Skip to content

Read the Windows neighbor table directly, and stop reporting the broadcast address as a host - #495

Merged
fstubner merged 1 commit into
mainfrom
perf/windows-neighbor-table
Oct 2, 2026
Merged

fstubner merged 1 commit into
mainfrom
perf/windows-neighbor-table

Conversation

@fstubner

@fstubner fstubner commented Oct 1, 2026

Copy link
Copy Markdown
Owner

From the R&D pass on discovery.

Bug fixed. On Windows the neighbor table lists 192.168.1.255 with MAC ff:ff:ff:ff:ff:ff (a static entry), and discover reported it as an ICMP-silent host, which sweep then scanned. Seen in 10 of 10 runs on a home /24 before, 0 of 10 after.

Change.

  • Windows reads the table with GetIpNetTable2 (IPv4 only, as before) instead of running arp -a and parsing it. Only live neighbor states (reachable, stale, delay, probe, permanent) with a unicast MAC are kept, so the arp command also stops listing broadcast and multicast entries (57 → 23 rows here, all of the dropped ones ff:ff… or 01:00:5e…).
  • Discover drops the subnet's network and broadcast addresses (except on /31 and /32) and any broadcast or multicast MAC, on every platform.

Speed: no change in the normal case, stated plainly. My first measurement said discover was 40% faster. That was taken while other builds were saturating the CPU, when arp -a took about 4 s. On an idle machine arp -a takes 65 ms, and a /24 discover measured 1.72 s before and 1.71 s after (10 interleaved runs each). What remains is one fewer program start per discover, which matters only under load.

Dropped from the prototype: shortening the mDNS window from 1.5 s to 1 s. It looked faster under load, but names were lost (linux.local named in 5 of 8 runs).

Tests: the neighbor filter and the host-address filter, plus a live read of the table asserting no broadcast entry. Breaking either filter fails 3 of the 6. Clippy clean.

Not verified: macOS and Linux behaviour (the discover filter applies there too; their table readers are unchanged).

…dcast address as a host

Discovery and sweep ran `arp -a` and parsed its text on Windows. They now read the table with GetIpNetTable2, keeping only live neighbor states with a unicast MAC. Discover also drops the subnet's network and broadcast addresses (except on /31 and /32) and any broadcast or multicast MAC, on every platform: the Windows table lists x.x.x.255 as ff:ff:ff:ff:ff:ff, and discover reported it as a host that a sweep then scanned.

Timing: arp -a took 65 ms idle and about 4 s under heavy CPU load on the same Windows 11 machine. On an idle machine a /24 discover measured 1.72 s before and 1.71 s after (10 interleaved runs), so this is not a speed change in the normal case.
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Site preview: https://pr-495.netscli-site-preview.pages.dev

Built from f9961ef with NETSCLI_PREVIEW=1 — noindex, and analytics disabled so it does not report into netscli.com's numbers.

Production is unaffected: netscli.com is served from GitHub Pages via pages.yml, which is manual-only.

@fstubner
fstubner merged commit 927e137 into main Oct 2, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant