diff options
| author | srdusr <[email protected]> | 2025-06-26 14:59:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-06-26 14:59:00 +0200 |
| commit | 9046e6a10fd2d987cf6f6dc601ed3a75d286793f (patch) | |
| tree | 2f28a977e4bf8143a4a8468bc474bbab725b950c /PLAN.md | |
| parent | d9bedcec1bce8d15de6403377702d51d1bcb862f (diff) | |
| download | packeteer-9046e6a10fd2d987cf6f6dc601ed3a75d286793f.tar.gz packeteer-9046e6a10fd2d987cf6f6dc601ed3a75d286793f.zip | |
Unwrap VLAN (802.1Q/802.1ad) tags before protocol dispatch
The single highest-value coverage gap so far, and structural rather
than a new dissector: a VLAN-tagged frame's ethertype reads as 0x8100,
so every existing decoder - ARP, IPv4, IPv6, and everything built on
top of them - was completely invisible on any tagged network.
walk_vlan_tags() (ethernet.hpp) is composable and separate from
parse_ethernet(), the same relationship walk_ipv6_extension_headers()
has to parse_ipv6(): the base parse stays an unconditional fixed-header
decode, and this is what a caller reaches for when it needs the real
protocol underneath. Handles stacked (QinQ) tags, bounded at 4 levels
against a corrupt/hostile frame claiming an unbounded chain.
Live-verified with genuine kernel-tagged frames, not synthetic bytes:
a dummy0 interface with an 802.1Q dummy0.42 sub-interface (VLAN 42),
captured on the parent while pinging out the sub-interface. Both
interfaces and the kernel modules they pulled in were torn down
afterward.
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 24 |
1 files changed, 24 insertions, 0 deletions
@@ -437,3 +437,27 @@ None currently open. decoded; fixed by actually binding the "server" send to port 67 (as real DHCP servers do), which then correctly decoded "DHCP OFFER yiaddr=192.168.1.50" on top of "DHCP DISCOVER" for the request. +- VLAN (802.1Q/802.1ad) tag unwrapping: walk_vlan_tags() (ethernet.hpp) + was the single highest-value gap found while pushing toward broader + protocol coverage - not a new protocol dissector but a structural + fix, since a tagged frame's ethertype reads as 0x8100 and every + existing decoder (ARP, IPv4, IPv6, and everything built on top of + them) was completely invisible on any VLAN-tagged network before + this. Composable and separate from parse_ethernet() the same way + walk_ipv6_extension_headers() is separate from parse_ipv6() - the + base parse stays an unconditional fixed-header decode; this is what + a caller reaches for when it needs the real protocol underneath. + Handles stacked (QinQ, 802.1ad) tags, bounded at 4 levels so a + corrupt/hostile frame claiming an unbounded tag chain can't spin -- + real QinQ stacks are 2 deep at most. summarize_packet() still shows + the literal on-the-wire outer ethertype (0x8100) plus a vlan=N (or + vlan=N,M for stacked) annotation, then dispatches ARP/IPv4/IPv6 on + the real ethertype underneath. Live-verified with genuine + kernel-tagged frames, not synthetic bytes: created a `dummy0` + interface with an 802.1Q `dummy0.42` sub-interface (VLAN 42), + captured on the parent while pinging out the sub-interface, and got + real 802.1Q-tagged ICMP echo requests back - "ethertype=0x8100 + vlan=42 | IPv4 10.99.99.1 -> 10.99.99.2 ... | ICMP Echo Request" + correctly unwrapped. Both virtual interfaces and the dummy/8021q + kernel modules they pulled in were torn down afterward, restoring + the machine to its prior state. |