fix(cpworker): report pcap_file read errors instead of end of file - #278
Merged
Merged
Conversation
added 2 commits
September 30, 2026 12:21
pcap_file_do_capture() handled only a packet and PCAP_ERROR_BREAK. When libpcap failed on a damaged record (truncated data, incl_len above the snaplen), the PCAP_ERROR was dropped without pcap_geterr(), the next read hit EOF, and the log said only "end of file". A partial replay looked like a complete one. Log the libpcap error and stop reading the file there, as at EOF: after a bad record libpcap may be left mid-record, and reading on could parse packet data as record headers. Once done, the capturer no longer calls pcap_next_ex() and only emits heartbeats. Add TestPcapFileCorrupt: an intact file (control), a truncated last record and an oversized incl_len; checks the log line and that exactly the records before the damage are forwarded. Passes with the bundled libpcap 1.6.2 and the system 1.10.4. Fixes #246 Refs #243
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
pcap_file_do_capture()handled only "got a packet" andPCAP_ERROR_BREAK. When libpcap failed on a damaged record (truncated data, orincl_lenabove the snaplen), thePCAP_ERRORwas dropped withoutpcap_geterr(). The next read then hit EOF, and the log said onlyINFO end of file. A partial replay looked like a complete one.Fix
PCAP_ERROR, log the libpcap error at ERROR and stop reading the file, the same way as at EOF. After a bad record libpcap may be left mid-record, and reading on could parse packet data as record headers.pcap_next_ex()and only emits heartbeats.Log output now:
Also runs gofmt on
reload_test.go(a doc comment only).Tests
New integration test
TestPcapFileCorrupt(cpworker/tests/integration/pcap_file_test.go), built fromhttp.pcap:intactend of file, no errortruncated_recordend of fileoversized_incl_lenincl_len = 0x7ffffff0, rest intactend of fileForwarded packets are compared byte for byte with the input records.
Unit tests (5/5) and the full integration suite (
run_test.sh all) pass with the bundled libpcap 1.6.2.Fixes #246
Refs #243 (item 5: corrupt/truncated pcap input to
pcap_file)