Skip to content

fix(dumpkit): pcap output drops the input's snaplen, thiszone and sigfigs #1165

Description

@JarryShaw

Describe the bug
With format='pcap' (after #1164), the written global header keeps the input's magic, byte order, nanosecond flag and link type, but not its snaplen, thiszone or sigfigs. Every output file carries snaplen 262144, the Header default.

To Reproduce
On the #1164 branch, extract any examples/captures/*.pcap except in.pcap with format='pcap' and compare header bytes 16–19. For example, http.pcap has ffff0000 (65535) and its output has 00000400. 16 captures differ only there, and the records are identical.

Expected behavior
The output header should carry the input header's snaplen, thiszone and sigfigs.

Additional context
PCAPIO._dump_header (pcapkit/dumpkit/pcap.py:~129-142) builds Header from byteorder and nanosecond only, and Extractor._open_output forwards only protocol/byteorder/nanosecond. Found by the #1164 cross-review. The new tests only use in.pcap, whose snaplen happens to be the default.

Activity

  1. added
    fixPull requests that fix a defect (fix: subject prefix)
    blockedDeferred pending another issue or decision; see the last comment for what unblocks it
    on Oct 6, 2026
  2. JarryShaw commented on Oct 6, 2026

    @JarryShaw
    OwnerAuthor

    Blocked until #1164 merges: the pcap output path this fixes only exists on that branch, and the fix would touch pcapkit/foundation/extraction.py and pcapkit/dumpkit/pcap.py alongside it.

  3. JarryShaw commented on Oct 7, 2026

    @JarryShaw
    OwnerAuthor

    Unblocked: #1164 merged at 01:45Z. A worker is on it now.

  4. added
    wipWork in flight - a covering PR is open or an agent is actively on it
    and removed
    blockedDeferred pending another issue or decision; see the last comment for what unblocks it
    on Oct 7, 2026
  5. moved this from Blocked to WIP in PyPCAPKiton Oct 7, 2026
  6. removed
    wipWork in flight - a covering PR is open or an agent is actively on it
    on Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    fixPull requests that fix a defect (fix: subject prefix)

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions