Repository navigation
fix(extraction): extraction with format='pcap' fails (#1127) - #1164
Merged
Merged
Conversation
Extractor.__init__ created the output writer before any engine had read the global header, so PCAPIO was built without the link type it needs and every engine failed with a TypeError. - Extractor keeps the writer class until the engine's header step, which now creates the writer via Extractor._open_output with the header's link type, byte order and timestamp resolution; run() opens it for engines with no header step. - The PCAP engine hands a PCAP writer the frame itself and skips the "Global Header" record the writer has already written, so in.pcap round-trips byte-identically. - The third-party engines produce frames without octets, so PCAP output from them falls back to JSON with a FormatWarning, as their flow tracing already does; PCAP-NG input raises FormatError. Closes #1127
Owner
Author
|
Cross-review verdict on
|
Contributor
|
Coverage: 88.88% (unit tier, Python 3.14,
Per-file detail: the |
JarryShaw
added a commit
that referenced
this pull request
Oct 7, 2026
- 4 new 1.5.0 entries: HTTP/2 sample stream identifiers (#1161), TCP option re-padding (#1163, breaking), format='pcap' output (#1164), declared lengths on truncated captures (#1166, breaking) - extend the PCAP Header (#1159), HIP (#1160) and from_data round-trip (#1162) entries rather than duplicating them - regenerate CHANGELOG.md with util/changelog_md.py - process.rst: entry-count pin re-measured, 189 -> 193 tests/project: conventions_doc_claims, changelog_md and documentation_claims pass; changelog_md.py --check is in step.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
make pylint,make mypy,make isort) — ran the three tools with the Makefile flags on the changedpcapkit/files: isort and mypy clean; pylint reports onlyprotected-access, as the engines already domake testpasses, and a test case covers the change — ran the modules listed below, not the full suiteWhat is the purpose of your pull request?
fix— corrects a defectDescription of your pull request and other information
Closes #1127.
Extractor.__init__created the writer before any header was read, soPCAPIOhad no link type and every engine failed (extraction.py:1202). Now the header step creates it throughExtractor._open_output(protocol=, byteorder=, nanosecond=), andrun()opens it for engines with no header step. A PCAP writer gets the frame itself and skips the dictGlobal Headerrecord. Third-party engines have no frame octets, so they fall back to JSON with aFormatWarning, as their flow tracing already does. PCAP-NG input raisesFormatError.Probe (
in.pcap/dhcp.pcapng,format='pcap'): before, all 8 engine × input runs fail withTypeError: PCAPIO.__init__() missing ... 'protocol'. After: default +in.pcapwrites a byte-identical 605-byte copy, and split / zero-frame output works. dpkt, scapy and pyshark write JSON with a warning. Default + pcapng raisesFormatError.Tests: new
tests/foundation/test_extraction_pcap_output_unit.pypasses 7 and fails 7 without the fix. Passing: #1149'stest_extraction_record_header_unit(10),test_extraction(22),engines/test_runtime_engines(5),engines/test_pcapng_engine(14), the other engine modules,interface/test_coreandtest_misc, andtests/project(389 passed, 1 skipped). Fixture-only edits:_open_outputon the mock extractor andbyteorderonFakeHeader.