Describe the bug
With format='pcap' (after #1164), the written global header keeps the input's magic, byte order, nanosecond flag and link type, but not its snaplen, thiszone or sigfigs. Every output file carries snaplen 262144, the Header default.
To Reproduce
On the #1164 branch, extract any examples/captures/*.pcap except in.pcap with format='pcap' and compare header bytes 16–19. For example, http.pcap has ffff0000 (65535) and its output has 00000400. 16 captures differ only there, and the records are identical.
Expected behavior
The output header should carry the input header's snaplen, thiszone and sigfigs.
Additional context
PCAPIO._dump_header (pcapkit/dumpkit/pcap.py:~129-142) builds Header from byteorder and nanosecond only, and Extractor._open_output forwards only protocol/byteorder/nanosecond. Found by the #1164 cross-review. The new tests only use in.pcap, whose snaplen happens to be the default.
Describe the bug
With
format='pcap'(after #1164), the written global header keeps the input's magic, byte order, nanosecond flag and link type, but not itssnaplen,thiszoneorsigfigs. Every output file carries snaplen 262144, theHeaderdefault.To Reproduce
On the #1164 branch, extract any
examples/captures/*.pcapexceptin.pcapwithformat='pcap'and compare header bytes 16–19. For example,http.pcaphasffff0000(65535) and its output has00000400. 16 captures differ only there, and the records are identical.Expected behavior
The output header should carry the input header's
snaplen,thiszoneandsigfigs.Additional context
PCAPIO._dump_header(pcapkit/dumpkit/pcap.py:~129-142) buildsHeaderfrombyteorderandnanosecondonly, andExtractor._open_outputforwards onlyprotocol/byteorder/nanosecond. Found by the #1164 cross-review. The new tests only usein.pcap, whose snaplen happens to be the default.