Repository navigation
fix(engines): take a scapy packet's link type and clock from its interface (#1503, #1517, #1549) - #1563
Merged
Conversation
Owner
Author
|
Verdict: NEEDS CHANGES at Blocking: under scapy 2.8.0 every PCAP-NG packet is dropped, with no error. CI installs 2.8.0 because scapy is unpinned; the local venv has 2.7.0.
Also needed:
Confirmed on 2.7.0:
The author is fixing all three. |
Contributor
|
Coverage: 89.57% (unit tier, Python 3.14,
Per-file detail: the |
…rface (#1503, #1517, #1549) - A Simple Packet Block has no timestamp, and scapy left the packet with the time it was built; the engine's PCAP-NG reader now sets it to 0, as the default engine reads it (#1503). - The flow tracer looked the link type up by the first layer's name, so a raw IPv4 packet (`IP`) raised MissingKeyError. Both readers now attach the interface's link type with `attach_linktype`, and `tcp_traceflow` uses it; only a packet built by hand is still looked up by name, with no default (#1517). - scapy ignores `if_tsoffset`; the PCAP-NG reader now reads option 14 of each interface itself and adds it to every timestamp on it (#1549). - The overrides hold on scapy 2.5, 2.7 and 2.8: `_check_interface_id` passes its result through (2.8 skips a block on a false one), the offsets are kept by the reader rather than in scapy's interface tuple, and a missing hook raises VersionError. - Document `packet2frame`, `attach_resolution` and `attach_linktype`; delete the #1503 Gap row of the engine agreement table. New runtime and unit tests fail on main; scapy, trace and agreement selections pass on scapy 2.7.0 and 2.8.0.
JarryShaw
force-pushed
the
fix/1503-1517-1549-scapy-reader
branch
from
October 10, 2026 04:40
17e0000 to
71df9d4
Compare
Owner
Author
|
Verdict: GOOD TO GO at
Non-blocking:
|
This was referenced Oct 10, 2026
4 of 13 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please follow the guide below
You will be asked some questions, please read them carefully and answer honestly
Put an
xinto all the boxes [ ] relevant to your pull request (like that [x])Use Preview tab to see how your pull request will actually look like
Searched for similar pull requests
Followed the coding style (
make pylint,make mypy,make isort)make testpasses, and a test case covers the changeAdded a changelog entry under
docs/source/changelog/and regeneratedCHANGELOG.md, if the change is user-visible — N/A — centralised in docs(changelog): shared 1.5.0 changelog — long-lived, merges last (#610, #616, #617, #618, #620) #657What is the purpose of your pull request?
Tick the commit type your subject line carries.
fix— corrects a defectfeat— adds a featureperf— changes performance, not behaviourrefactor— changes neither behaviour nor performancetest— tests onlydocs— documentation onlyci— workflows or build toolingrelease— bumps the version or rolls up a distributionchore— anything elseDescription of your pull request and other information
All three fixes are in the scapy engine's reader subclasses (
_reader_type(),pcapkit/foundation/engines/scapy.py), the one place that sees each packet's interface:Packet.timeto 0, as the default engine reads it, where scapy left the time the packet was built. The fix is on the packet itself, soextractor.frameand every toolkit adapter get 0; a packet built by hand keeps its own time.attach_linktype, new inpcapkit/toolkit/scapy.py).tcp_traceflowuses it and looks a packet up by layer name only when nothing is attached, still with no default (Registries mint a permanent member for every unrecognised value: 1,169 extend_enum sites across 113 registries #775).if_tsoffset(option 14,endian + 'q') with each IDB, captures the interface ID in_check_interface_id, and adds the offset toPacket.time._check_interface_idpasses scapy's result through (2.8 returns a bool and skips the block onFalse), the offsets are kept by the reader, not in scapy's interface tuple (an int in 2.5), and a missing hook raisesVersionError.Deletes the
Gap(1503, ...)row. Tests:tests/foundation/engines/test_scapy_reader_interfaces_runtime.py(SPB,if_tsoffsetover two byte orders with EPB and obsolete Packet Blocks, raw-IPv4 PCAP-NG and PCAP traces compared byte for byte with the default engine),tests/foundation/engines/test_scapy_reader_hooks_unit.py(the hook contracts against a stand-in parent, whatever scapy is installed) andtests/toolkit/test_scapy_linktype_unit.py. All fail onmain. Also documentspacket2frame,attach_resolutionandattach_linktype.Closes #1503
Closes #1517
Closes #1549