Repository navigation
fix(foundation): restore record_header as the shared global-header step for third-party engines - #1149
Merged
Conversation
This was referenced Oct 6, 2026
Owner
Author
|
Cross-review verdict on
Nits:
|
JarryShaw
force-pushed
the
fix/1104-record-header
branch
from
October 6, 2026 21:48
d3f88e7 to
d99ebcc
Compare
JarryShaw
force-pushed
the
fix/1104-record-header
branch
from
October 6, 2026 21:50
d99ebcc to
afdf756
Compare
Contributor
|
Coverage: 86.80% (unit tier, Python 3.14,
Per-file detail: the |
Owner
Author
|
Cross-review verdict on
|
…ep for third-party engines The DPKT, Scapy and PyShark engines call Extractor.record_header() at setup again, as they did before 429f1a0 and 74707eb. Their output now opens with the header record the built-in engines write ("Global Header" for PCAP, "Section Header 1" for PCAP-NG), and _offmt is set at header time, so Extractor.format works on a capture with no frames. The per-frame _offmt assignments in the three engines are dropped as redundant. test_runtime_engines' stand-in extractor gains a record_header mock, and its DPKT read_frame _offmt pin is updated. Closes #1104
JarryShaw
force-pushed
the
fix/1104-record-header
branch
from
October 6, 2026 22:15
afdf756 to
1f3ac16
Compare
Owner
Author
|
Cross-review verdict on
|
4 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
make pylint,make mypy,make isort). Ran these with the Makefile flags on the four source files: no new pylint codes, the same 2 pre-existing mypy errors inscapy.py, and isort clean.make testpasses, and a test case covers the change. Only the modules listed below were run.What is the purpose of your pull request?
fix— corrects a defectDescription of your pull request and other information
Closes #1104 (option 3). DPKT, Scapy and PyShark call
ext.record_header()at setup again, as they did before429f1a09a/74707ebc8. That call also sets_offmt, so the per-frame_offmtassignments were redundant and are removed.Behaviour change (all three engines): JSON, plist and tree output gains one leading record,
Global Headerfor PCAP orSection Header 1for PCAP-NG. The record is identical to the default engine's. Withfiles=True, aGlobal Header.<ext>file is written as well. The frame records are unchanged.Extractor.formatnow works on a capture with no frames, where it used to raiseAttributeError. DPKT still takes the link type fromreader.datalink(), because a PCAP-NG section header carries none.Probe (
in.pcap/dhcp.pcapng/ a 0-frame PCAP,format='json'):['Frame 1', …]; 0 frames →.formatraisesAttributeError: ... '_offmt'['Global Header', 'Frame 1', …]/['Section Header 1', …]; 0 frames →.format == 'json'Not #1127:
format='pcap'fails on every engine, the default one included, atextraction.py:1193.Extractor.__init__buildsPCAPIO(ofnm)there, before any engine or header step runs. So this change cannot fix it.Tests: new
tests/foundation/test_extraction_record_header_unit.pygives 10 passed, and 10 failed with the source diff reverse-applied. PyShark is installed, but it is unsupported on 3.14, so it is driven through a stand-in module.test_runtime_engines.pywas edited: its stand-in extractor gainsrecord_header, and the DPKT_offmtpin now expects the header-time assignment. Modules run: runtime_engines 5 passed, test_extraction 22, offmt_unit 3, no_eof 11, scapy_engine 2, pyshark_engine 8+1 skipped, integration engine_parity 5, engine_runtime 4, output_formats 13+1 skipped, files_output_naming 4, cli_subprocess 14,tests/project385 passed, 1 skipped.