srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/tests/test_dissector.cpp
AgeCommit message (Collapse)AuthorFilesLines
2026-05-26Add deeper TLS (ServerHello, ALPN); fix a QUIC/TCP false-positive bugsrdusr1-5/+32
TLS: ServerHello now reports the negotiated version and cipher suite alongside the existing ClientHello SNI support, plus ClientHello's ALPN extension. ServerHello's version prefers the supported_versions extension over legacy_version when present - TLS 1.3 always sets legacy_version to 0x0303 for middlebox compatibility, so reading only that field would misreport every real TLS 1.3 connection as 1.2. Cipher suite names are hardcoded only for TLS 1.3's five suites (a small closed set); everything else reports as raw hex rather than a guessed name from a "common suites" list. Live-verifying that against a real Cloudflare TLS 1.3 handshake surfaced a real, unrelated bug in the QUIC dissector added earlier: it was also being tried against TCP port-443 payloads (a side effect of the earlier L7Registry port-sharing fix), and produced false "QUIC" labels on TLS ciphertext continuation fragments - large encrypted records split across multiple TCP segments, each fed to the parser independently since this project doesn't reassemble by default, so a later fragment's effectively random bytes occasionally passed as a plausible QUIC header. Fixed in two layers: parse_quic() now enforces RFC 9000's real 20-byte cap on connection ID lengths, closing most of the long-header false- positive surface; and L7Dissector gained a transport() method (defaulting to kAny, so every other dissector's behavior is unchanged) so QuicDissector can declare itself UDP-only - necessary because the length cap alone can't touch QUIC's short-header form, which by design has no structural signal beyond one bit once header protection can't be removed without connection state. Re-verified against the identical live scenario afterward: zero false QUIC labels on the same Cloudflare TCP handshake, and a repeat of the earlier real HTTP/3 capture confirmed genuine QUIC still decodes correctly on UDP.
2025-11-16Add a cleartext-only QUIC dissector; fix a port-collision bug in L7Registrysrdusr1-0/+74
QUIC decodes only what RFC 9000 sends in cleartext at the framing level: long/short header form, version, long-packet type, and both connection IDs. Everything past that is encrypted from the first protected byte onward, even for Initial packets - decrypting that is real crypto machinery this project deliberately doesn't take on, the same call already made for TLS's SNI-only extraction. Caught a real, previously-latent bug while wiring this in, by design review rather than live-traffic debugging: L7Registry::dissect() returned on the first dissector whose port() matched, even if that dissector's summarize() then failed. Harmless while every registered port was unique, but QUIC is the first protocol here to genuinely share a well-known port with something already registered (443: TLS over TCP, QUIC over UDP - the registry has no transport dimension). Without the fix, tls_dissector would silently claim every port-443 lookup and QUIC would never be reachable. Fixed to try each same-port dissector until one actually succeeds, locked in with stub-dissector tests independent of any real protocol's parsing. Live-verified thoroughly: real HTTP/3 traffic to google.com via `curl --http3-only`, captured on wlp1s0, correctly decoding the full connection lifecycle against Google's actual production QUIC implementation - Initial packets (including a genuine connection ID migration mid-handshake), Handshake packets, and 1-RTT short-header packets. This also confirms the L7Registry fix live: without it none of this would have decoded at all.