Repository navigation
fix(engines): reset the scapy reader's interfaces at each PCAP-NG section (#1522) - #1546
Merged
Merged
Conversation
…tion (#1522) Scapy's RawPcapNgReader appends every section's Interface Description Blocks to one table, so an interface ID in a later section resolved to the first section's interface, with its link type and if_tsresol: a microsecond section after a nanosecond one was dated 1000x too small, and its traced PCAP differed from the default engine's. The engine's PCAP-NG reader subclass now starts each section with no interfaces, as the PCAP-NG specification defines a section. The new runtime test builds two two-section captures from tcp.pcap and checks each frame's layer, resolution and timestamp, and that the traced PCAP flows match the default engine's byte for byte.
Owner
Author
|
Verdict: GOOD TO GO at
Not blocking:
|
Contributor
|
Coverage: 90.01% (unit tier, Python 3.14,
Per-file detail: the |
This was referenced Oct 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please follow the guide below
You will be asked some questions, please read them carefully and answer honestly
Put an
xinto all the boxes [ ] relevant to your pull request (like that [x])Use Preview tab to see how your pull request will actually look like
Searched for similar pull requests
Followed the coding style (
make pylint,make mypy,make isort)make testpasses, and a test case covers the change — test added; ran the new module,tests/toolkit/test_engine_pcap_trace_runtime.py, the scapy and runtime engine tests, the engine agreement harness, the isort/shard/tier/docstring guards, not the full suiteAdded a changelog entry under
docs/source/changelog/and regeneratedCHANGELOG.md, if the change is user-visible — N/A — centralised in docs(changelog): shared 1.5.0 changelog — long-lived, merges last (#610, #616, #617, #618, #620) #657What is the purpose of your pull request?
Tick the commit type your subject line carries.
fix— corrects a defectfeat— adds a featureperf— changes performance, not behaviourrefactor— changes neither behaviour nor performancetest— tests onlydocs— documentation onlyci— workflows or build toolingrelease— bumps the version or rolls up a distributionchore— anything elseDescription of your pull request and other information
Scapy's
RawPcapNgReaderappends every section's IDBs to oneinterfaceslist, so interface 0 of a later section resolved to section 1's, link type andif_tsresolincluded. The engine's_PcapNgReader(pcapkit/foundation/engines/scapy.py) now overrides_read_block_shbto start each section with no interfaces, as the PCAP-NG specification defines a section.tests/foundation/engines/test_scapy_pcapng_sections_runtime.pybuilds two captures fromtcp.pcap: the issue's (Ethernetif_tsresol=9, then Ethernet microseconds), and one whose section 2 has raw IPv6 (229) as interface 0 and Ethernet as interface 1. It checks each frame's layer, resolution and timestamp, and that every traced PCAP flow matches the default engine's byte for byte, both trace resolutions. Onc3d412015all 6 subtests fail (Decimal('1500000.000003318')vs1500000000.003318;Dot3vsIPv6). The agreement harness has no #1522 row:test.pcapng's section 2 interface 0 has the same link type and resolution as section 1's, so it could not see the bug.Closes #1522