Master the fundamental concepts of network stack fundamentals through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it workslibpcap is the standard cross-platform library for capturing network traffic. It powers tcpdump, Wireshark, and countless custom analyzers. For example, opening eth0 with a filter like tcp port 80 lets you see only HTTP traffic destined for port 80.
The typical capture sequence:
pcap_findalldevs(): enumerate interfaces (eth0, lo, wlan0)pcap_open_live(): open a device with snapshot length and timeoutpcap_compile() + pcap_setfilter(): apply a BPF filter stringpcap_loop(): call your callback for each matching packetpcap_close(): release the handleBerkeley Packet Filter expressions compile to bytecode that runs in the kernel before packets reach user space. Common filters:
icmp for ping trafficudp port 53 for DNS querieshost 192.168.1.1 for traffic to or from one hostEach captured packet arrives with a pcap_pkthdr timestamp and length, followed by raw bytes starting at the Ethernet header.
This task asks you to document the libpcap setup flow even though live capture cannot run in the sandbox. You will need this API knowledge when you build custom packet analyzers instead of clicking through someone else's Wireshark capture. The BPF compiler inside libpcap is the ancestor of Linux eBPF, which now runs sandboxed programs in the kernel for networking and security tooling.
Write a C program that parses the pcap file format: a 24-byte global header plus one 16-byte packet record header, supplied on stdin as 40 whitespace-separated hex bytes.
The magic number tells you the file's byte order: bytes d4 c3 b2 a1 mean the file was written little-endian, bytes a1 b2 c3 d4 mean big-endian (both encode the value 0xa1b2c3d4). Decode every field honoring that byte order.
Global header: magic (4), version_major (2), version_minor (2), thiszone (4), sigfigs (4), snaplen (4), linktype (4). Packet record: ts_sec (4), ts_usec (4), incl_len (4), orig_len (4).
Print one key=value line each for: byte_order (little-endian or big-endian), version_major, version_minor, snaplen, linktype, ts_sec, ts_usec, incl_len, orig_len, and truncated_bytes = orig_len - incl_len. If the first four bytes match neither arrangement, print only bad_magic.