srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
authorsrdusr <[email protected]>2025-06-25 22:11:00 +0200
committersrdusr <[email protected]>2025-06-25 22:11:00 +0200
commitd9bedcec1bce8d15de6403377702d51d1bcb862f (patch)
tree363621175b93fa347dc288f9e53a8ede2d453d6d /PLAN.md
parentf8fc8806401596b08779cf8c88da31408c9b0547 (diff)
downloadpacketeer-d9bedcec1bce8d15de6403377702d51d1bcb862f.tar.gz
packeteer-d9bedcec1bce8d15de6403377702d51d1bcb862f.zip
Add NTP and DHCP L7 dissectors
NTP decodes the fixed header's version/mode/stratum - the timestamp fields need NTP era/fraction fixed-point math to render meaningfully and add nothing a one-line summary needs, so they're left alone. DHCP decodes RFC 2131's BOOTP fixed header + magic cookie, then walks the TLV options bounds-safely for option 53 (message type), plus yiaddr when the server has assigned one. It's the first dissector needing two well-known ports (67 server, 68 client) rather than one; registering at just 67 still matches both directions since l7_summarize() already falls back from dst_port to src_port. Verified live: NTP against a real pool.ntp.org query on wlp1s0 (a genuine stratum-2 reply came back). DHCP over loopback with a synthetic-but-wire-format-real DISCOVER/OFFER exchange rather than a real lease renewal, to avoid disrupting this machine's actual network state - caught a test-setup mistake in the process (both packets sent from the same ephemeral port instead of the OFFER actually originating from port 67), not a dissector bug.
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md31
1 files changed, 31 insertions, 0 deletions
diff --git a/PLAN.md b/PLAN.md
index 5c0f2f1..c384e20 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -406,3 +406,34 @@ None currently open.
split-segment HTTP scenario used to verify -a on the CLI and GUI:
both "checksums: IP=ok TCP=..." and "[reassembled request: ... Host:
... (72 bytes so far)]" appeared correctly inline in the packet list.
+- NTP (packeteer/l7/ntp.hpp) and DHCP (packeteer/l7/dhcp.hpp)
+ dissectors. NTP decodes only the first two header bytes (version,
+ mode, stratum) - the timestamp fields need NTP era/fraction
+ fixed-point math to render meaningfully and add nothing a one-line
+ summary needs, so they're left alone. DHCP decodes RFC 2131's fixed
+ 236-byte BOOTP header + 4-byte magic cookie, then walks the
+ variable-length TLV options bounds-safely to find option 53 (message
+ type) - the one field that actually says DISCOVER/OFFER/REQUEST/ACK/
+ etc; other options are skipped over, not decoded. yiaddr (the address
+ being offered/assigned) is shown when non-zero since it's genuinely
+ new information, not a repeat of the IPv4 line's src/dst above it --
+ formatted with a small local snprintf helper inside dhcp.hpp rather
+ than reusing summarize.hpp's ipv4_to_string, since summarize.hpp
+ already depends on this header and the reverse include would be
+ circular (same reasoning as arp_summary living in summarize.hpp
+ instead of arp.hpp, just resolved in the other direction here).
+ DHCP is the first dissector needing two well-known ports (67 server,
+ 68 client) rather than one; registering at just 67 still matches
+ both directions because l7_summarize() already falls back from
+ dst_port to src_port. Verified live: NTP against a real query to
+ pool.ntp.org on wlp1s0 ("NTP v4 client stratum=0" request, "NTP v4
+ server stratum=2" reply from an actual stratum-2 timeserver at
+ 196.10.55.57). DHCP verified over loopback with a synthetic-but-
+ wire-format-real DISCOVER/OFFER exchange (not a real DHCP renewal,
+ to avoid disrupting this machine's actual network state) - caught a
+ test-setup mistake in the process, not a dissector bug: the first
+ attempt sent both packets from the same arbitrary ephemeral port, so
+ the OFFER's source port never matched DHCP's server port and nothing
+ decoded; fixed by actually binding the "server" send to port 67 (as
+ real DHCP servers do), which then correctly decoded "DHCP OFFER
+ yiaddr=192.168.1.50" on top of "DHCP DISCOVER" for the request.