diff options
| author | srdusr <[email protected]> | 2025-06-25 22:11:00 +0200 |
|---|---|---|
| committer | srdusr <[email protected]> | 2025-06-25 22:11:00 +0200 |
| commit | d9bedcec1bce8d15de6403377702d51d1bcb862f (patch) | |
| tree | 363621175b93fa347dc288f9e53a8ede2d453d6d /tests/test_smtp.cpp | |
| parent | f8fc8806401596b08779cf8c88da31408c9b0547 (diff) | |
| download | packeteer-d9bedcec1bce8d15de6403377702d51d1bcb862f.tar.gz packeteer-d9bedcec1bce8d15de6403377702d51d1bcb862f.zip | |
Add NTP and DHCP L7 dissectors
NTP decodes the fixed header's version/mode/stratum - the timestamp
fields need NTP era/fraction fixed-point math to render meaningfully
and add nothing a one-line summary needs, so they're left alone.
DHCP decodes RFC 2131's BOOTP fixed header + magic cookie, then walks
the TLV options bounds-safely for option 53 (message type), plus
yiaddr when the server has assigned one. It's the first dissector
needing two well-known ports (67 server, 68 client) rather than one;
registering at just 67 still matches both directions since
l7_summarize() already falls back from dst_port to src_port.
Verified live: NTP against a real pool.ntp.org query on wlp1s0 (a
genuine stratum-2 reply came back). DHCP over loopback with a
synthetic-but-wire-format-real DISCOVER/OFFER exchange rather than a
real lease renewal, to avoid disrupting this machine's actual network
state - caught a test-setup mistake in the process (both packets
sent from the same ephemeral port instead of the OFFER actually
originating from port 67), not a dissector bug.
Diffstat (limited to 'tests/test_smtp.cpp')
0 files changed, 0 insertions, 0 deletions