srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-06-26 14:59:00 +0200
committersrdusr <[email protected]>2025-06-26 14:59:00 +0200
commit9046e6a10fd2d987cf6f6dc601ed3a75d286793f (patch)
tree2f28a977e4bf8143a4a8468bc474bbab725b950c /PLAN.md
parentd9bedcec1bce8d15de6403377702d51d1bcb862f (diff)
downloadpacketeer-9046e6a10fd2d987cf6f6dc601ed3a75d286793f.tar.gz
packeteer-9046e6a10fd2d987cf6f6dc601ed3a75d286793f.zip
Unwrap VLAN (802.1Q/802.1ad) tags before protocol dispatch
The single highest-value coverage gap so far, and structural rather than a new dissector: a VLAN-tagged frame's ethertype reads as 0x8100, so every existing decoder - ARP, IPv4, IPv6, and everything built on top of them - was completely invisible on any tagged network. walk_vlan_tags() (ethernet.hpp) is composable and separate from parse_ethernet(), the same relationship walk_ipv6_extension_headers() has to parse_ipv6(): the base parse stays an unconditional fixed-header decode, and this is what a caller reaches for when it needs the real protocol underneath. Handles stacked (QinQ) tags, bounded at 4 levels against a corrupt/hostile frame claiming an unbounded chain. Live-verified with genuine kernel-tagged frames, not synthetic bytes: a dummy0 interface with an 802.1Q dummy0.42 sub-interface (VLAN 42), captured on the parent while pinging out the sub-interface. Both interfaces and the kernel modules they pulled in were torn down afterward.
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md24
1 files changed, 24 insertions, 0 deletions
diff --git a/PLAN.md b/PLAN.md
index c384e20..a9a8da6 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -437,3 +437,27 @@ None currently open.
decoded; fixed by actually binding the "server" send to port 67 (as
real DHCP servers do), which then correctly decoded "DHCP OFFER
yiaddr=192.168.1.50" on top of "DHCP DISCOVER" for the request.
+- VLAN (802.1Q/802.1ad) tag unwrapping: walk_vlan_tags() (ethernet.hpp)
+ was the single highest-value gap found while pushing toward broader
+ protocol coverage - not a new protocol dissector but a structural
+ fix, since a tagged frame's ethertype reads as 0x8100 and every
+ existing decoder (ARP, IPv4, IPv6, and everything built on top of
+ them) was completely invisible on any VLAN-tagged network before
+ this. Composable and separate from parse_ethernet() the same way
+ walk_ipv6_extension_headers() is separate from parse_ipv6() - the
+ base parse stays an unconditional fixed-header decode; this is what
+ a caller reaches for when it needs the real protocol underneath.
+ Handles stacked (QinQ, 802.1ad) tags, bounded at 4 levels so a
+ corrupt/hostile frame claiming an unbounded tag chain can't spin --
+ real QinQ stacks are 2 deep at most. summarize_packet() still shows
+ the literal on-the-wire outer ethertype (0x8100) plus a vlan=N (or
+ vlan=N,M for stacked) annotation, then dispatches ARP/IPv4/IPv6 on
+ the real ethertype underneath. Live-verified with genuine
+ kernel-tagged frames, not synthetic bytes: created a `dummy0`
+ interface with an 802.1Q `dummy0.42` sub-interface (VLAN 42),
+ captured on the parent while pinging out the sub-interface, and got
+ real 802.1Q-tagged ICMP echo requests back - "ethertype=0x8100
+ vlan=42 | IPv4 10.99.99.1 -> 10.99.99.2 ... | ICMP Echo Request"
+ correctly unwrapped. Both virtual interfaces and the dummy/8021q
+ kernel modules they pulled in were torn down afterward, restoring
+ the machine to its prior state.