Skip to content

arch: minor cleanups to winpcapy and libpcap - #5211

Merged
gpotter2 merged 2 commits into
secdev:masterfrom
gpotter2:winpcapy-fix
Sep 30, 2026
Merged

gpotter2 merged 2 commits into
secdev:masterfrom
gpotter2:winpcapy-fix

Conversation

@gpotter2

@gpotter2 gpotter2 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Prompted by #5209

@gpotter2
gpotter2 force-pushed the winpcapy-fix branch 2 times, most recently from d5b00b8 to 54219ac Compare September 30, 2026 19:52
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 80.76923% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.17%. Comparing base (90623e7) to head (46a371c).

Files with missing lines Patch % Lines
scapy/arch/libpcap.py 75.00% 3 Missing ⚠️
scapy/config.py 81.81% 2 Missing ⚠️
Additional details and impacted files
@@           Coverage Diff           @@
##           master    #5211   +/-   ##
=======================================
  Coverage   81.16%   81.17%           
=======================================
  Files         393      393           
  Lines       98120    98134   +14     
=======================================
+ Hits        79637    79658   +21     
+ Misses      18483    18476    -7     
Files with missing lines Coverage Δ
scapy/arch/windows/__init__.py 66.29% <100.00%> (+0.06%) ⬆️
scapy/config.py 85.44% <81.81%> (-0.19%) ⬇️
scapy/arch/libpcap.py 77.16% <75.00%> (+0.75%) ⬆️

... and 7 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@gpotter2

gpotter2 commented Sep 30, 2026 •

Copy link
Copy Markdown
Member Author

Sometimes I forget how some of our arch/ is very ugly. This PR side-tracked a lot.

@gpotter2
gpotter2 force-pushed the winpcapy-fix branch 2 times, most recently from fb9664a to e42d41b Compare September 30, 2026 20:48
@KernelClint

Copy link
Copy Markdown
Contributor

Fine by me to go with this one. I tested it by reading a pcap file through libpcap:

Platform master #5211
NetBSD 10.1 i386 wrong lengths pass
Alpine 3.22 i386 and armv7 (musl) wrong lengths or segfault segfault
Debian 13 armhf wrong lengths segfault
Debian 13 i386 and x86_64, macOS arm64 pass pass

So it fixes NetBSD, but not 32-bit Linux where time_t is 64-bit: musl, and Debian 13 on armhf (which Raspberry Pi OS 32-bit is built on). There, both fields of struct timeval are 64-bit, so caplen is at byte 16 rather than 8. Your new test does catch it (it crashes there), but only when run on those platforms. I can send that extra branch if you want it.

Two smaller things:

  • The new test's packet has the same captured length and length on the wire, so it still passes with the GHSA-c547 fix reverted. The test it replaces checked that. Could you keep it as well?
  • _socket_changer has elif attr == "use_bsd":, which I think is meant to be "use_bpf".

@gpotter2 gpotter2 changed the title winpcapy: fix timeval arch: minor cleanups to winpcapy and libpcap Sep 30, 2026
@gpotter2
gpotter2 merged commit b9c6129 into secdev:master Sep 30, 2026
23 checks passed
@gpotter2
gpotter2 deleted the winpcapy-fix branch September 30, 2026 21:50
@gpotter2

Copy link
Copy Markdown
Member Author

Thanks a lot for the review.

The new test's packet has the same captured length and length on the wire, so it still passes with the GHSA-c547 fix reverted. The test it replaces checked that. Could you keep it as well?

You're right, see b0a6933.

@gpotter2 gpotter2 added this to the 2.8.0 milestone Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants