diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 60 |
1 files changed, 58 insertions, 2 deletions
@@ -30,8 +30,9 @@ unowned buffers) via a real-world capture pipeline. 3. [done] pcapng read/write 4. [done] Bounded channel + drop-on-backpressure between capture and render 5. [in progress] L7 dissector interface, add protocols incrementally -- - interface + DNS + HTTP + TLS SNI done (wireframe/l7/); more - protocols can still be added incrementally, by design + interface + DNS + HTTP + TLS SNI + mDNS + SSH banner done + (wireframe/l7/); more protocols can still be added incrementally, + by design 6. [done] Filtering (-f <expr>, libpcap's own BPF compiler - see Decisions) 7. [done] Drop privileges after opening the capture handle (see Decisions) 8. [done] TCP stream reassembly, opt-in via -a (see Decisions) @@ -312,3 +313,58 @@ None currently open. without needing active FIN/RST-triggered flow teardown - simpler, and stale entries past those caps don't affect correctness, just bounded memory use. +- GUI parity for -c/-a: checksum_status() and reassembled_http_status() + moved out of main.cpp into a new shared header + (wireframe/packet_diagnostics.hpp) rather than duplicated into + gui_main.cpp - the same reasoning wireframe::CaptureSession exists + for at the setup layer, applied here to the diagnostics layer. GUI's + hex dump was already always-on for the selected row (no -x-equivalent + flag needed); checksum status is computed lazily when a row is + selected (stateless, cheap); reassembled HTTP status has to be + computed at consume time instead (reassembly needs in-order state + across packets), so PacketRow gained an + optional<string> reassembled_http field set once in consumer_loop. + Both are still opt-in via the same -c/-a flag names as the CLI, off + by default. Visually verified under Xvfb (python-xlib synthetic + click) with the same split-segment scenario used to verify -a on the + CLI: selecting the packet whose segment completed the request showed + both "checksums: IP=ok TCP=BAD" and "reassembled request: GET + /split-test Host: split.example.com (72 bytes so far)" together in + the details pane, and a second run with neither flag confirmed both + lines are absent by default. The TCP=BAD reading on lo in that + screenshot is the checksum-offload caveat working as documented, not + a bug - Linux's loopback receive path typically never computes a + real TCP checksum at all (CHECKSUM_UNNECESSARY), which is exactly the + false-positive scenario -c's opt-in-ness exists to guard against. +- mDNS (wireframe/l7/mdns.hpp) and SSH banner (wireframe/l7/ssh.hpp) + dissectors, registered alongside DNS/HTTP/TLS in l7_registry(). + mDNS reuses parse_dns() outright - RFC 6762 keeps DNS's exact wire + format, just over UDP 5353 instead of 53 - and deliberately omits + the id= field DNS's own summary shows, since RFC 6762 18.1 has + multicast queries send it as zero, which would just be "id=0" noise + on every real packet. SSH's identification banner (RFC 4253 4.2) is + the one part of an SSH connection ever sent in the clear - a single + line before key exchange encrypts everything else - so unlike every + other dissector here, there's structurally nothing further to add to + it later. Live-verified against real traffic: SSH against this + machine's actual running sshd via /dev/tcp on lo, correctly decoding + "SSH 2.0 OpenSSH_10.4" (matching the real installed OpenSSH version); + mDNS via a real DNS-wire-format query sent to 127.0.0.1:5353 (no + avahi/mDNS responder running on this sandboxed machine, so a + synthetic-but-wire-format-real packet substituted for organic + traffic), correctly decoding "mDNS query myhost.local type=1" with no + id= field present. +- Fuzzing: two new libFuzzer harnesses added alongside the original + nine - fuzz_checksum (internet_checksum/verify_ipv4_checksum + directly, plus verify_tcp/udp_checksum_ipv4 with the first 8 input + bytes providing src/dst addresses) and fuzz_tcp_reassembly (unlike + every other harness, drives *one* TcpReassembler with a whole + sequence of segments parsed out of a single input, since the + interesting bugs in cross-call state - the flow map, per-direction + sequence tracking, the buffer cap - don't show up from one segment + alone). All 12 harnesses (the original nine plus these two) run + clean - no crashes, no ASan/UBSan errors, no leak/timeout artifacts + - across roughly 90 million total executions in a 20-second-each + pass; summarize's own harness also now exercises the ICMP decode path + added earlier this session and the new mDNS/SSH dissectors, since all + of that lives inside summarize_packet()'s call graph already. |