srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md60
1 files changed, 58 insertions, 2 deletions
diff --git a/PLAN.md b/PLAN.md
index bc9ba8e..6defe1d 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -30,8 +30,9 @@ unowned buffers) via a real-world capture pipeline.
3. [done] pcapng read/write
4. [done] Bounded channel + drop-on-backpressure between capture and render
5. [in progress] L7 dissector interface, add protocols incrementally --
- interface + DNS + HTTP + TLS SNI done (wireframe/l7/); more
- protocols can still be added incrementally, by design
+ interface + DNS + HTTP + TLS SNI + mDNS + SSH banner done
+ (wireframe/l7/); more protocols can still be added incrementally,
+ by design
6. [done] Filtering (-f <expr>, libpcap's own BPF compiler - see Decisions)
7. [done] Drop privileges after opening the capture handle (see Decisions)
8. [done] TCP stream reassembly, opt-in via -a (see Decisions)
@@ -312,3 +313,58 @@ None currently open.
without needing active FIN/RST-triggered flow teardown - simpler,
and stale entries past those caps don't affect correctness, just
bounded memory use.
+- GUI parity for -c/-a: checksum_status() and reassembled_http_status()
+ moved out of main.cpp into a new shared header
+ (wireframe/packet_diagnostics.hpp) rather than duplicated into
+ gui_main.cpp - the same reasoning wireframe::CaptureSession exists
+ for at the setup layer, applied here to the diagnostics layer. GUI's
+ hex dump was already always-on for the selected row (no -x-equivalent
+ flag needed); checksum status is computed lazily when a row is
+ selected (stateless, cheap); reassembled HTTP status has to be
+ computed at consume time instead (reassembly needs in-order state
+ across packets), so PacketRow gained an
+ optional<string> reassembled_http field set once in consumer_loop.
+ Both are still opt-in via the same -c/-a flag names as the CLI, off
+ by default. Visually verified under Xvfb (python-xlib synthetic
+ click) with the same split-segment scenario used to verify -a on the
+ CLI: selecting the packet whose segment completed the request showed
+ both "checksums: IP=ok TCP=BAD" and "reassembled request: GET
+ /split-test Host: split.example.com (72 bytes so far)" together in
+ the details pane, and a second run with neither flag confirmed both
+ lines are absent by default. The TCP=BAD reading on lo in that
+ screenshot is the checksum-offload caveat working as documented, not
+ a bug - Linux's loopback receive path typically never computes a
+ real TCP checksum at all (CHECKSUM_UNNECESSARY), which is exactly the
+ false-positive scenario -c's opt-in-ness exists to guard against.
+- mDNS (wireframe/l7/mdns.hpp) and SSH banner (wireframe/l7/ssh.hpp)
+ dissectors, registered alongside DNS/HTTP/TLS in l7_registry().
+ mDNS reuses parse_dns() outright - RFC 6762 keeps DNS's exact wire
+ format, just over UDP 5353 instead of 53 - and deliberately omits
+ the id= field DNS's own summary shows, since RFC 6762 18.1 has
+ multicast queries send it as zero, which would just be "id=0" noise
+ on every real packet. SSH's identification banner (RFC 4253 4.2) is
+ the one part of an SSH connection ever sent in the clear - a single
+ line before key exchange encrypts everything else - so unlike every
+ other dissector here, there's structurally nothing further to add to
+ it later. Live-verified against real traffic: SSH against this
+ machine's actual running sshd via /dev/tcp on lo, correctly decoding
+ "SSH 2.0 OpenSSH_10.4" (matching the real installed OpenSSH version);
+ mDNS via a real DNS-wire-format query sent to 127.0.0.1:5353 (no
+ avahi/mDNS responder running on this sandboxed machine, so a
+ synthetic-but-wire-format-real packet substituted for organic
+ traffic), correctly decoding "mDNS query myhost.local type=1" with no
+ id= field present.
+- Fuzzing: two new libFuzzer harnesses added alongside the original
+ nine - fuzz_checksum (internet_checksum/verify_ipv4_checksum
+ directly, plus verify_tcp/udp_checksum_ipv4 with the first 8 input
+ bytes providing src/dst addresses) and fuzz_tcp_reassembly (unlike
+ every other harness, drives *one* TcpReassembler with a whole
+ sequence of segments parsed out of a single input, since the
+ interesting bugs in cross-call state - the flow map, per-direction
+ sequence tracking, the buffer cap - don't show up from one segment
+ alone). All 12 harnesses (the original nine plus these two) run
+ clean - no crashes, no ASan/UBSan errors, no leak/timeout artifacts
+ - across roughly 90 million total executions in a 20-second-each
+ pass; summarize's own harness also now exercises the ICMP decode path
+ added earlier this session and the new mDNS/SSH dissectors, since all
+ of that lives inside summarize_packet()'s call graph already.