# Naming - alternatives to "wireframe" Current name: **wireframe** - wire (network) + frame (Ethernet/IP frame, also doubles as a UI "wireframe"). Already a decent pun, kept here as the baseline to beat. Landscape checked for collisions / conventions: tcpdump, Wireshark, tshark, termshark, ngrep, ettercap, etherape, snoop, bmon, iftop, nethogs, bandwhich, trippy, gping, dog, ntap, netwatch. ## Conventions those projects use - **Unix terseness**: tcpdump, ngrep, ss, ip - short, lowercase, often a syscall or protocol abbreviation mashed with a verb (dump, grep, top). - **-shark family**: Wireshark → tshark (terminal) → termshark (TUI). A recognizable brand extended by prefixing the interface type. - **Verb-as-noun branding**: bandwhich, trippy, dog, bat, fd, ripgrep - a plain English word or pun, repurposed, no domain jargon in the name itself. This is the modern Rust-CLI convention. - **Portmanteau of domain nouns**: etherape (ether + ape), snoop, ettercap (etter + cap, Italian "hetter" + capture). ## Candidates ### Unix-style short (syscall/tool-terse) - `pktap` - packet + tap - `nettap` - `rawtap` - `spantap` - nods to `std::span`, the project's core learning device - `ethtap` - `frmtap` - frame + tap ### -shark / portmanteau branding (extends the Wireshark lineage like tshark/termshark did) - `frameshark` - `spanshark` - `wiresnoop` - `packsnoop` - `bytewire` - `netframe` - `packframe` - `framewire` ### Evocative single word (bandwhich/trippy/dog convention - plain word, no jargon) - `peek` - `probe` - `glimpse` - `sift` - `trawl` - `snare` - `prowl` - `siphon` ### References `std::span` directly (the project's actual technical hook) - `spancap` - `spanview` - `bytespan` - `octospan` ### Playful / punny - `Framed` - "you've been framed" (packet frames) - `Packeteer` - `Sniffy` ## Recommendation If staying close to the current identity: **frameshark** or **spanshark** - same wire/frame pun as `wireframe`, but the `-shark` suffix signals "Wireshark-family tool" the way `tshark`/`termshark` do, which is the convention someone browsing packet tools will actually recognize. If going for the modern terse-CLI convention instead: **peek** or **probe** - short, typeable, no collision found in the tools checked above. `spantap`/`spancap` are worth considering only if you want the name itself to advertise the `std::span`-over-raw-buffers learning goal from PLAN.md - more of an in-joke for yourself than a discoverable tool name. ## More candidates (added after building the L2-L4 decoders) Building `include/wireframe/net/{ethernet,ipv4,tcp,udp}.hpp` surfaced a few more angles - the decoders read one **octet** at a time by hand (no struct-casting, per PLAN.md's alignment/UB concerns), and the live output is fundamentally a **packet list view**, which is its own naming lane. - `octet` - the actual networking term for a byte; short, real word, precise, and nobody else in the landscape checked above uses it. - `octetap` - `byteframe` - `framecap` - `tapframe` - `pcapview` - `netspan` - pairs "span" (the `std::span` hook) with "net" instead of a -tap/-cap suffix - `wiretap` - plain-word option in the bandwhich/trippy lane; flag: it's a common enough English/legal term that it may already be taken somewhere, worth a quick search before committing - `flagship` - pun on TCP flags (SYN/ACK/FIN etc. decoded in `tcp.hpp`); cute but arguably too cute / unclear at a glance that it's a network tool No changes to the recommendation above - `frameshark`/`spanshark` (brand lineage) or `peek`/`probe` (terse-CLI lane) are still the strongest picks. `octet` is the one addition here worth weighing seriously: it's the most precise single word for what the tool actually operates on.