Skip to content

Feature: CAN XL Support - #5152

Open
RB-FriedrichWiemer wants to merge 23 commits into
secdev:masterfrom
RB-FriedrichWiemer:feature/canxl-support
Open

RB-FriedrichWiemer wants to merge 23 commits into
secdev:masterfrom
RB-FriedrichWiemer:feature/canxl-support

Conversation

@RB-FriedrichWiemer

Copy link
Copy Markdown

Description

This is my first pull request to scapy.
It adds CAN XL support to the existing CAN layer, making use of the CAN XL implementation available on Linux' SocketCAN.

@polybassa

Copy link
Copy Markdown
Contributor

Thanks for this PR. Please resolve the conflicts with the master.

Comment thread scapy/contrib/cansocket_native.py Outdated
Comment thread scapy/contrib/cansocket_native.py Outdated
Comment thread scapy/layers/can.py Outdated
Comment thread scapy/layers/can.py Outdated
Comment thread scapy/layers/can.py Outdated
Comment thread scapy/layers/can.py Outdated
Comment thread scapy/layers/can.py Outdated
Comment thread scapy/layers/can.py Outdated
@codecov

codecov Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 82.35294% with 18 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.13%. Comparing base (d1bbdaf) to head (50989fa).

Files with missing lines Patch % Lines
scapy/contrib/cansocket_native.py 55.55% 12 Missing ⚠️
scapy/layers/can.py 92.95% 5 Missing ⚠️
scapy/contrib/cansocket_python_can.py 75.00% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##           master    #5152      +/-   ##
==========================================
+ Coverage   80.84%   81.13%   +0.29%     
==========================================
  Files         393      393              
  Lines       98325    98414      +89     
==========================================
+ Hits        79488    79853     +365     
+ Misses      18837    18561     -276     
Files with missing lines Coverage Δ
scapy/contrib/cansocket_python_can.py 84.02% <75.00%> (-0.36%) ⬇️
scapy/layers/can.py 93.04% <92.95%> (-0.07%) ⬇️
scapy/contrib/cansocket_native.py 70.58% <55.55%> (-7.99%) ⬇️

... and 25 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@RB-FriedrichWiemer RB-FriedrichWiemer changed the title [Draft] Feature: CAN XL Support Feature: CAN XL Support Sep 22, 2026
@pfasante

Copy link
Copy Markdown

the byte-swap for wireshark pcaps I still need to check

@polybassa polybassa left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Let's check what wireshark does, then we can merge

@polybassa

Copy link
Copy Markdown
Contributor

Please fix the failing job.

polybassa
polybassa previously approved these changes Sep 25, 2026
@pfasante
pfasante force-pushed the feature/canxl-support branch from 99486a3 to ed1f066 Compare September 25, 2026 22:30
@polybassa

Copy link
Copy Markdown
Contributor

sorry, there is still the AI-Trailer job failing. You may need to to a rebase.

RB-FriedrichWiemer and others added 13 commits September 29, 2026 22:13
Introduce the CANXL class in scapy.layers.can, following the Linux
struct canxl_frame wire format and inheriting from the CAN class.
Provides additional ISO 11898-1:2024 property accessors and
show(style='11898-1') for ISO field-name rendering.

AI-Assisted: yes (Claude Opus and Sonnet)
AI-Assisted: yes (Claude Opus and Sonnet)
AI-Assisted: yes (Claude Opus and Sonnet)
Tests pass on Linux. On Windows, tests appear to timeout -- needs further investigation.

AI-Assisted: yes (Claude Opus and Sonnet)
Covers quick start, field naming (Linux vs ISO), byte-order handling, NativeCANSocket usage, can-utils interop, and known limitations.

AI-Assisted: yes (Claude Opus and Sonnet)
AI-Assisted: yes (Claude Opus and Sonnet)
AI-Assisted: no
Declare the CAN XL header as little endian via BitField's tot_size /
end_tot_size, LEShortField and XLEIntField, instead of swapping the
prio, length and af regions by hand. Removes CANXL.inv_endianness()
and the swap in pre_dissect() and post_build().

AI-Assisted: yes (Claude Opus and Sonnet)
post_dissect duplicated CAN.post_dissect, and the default
guess_payload_class already returns conf.raw_layer when no payload
class is bound.

AI-Assisted: yes (Claude Opus and Sonnet)
Keep Packet.show()'s signature unchanged and expose the ISO 11898-1
rendering as its own method.

AI-Assisted: yes (Claude Opus and Sonnet)
Use Packet.sprintf() for the fields it can resolve instead of
formatting each one against the color theme by hand. Format, FTYPE,
SEC and DLC are properties rather than fields, so they stay resolved
in Python.

AI-Assisted: yes (Claude Opus and Sonnet)
Both recv_raw() and send() open-coded the same four-byte swap that
CAN.inv_endianness() already performs. Also drops _is_canxl(), a
single-use wrapper around CANXL.is_canxl_frame().

AI-Assisted: yes (Claude Opus and Sonnet)
AI-Assisted: yes (Gemini 3.8 Flash)
@pfasante
pfasante force-pushed the feature/canxl-support branch from ed1f066 to 46ca8ea Compare September 29, 2026 20:17
@gpotter2

Copy link
Copy Markdown
Member

@polybassa

sorry, there is still the AI-Trailer job failing. You may need to to a rebase.

finally managed to fix that need for rebasing... will merge it ASAP. sorry about that 78c41b5

@polybassa polybassa self-assigned this Sep 30, 2026
@polybassa

Copy link
Copy Markdown
Contributor

Could you please have a look why some can related tests are failing

CAN XL support changed send() to choose the padding size from the packet
type, so a classic CAN frame sent on a socket opened with fd=True was
transmitted as a 16 byte frame instead of a CAN FD frame.

AI-Assisted: yes (Claude Opus and Sonnet)
Python 3.7 rejects the backslash continuation when UTScapy compiles the
test, with "SyntaxError: trailing comma not allowed without surrounding
parentheses".

AI-Assisted: yes (Claude Opus and Sonnet)
Comment thread scapy/contrib/cansocket_native.py Outdated
# CAN/CANFD: pad to the frame size the socket was opened with, so
# that a classic CAN frame sent on an fd socket stays a CAN FD frame
mtu = CAN_FD_MTU if self.fd else CAN_MTU
bs = bs + b"\x00" * (mtu - len(bs))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there a reason why mtu is not self.MTU anymore?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See update in 32b78d3

I think its correct now?

Comment thread scapy/layers/can.py Outdated
log_runtime.warning(
"CAN XL payload length %d exceeds the ISO 11898-1 "
"maximum of %d (11-bit field)", length, CANXL_MAX_DLEN)
pkt = pkt[:6] + struct.pack('<H', length) + pkt[8:]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should only compute length if the field is None.
Scapys intention is to do the right thing by default, but if you specify a incorrect value yourself, this value should be sent to the wire

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good point, fixed that.

Also required some test updates that where encoding this "fixing" behavior

Comment thread scapy/layers/can.py Outdated
"CAN XL frame has IDE set; clearing it "
"(IDE is always 0 for CAN XL per ISO 11898-1)")
flags = (pkt[4] | CANXL_XLF | CANXL_FDF) & ~CANXL_IDE
pkt = pkt[:4] + bytes([flags]) + pkt[5:]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here

Comment thread scapy/layers/can.py Outdated
# dropped rather than preserved as a Padding layer. CAN XL
# frames from a native socket have exact-length data; any
# trailing garbage is safely discarded.
return p[:data_len], None

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please respect the remove_padding config here

Comment thread scapy/layers/can.py Outdated
# but Linux struct canxl_frame uses a full 16-bit field.
# For kernel compatibility we use a 16-bit field; post_build warns
# if the computed length falls outside the valid range.
LEShortField('length', 0),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ideally, change the default to None

self.MTU is CANXL_MTU on a socket opened with xl=True, which is not a
valid frame size for a classic CAN or CAN FD frame, so those are padded
to CAN_MTU there.

AI-Assisted: yes (Claude Opus and Sonnet)
Default the length field to None and compute it from the payload in
post_build only in that case, so that a value set by the user reaches
the wire unchanged.

AI-Assisted: yes (Claude Opus and Sonnet)
post_build forced XLF and FDF on and IDE off, overriding a value set by
the user. The field default still follows ISO 11898-1.

AI-Assisted: yes (Claude Opus and Sonnet)
Trailing bytes beyond the stated length were always discarded. They are
now kept as Padding when remove-padding is disabled, as for CAN and
CAN FD.

AI-Assisted: yes (Claude Opus and Sonnet)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants