Sitelet https://github.com/Netis/cloud-probe/pull/278
Skip to content

fix(cpworker): report pcap_file read errors instead of end of file - #278

Merged
timmy21 merged 2 commits into
0.9.xfrom
fix/246-pcap-file-read-error
Sep 30, 2026
Merged

timmy21 merged 2 commits into
0.9.xfrom
fix/246-pcap-file-read-error

Conversation

@timmy21

@timmy21 timmy21 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem

pcap_file_do_capture() handled only "got a packet" and PCAP_ERROR_BREAK. When libpcap failed on a damaged record (truncated data, or incl_len above the snaplen), the PCAP_ERROR was dropped without pcap_geterr(). The next read then hit EOF, and the log said only INFO end of file. A partial replay looked like a complete one.

Fix

  • On PCAP_ERROR, log the libpcap error at ERROR and stop reading the file, the same way as at EOF. After a bad record libpcap may be left mid-record, and reading on could parse packet data as record headers.
  • Once EOF or an error is reached, the capturer no longer calls pcap_next_ex() and only emits heartbeats.

Log output now:

ERROR pcap_file.c:50: read pcap file error: truncated dump file; tried to read 99 captured bytes, only got 49; skip the rest of the file
ERROR pcap_file.c:50: read pcap file error: invalid packet capture length 2147483632, bigger than snaplen of 2048; skip the rest of the file

Also runs gofmt on reload_test.go (a doc comment only).

Tests

New integration test TestPcapFileCorrupt (cpworker/tests/integration/pcap_file_test.go), built from http.pcap:

case input expected
intact unchanged (control) all records, end of file, no error
truncated_record record #9 cut in half at end of file first 9 records, error line, no end of file
oversized_incl_len record #9 incl_len = 0x7ffffff0, rest intact first 9 records, error line, no end of file

Forwarded packets are compared byte for byte with the input records.

libpcap before after
1.6.2 (bundled) both damaged cases fail pass
1.10.4 (system, Ubuntu 24.04) both damaged cases fail pass

Unit tests (5/5) and the full integration suite (run_test.sh all) pass with the bundled libpcap 1.6.2.

Fixes #246

Refs #243 (item 5: corrupt/truncated pcap input to pcap_file)

timmy.yuan added 2 commits September 30, 2026 12:21
pcap_file_do_capture() handled only a packet and PCAP_ERROR_BREAK. When
libpcap failed on a damaged record (truncated data, incl_len above the
snaplen), the PCAP_ERROR was dropped without pcap_geterr(), the next
read hit EOF, and the log said only "end of file". A partial replay
looked like a complete one.

Log the libpcap error and stop reading the file there, as at EOF: after
a bad record libpcap may be left mid-record, and reading on could parse
packet data as record headers. Once done, the capturer no longer calls
pcap_next_ex() and only emits heartbeats.

Add TestPcapFileCorrupt: an intact file (control), a truncated last
record and an oversized incl_len; checks the log line and that exactly
the records before the damage are forwarded. Passes with the bundled
libpcap 1.6.2 and the system 1.10.4.

Fixes #246
Refs #243
@timmy21
timmy21 merged commit 65adb91 into 0.9.x Sep 30, 2026
1 check passed
@timmy21
timmy21 deleted the fix/246-pcap-file-read-error branch September 30, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[cpworker] pcap_file capturer swallows libpcap read errors and reports a damaged file as "end of file"

1 participant