srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/NAMES.md
blob: d5cf43e31d9006aebc1691068277bc62edcd372c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
# Naming

**Decided: packeteer.** packet + `-eer` (the agent-noun suffix in
*engineer*, *puppeteer*, *musketeer*, *auctioneer* - "one who wields the
thing"), landing on a practitioner/character feel rather than a plain
descriptive tool name. Checked before committing: no existing
open-source packet-capture/analysis project uses it. Two known,
non-blocking collisions worth remembering if this ever comes up -
**Packeteer, Inc.** (1996-2008, NASDAQ: PKTR) was a real networking
company that made *PacketShaper*, a WAN traffic-shaping appliance,
acquired by Blue Coat Systems and fully absorbed since - defunct, no
live trademark, but it'll surface in searches; and the bare
`packeteer` username/org on GitHub is already held by an unrelated
individual, so the repo lives under this project's own namespace
rather than as a top-level org name.

The rest of this file is the brainstorm that led here, kept for the
record rather than pruned.

Landscape checked for collisions / conventions: tcpdump, Wireshark, tshark,
termshark, ngrep, ettercap, etherape, snoop, bmon, iftop, nethogs,
bandwhich, trippy, gping, dog, ntap, netwatch.

## Conventions those projects use

- **Unix terseness**: tcpdump, ngrep, ss, ip - short, lowercase, often a
  syscall or protocol abbreviation mashed with a verb (dump, grep, top).
- **-shark family**: Wireshark → tshark (terminal) → termshark (TUI). A
  recognizable brand extended by prefixing the interface type.
- **Verb-as-noun branding**: bandwhich, trippy, dog, bat, fd, ripgrep - a
  plain English word or pun, repurposed, no domain jargon in the name
  itself. This is the modern Rust-CLI convention.
- **Portmanteau of domain nouns**: etherape (ether + ape), snoop, ettercap
  (etter + cap, Italian "hetter" + capture).
- **Agent-noun branding**: packeteer (packet + -eer, "one who wields
  packets") - the convention this project's name actually landed on;
  not represented in the landscape checked above, which leaned
  Unix-terse/portmanteau/plain-word instead.

## Names considered along the way (not chosen)

### Wire/frame lineage (the project's working name for most of its build)
`wireframe` - wire (network) + frame (Ethernet/IP frame, also a UI
"wireframe" pun) - was the working name up to this point. Dropped in
favor of packeteer once the project had grown well past "one narrow
decoder" into full L2-L7 dissection, reassembly, checksums, privilege
dropping, and dual frontends - packeteer's agent-noun framing fit
that breadth better than a still-literal wire/frame pun.

### Unix-style short (syscall/tool-terse)
- `pktap` - packet + tap
- `nettap`
- `rawtap`
- `spantap` - nods to `std::span`, the project's core learning device
- `ethtap`
- `frmtap` - frame + tap

### -shark / portmanteau branding (extends the Wireshark lineage like tshark/termshark did)
- `frameshark`
- `spanshark`
- `wiresnoop`
- `packsnoop`
- `bytewire`
- `netframe`
- `packframe`
- `framewire`
- `layershark` / `stackshark` - added later, once L2-L7 were all decoded
- `wirehawk` - same wire+animal cadence as Wireshark, swapping the
  predator for "hawk-eyed" (keen observation) instead
- `wirespider` - a spider senses everything through vibrations along
  silk threads, a close metaphor for sensing traffic on a wire;
  arguably the tightest metaphor fit in this whole lineage
- `orca` - orcas are one of the few animals that hunt sharks; considered
  as a way to "supersede" the Wireshark pun rather than extend it

### Evocative single word (bandwhich/trippy/dog convention - plain word, no jargon)
- `peek`
- `probe`
- `glimpse`
- `sift`
- `trawl`
- `snare`
- `prowl`
- `siphon`
- `dissect` - plain, describes exactly what the tool does at every
  layer; risk is it's a generic verb likely to collide with something

### References `std::span` directly (the project's actual technical hook)
- `spancap`
- `spanview`
- `bytespan`
- `octospan`
- `netspan`

### Byte/octet lane (surfaced once the L2-L4 decoders read one octet at a time by hand)
- `octet` - the actual networking term for a byte; precise, unclaimed
  in the landscape checked
- `octetap`
- `byteframe`
- `framecap`
- `tapframe`
- `pcapview`

### Reassembly/privilege-dropping lane (surfaced once those features landed)
- `flowtap` - "flow" is the real industry term for a TCP 4-tuple's
  worth of tracked state, more precise than "stream"
- `stitchtap` - literal description of reassembly
- `reflow` - collides conceptually with CSS/text "reflow"
- `dropcap` - pun on dropping root/CAP_NET_RAW right after opening the
  capture handle, which also happens to be a real typography term (an
  oversized first letter) - two genuine meanings on one word, the
  strongest pun found in this whole search
- `polytap` - poly- (the many protocols dissected: DNS/HTTP/TLS/mDNS/
  SSH/ICMP) + tap

### Playful / punny
- `Framed` - "you've been framed" (packet frames)
- `Packeteer` - **chosen**, see top of file
- `Sniffy`
- `wiretap` - plain-word option; flagged as possibly already taken
  somewhere given how common the word is, never fully checked
- `flagship` - pun on TCP flags (SYN/ACK/FIN); cute but unclear at a
  glance that it's a network tool