-
Notifications
You must be signed in to change notification settings - Fork 1
platform vtable
sloth wiki-sync edited this page Sep 30, 2026
·
1 revision
Summary: platform_ops_t in include/sloth.h is the seam between kernel-facing code and the rest of sloth. Views never call platform ops directly; they read sloth_state_t. The test suite swaps the vtable for tests/fake_platform.c.
Sources: CLAUDE.md, docs/views/connections.md, docs/views/interfaces.md (referenced).
Last updated: 2026-05-25.
- Lets the test suite drive views with deterministic kernel-state
fixtures (no rtnetlink chatter, no
/procreads). - Keeps Linux-specific code (
rtnetlink,nl80211,INET_DIAG,/proc/net/*) confined tosrc/platform/linux*.c. - Makes per-view code portable: a view that only touches
sloth_state_tdoesn't care whether the data came from netlink or a fake.
- rtnetlink — interface enumeration, MAC, MTU, link state.
- nl80211 — WiFi station info, RSSI, channel.
-
/proc/net/{tcp,tcp6,udp,udp6}— socket table. -
/proc/<pid>/fd/*— inode → PID mapping (so connections can show process names). -
INET_DIAGnetlink — per-socket RTT and retransmits. - sysfs — interface counters used by the bandwidth smoother.
-
Views never call platform ops directly. They read
sloth_state_t. -
No mocks of real-data interfaces. The fake platform in
tests/fake_platform.clives there so the seam stays narrow. - Errors at boundaries only (user input, syscalls, parsing). Trust internal code beyond the platform layer.
Mirrored from docs/wiki/ on main by .github/scripts/wiki_sync.sh. Edit there, not here — hand edits to this wiki are overwritten on the next push.
Read this first — the complete reference
- what-sloth-does
- how-wifi-works
- monitor-mode
- where-exploits-happen
- wifi-sigint-techniques
- cli-reference
- wifi-state-of-the-art
Start here
Engines
WiFi SIGINT
- wifi-sigint
- non-ip-sensors
- mac-randomisation
- evil-twin-reproducer
- btm-abuse
- action-frames
- research-corpus
- captive-portal
- fragattacks
- tool-fingerprints
- enterprise-rogue
- ipv6-ndp
- smb-snoop
- kerberos-snoop
- ldap-snoop
- bgp-snoop
- ssh-snoop
- rdp-snoop
- snmp-snoop
- mqtt-snoop
UI and infrastructure
- ip-palette
- platform-vtable
- version-checkin
- manifest-format
- pcap-export
- jsonl-schema
- data-socket-exposure
- sqlite-schema
- ring-buffers
Factory infrastructure
Reference
Source material
Maintenance