[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-18 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

John Thacker  changed:

   What|Removed |Added

 Status|IN_PROGRESS |RESOLVED
 Resolution|--- |FIXED

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-15 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

--- Comment #6 from Gerrit Code Review  ---
Change 38165 merged by Jaap Keuter:
dicom: fix exporting objects with tshark

https://code.wireshark.org/review/38165

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-15 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

--- Comment #5 from Gerrit Code Review  ---
Change 38165 had a related patch set uploaded by Pascal Quantin:
dicom: fix exporting objects with tshark

https://code.wireshark.org/review/38165

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-15 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

--- Comment #4 from Gerrit Code Review  ---
Change 38164 merged by Anders Broman:
dicom: fix exporting objects with tshark

https://code.wireshark.org/review/38164

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-14 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

John Thacker  changed:

   What|Removed |Added

 Status|UNCONFIRMED |IN_PROGRESS
 Ever confirmed|0   |1
 CC||[email protected]

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-14 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

--- Comment #3 from Gerrit Code Review  ---
Change 38164 had a related patch set uploaded by John Thacker:
dicom: fix exporting objects with tshark

https://code.wireshark.org/review/38164

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-12 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

--- Comment #2 from Chuck Craft  ---
pcap here:
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16748

And resulting file names for tshark --export-objects:
tshark 3.0.12
-
 3_0_12/000453-1-C-STORE-RQ-DATA.dcm
 3_0_12/000925-1-1.3.12.2.1107.5.1.7.123018.301812031602269280561.dcm
 3_0_12/001393-1-1.3.12.2.1107.5.1.7.123018.301812031602269280562.dcm
 3_0_12/001860-1-1.3.12.2.1107.5.1.7.123018.301812031602269280563.dcm
 3_0_12/002328-1-1.3.12.2.1107.5.1.7.123018.301812031602269280564.dcm
 3_0_12/002799-1-1.3.12.2.1107.5.1.7.123018.301812031602269280565.dcm
 3_0_12/003267-1-1.3.12.2.1107.5.1.7.123018.301812031602269280566.dcm
 3_0_12/003736-1-1.3.12.2.1107.5.1.7.123018.301812031602269280567.dcm

filename = wmem_strdup_printf(wmem_packet_scope(), "%06d-%d-%s.dcm",
pinfo->num, cnt_same_pkt,
g_strcanon(pdv_curr->sop_instance_uid, G_CSET_A_2_Z G_CSET_a_2_z
G_CSET_DIGITS "-.", '-'));

tshark 3.2.6

 3_2_6/000453-1-C-STORE-RQ-DATA.dcm
 3_2_6/000925-1-CT-Image-Storage.dcm
 3_2_6/001393-1-CT-Image-Storage.dcm
 3_2_6/001860-1-CT-Image-Storage.dcm
 3_2_6/002328-1-CT-Image-Storage.dcm
 3_2_6/002799-1-CT-Image-Storage.dcm
 3_2_6/003267-1-CT-Image-Storage.dcm
 3_2_6/003736-1-CT-Image-Storage.dcm

 /* Make sure filename does not contain invalid character. Rather
conservative.*/
 filename = wmem_strdup_printf(wmem_packet_scope(), "%06d-%d-%s.dcm",
pinfo->num, cnt_same_pkt,
 g_strcanon(pdv->desc, G_CSET_A_2_Z G_CSET_a_2_z G_CSET_DIGITS
"-.", '-'));

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe

[Wireshark-bugs] [Bug 16771] dicom object extraction: discrepancy between tshark and wireshark

2020-08-12 Thread bugzilla-daemon
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16771

Chuck Craft  changed:

   What|Removed |Added

 CC||[email protected]

--- Comment #1 from Chuck Craft  ---
tl;dr: header fields (and filename) for export are set from tags, if available.
Prior to https://code.wireshark.org/review/#/c/31973/, tags were dissected and
available before export.
Wireshark makes a pass through the file to display fields before File->Export
Objects->DICOM...

epan/dissectors/packet-dcm.c:
If the UIDs are not set, then copy in Wireshark boilerplate values
---
dcm_export_create_object()
 if (pdv->is_storage &&
 pdv_curr->sop_class_uid&& strlen(pdv_curr->sop_class_uid)>0 &&
 pdv_curr->sop_instance_uid && strlen(pdv_curr->sop_instance_uid)>0)
 else {
 /* No SOP Instance or SOP Class UID found in PDV. Use wireshark ones
*/



3.0.12 - packet-dcm.c:
"UIDs" populated by dissect_dcm_pdv_body() before dcm_export_create_object()

if (tree || have_tap_listener(dicom_eo_tap)) {
/* The performance optimization now starts at tag level.

   During, tree can be NULL, but we need a few tags to be
decoded,
   i.e Class & Instance UID, so the export dialog has all
information and
   that the dicom header is complete
*/
offset += dissect_dcm_pdv_body(next_tvb, pinfo, tree, pdv,
0, next_tvb_length, pdv_description);
}

if (have_tap_listener(dicom_eo_tap)) {
/* Copy pure DICOM data to buffer, no PDV flags */

pdv->data = wmem_alloc(wmem_packet_scope(),
next_tvb_length);
tvb_memcpy(next_tvb, pdv->data, 0, next_tvb_length);
pdv->data_len = next_tvb_length;

/* Copy to export buffer */
dcm_export_create_object(pinfo, assoc, pdv);
}
}


Current - packet-dcm.c:
dcm_export_create_object() called before dissect_dcm_tag()
-
 if ((pdv_body_len > 0) && (pdv->is_last_fragment)) {
 /* At the last segment, merge all related previous PDVs and copy
to export buffer */
 dcm_export_create_object(pinfo, assoc, pdv);
 }
 }

 if (pdv->is_command || tree) {
 /* Performance optimization starts here. Don't put any COL_INFO
related stuff in here */

 if (pdv->syntax == DCM_UNK) {
 /* Eventually, we will have a syntax detector. Until then, don't
decode */

 proto_tree_add_bytes_format(tree, hf_dcm_data_tag, tvb,
 offset, pdv_body_len, NULL,
 "(%04x,%04x) %-8x Unparsed data", 0, 0, pdv_body_len);
 }
 else {

 gboolean is_first_tag = TRUE;

 /* Treat the left overs */
 offset = dissect_dcm_tag_open(tvb, pinfo, tree, pdv, offset,
endpos, &is_first_tag);

 /* Decode all tags, sequences and items in this PDV recursively */
 while (offset < endpos) {
 offset = dissect_dcm_tag(tvb, pinfo, tree, pdv, offset,
endpos, is_first_tag, &tag_value, &dummy);
 is_first_tag = FALSE;
 }
 }
 }

-- 
You are receiving this mail because:
You are watching all bug changes.___
Sent via:Wireshark-bugs mailing list 
Archives:https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
 mailto:[email protected]?subject=unsubscribe