; maybe too
+ literal/cute
+- `reflow` - re- (reassemble) + flow; short, but collides conceptually
+ with CSS/text "reflow", possibly confusing
+- `dropcap` - pun on dropping root/CAP_NET_RAW after opening the
+ capture handle, which doubles as an actual typography term ("drop
+ cap": an oversized first letter) - two real meanings landing on the
+ same word is rare enough to be worth serious consideration
+- `polytap` - poly- (many protocols: DNS/HTTP/TLS/mDNS/SSH/ICMP) + tap,
+ keeps the -tap suffix family from the first list
+- `layershark` / `stackshark` - extends the -shark lineage with the
+ OSI-layer angle (L2 through L7 all decoded by hand now)
+- `dissect` - plain English word, no jargon, describes exactly what
+ the tool does at every layer; downside is it's a very generic verb,
+ likely to collide with something already using it
+
+## Current standing recommendation
+
+Given how much the project now actually does - full L2-L7 decode
+(including reassembly), pcapng, filtering, checksum verification,
+privilege dropping, dual TUI/GUI frontends - a name that still reads
+as "one narrow tool" undersells it less than it used to when this list
+started. `frameshark` remains the strongest brand-lineage pick;
+`dropcap` is the strongest new candidate from this round, on the
+strength of its double meaning actually being true of the tool's own
+behavior rather than a stretch.