[Wireshark-dev] Is this a known problem?

2024-01-31 Thread Richard Sharpe
Hi folks, I installed 4.2.2 on a Windows Server 2012 system and got the following error: "The procedure entry point SystemParametersInfoForDpi could not be located in the dynamic link library ..." [image: image.png] Is there a work-around? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操

[Wireshark-dev] Resurrecting a discussion on being able to filter within embedded structures

2022-10-30 Thread Richard Sharpe
_subtree et al, which means that such filtering will not always be possible. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wiresha

Re: [Wireshark-dev] How do I indicate that a commit or MR fixes an issue?

2022-10-18 Thread Richard Sharpe
he change is > merged, while other references such as "see #4512" will simply link to the > issue. Thanks. Looks like I chose the wrong way :-( > On Tue, Oct 18, 2022 at 12:46 PM Richard Sharpe > wrote: >> >> Hi folks. >> >> What do I put in a c

[Wireshark-dev] How do I indicate that a commit or MR fixes an issue?

2022-10-18 Thread Richard Sharpe
Hi folks. What do I put in a commit message to indicate that it fixes an issue? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org

Re: [Wireshark-dev] Max size of a field seems to be 240 for a dissector

2022-10-18 Thread Richard Sharpe
On Tue, Oct 18, 2022 at 9:39 AM Pascal Quantin wrote: > > Hi Richard, > > Le mar. 18 oct. 2022 à 18:30, Richard Sharpe a > écrit : >> >> Hi folks, >> >> How do I squeeze more than 240 chars into a string field? > > You can't currently. As seen in

[Wireshark-dev] Max size of a field seems to be 240 for a dissector

2022-10-18 Thread Richard Sharpe
with 3.4.8? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options

[Wireshark-dev] The font size used for the menu etc does not seem to change when I change the main window font size

2022-10-13 Thread Richard Sharpe
, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev

Re: [Wireshark-dev] proto_item_append_text info not being picked up when extracting fields via tshark

2022-10-12 Thread Richard Sharpe
On Wed, Oct 12, 2022 at 11:10 AM Richard Sharpe wrote: > > Hi folks, > > As a result of a recent issue and MR I suggested the use of tshark to > extract some info but it does not work. > > I suggested this: > -- > ./run/tshark -r ~/SNR* -Y &quo

[Wireshark-dev] proto_item_append_text info not being picked up when extracting fields via tshark

2022-10-12 Thread Richard Sharpe
tshark is extracting is the scidx numbers but not the phi and psi values following it. Has anyone seen this issue before? I guess I will look into it soon but was interested to know if anyone has seen it. -- Regards, Richard Sharpe (何以解憂?唯

Re: [Wireshark-dev] display filter scanner.l possible weirdness

2022-08-23 Thread Richard Sharpe
On Tue, Aug 23, 2022 at 6:56 AM João Valverde wrote: > > On 8/23/22 14:29, Richard Sharpe wrote: > > On Tue, Aug 23, 2022 at 2:30 AM João Valverde wrote: > >> On 8/22/22 14:42, Richard Sharpe wrote: > >>> Hi folks, > >>> > >>> In try

Re: [Wireshark-dev] display filter scanner.l possible weirdness

2022-08-23 Thread Richard Sharpe
On Tue, Aug 23, 2022 at 2:30 AM João Valverde wrote: > > On 8/22/22 14:42, Richard Sharpe wrote: > > Hi folks, > > > > In trying to introduce my contexts approach for display filters to > > handle embedded/recursive structures in 802.11 Information Elements > &g

[Wireshark-dev] Is there some way in gitlab that I can be automatically informed when merge requests are created for ieee80211?

2022-08-22 Thread Richard Sharpe
Hi folks, Is there some way that gitlab can inform me of merge requests for the 802.11 dissector? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https

[Wireshark-dev] display filter scanner.l possible weirdness

2022-08-22 Thread Richard Sharpe
for the dfilter stuff? I have been using dftest to test my changes but it would be good to see if I have disturbed anything. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives

Re: [Wireshark-dev] Filter expressions for recursive structures

2022-08-19 Thread Richard Sharpe
On Wed, Aug 17, 2022 at 6:31 AM Richard Sharpe wrote: > > On Sun, Jul 31, 2022 at 3:36 AM João Valverde wrote: > > > > Maybe we could add wildcards? > > > > |diameter.*.Result-Code > > > > The star represents "any nesting level", not "

Re: [Wireshark-dev] Filter expressions for recursive structures

2022-08-17 Thread Richard Sharpe
ted and the generator is not > > respecting naming schemes but they face the same issue. > > > > Kind regards > > Roland > > > > > Am 29.07.2022 um 18:28 schrieb Richard Sharpe > > : > > > > > > Hi folks, > &g

Re: [Wireshark-dev] Syncthing protocol dissector

2022-02-28 Thread Richard Sharpe
..@wireshark.org > > > ?subject=unsubscribe > > > > > > -- > Tmore1 > ___ > Sent via:Wireshark-dev mailing list > Archives:https://www.wireshark.org/lists/wireshark-dev > Unsubscribe: https://www.wiresh

Re: [Wireshark-dev] Passing information to a sub dissector

2022-02-17 Thread Richard Sharpe
ftp streams could be opened in the same ssh session, how do I tell the > subdissector with which "conversation" it should work)? Conversation info should probably be in the pinfo, but if not, pass in enough info to find the conversation. -- Regards, Ri

[Wireshark-dev] How do I figure out why the test failed?

2021-12-17 Thread Richard Sharpe
figure out where it failed? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org

[Wireshark-dev] How do I create a merge request for changes to get into the next 3.6.x release

2021-12-15 Thread Richard Sharpe
? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev

[Wireshark-dev] My latest Merge Request pipeline failed in a weird way in the Windows build

2021-12-14 Thread Richard Sharpe
s occurred! What is going on? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wir

Re: [Wireshark-dev] Exporting FTP objects

2021-12-14 Thread Richard Sharpe
and do reassembly there. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman

Re: [Wireshark-dev] Exporting FTP objects

2021-12-14 Thread Richard Sharpe
starting sequence number) with the ending seq number or length and pointer to the data and a more-data flag or something. Then, when you have all the data you can index into the hash table by starting sequence number starting at 1. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) __

Re: [Wireshark-dev] Is there some reasonable way to split up epan/dissectors/packet-ieee80211.c into smaller files?

2021-12-03 Thread Richard Sharpe
ate the Wi-Fi 6 and Wi-Fi 7 and Wi-Fi 99 additions into separate files, for the most part. Perhaps we would need a mechanism for Wi-Fi X+1 to override some parts of Wi-Fi X as well, but I have no idea how to handle that for the moment. -- Regards, Richard Sharpe (何以解憂?唯有杜康。-

[Wireshark-dev] Is there some reasonable way to split up epan/dissectors/packet-ieee80211.c into smaller files?

2021-12-02 Thread Richard Sharpe
files? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options

Re: [Wireshark-dev] make rpm-package does not build custom dissectors ...

2021-10-29 Thread Richard Sharpe
On Fri, Oct 29, 2021 at 7:56 AM Richard Sharpe wrote: > > Hi folks, > > In one project I have a bunch of custom dissectors in a 3.5.0 build. > > They are all defined in epan/dissectors/CMakeListsCustom.txt. > > When I run cmake it tells me it found the custom stuff.

[Wireshark-dev] make rpm-package does not build custom dissectors ...

2021-10-29 Thread Richard Sharpe
run make rpm-package the custom dissectors are not built and there are not .o files in the build directory for the custom dissectors. Where should I look to figure out what is going wrong? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

Re: [Wireshark-dev] I have added another file to wireshark but keep getting unresolved references

2021-10-24 Thread Richard Sharpe
> Regards > Anders > > -Original Message- > From: Wireshark-dev On Behalf Of > Richard Sharpe > Sent: den 24 oktober 2021 15:17 > To: Developer support list for Wireshark > Subject: [Wireshark-dev] I have added another file to wireshark but keep > getting un

[Wireshark-dev] I have added another file to wireshark but keep getting unresolved references

2021-10-24 Thread Richard Sharpe
to the files list in epan/dissectors/CMakeLists.txt. What else should I do? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark

Re: [Wireshark-dev] Can an 'Apply as Column' column contain multiple columns?

2021-08-31 Thread Richard Sharpe
On Tue, Aug 31, 2021 at 7:52 AM chuck c wrote: > > http://www.packettrain.net/2017/07/05/wireshark-hints-multi-column/ Well, sh*t, seems there is nothing new under the sun. > On Tue, Aug 31, 2021 at 9:49 AM Richard Sharpe > wrote: >> >> Hi folks, >> >>

[Wireshark-dev] Can an 'Apply as Column' column contain multiple columns?

2021-08-31 Thread Richard Sharpe
, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev

Re: [Wireshark-dev] Getting captured interface name inside plugin

2021-06-06 Thread Richard Sharpe
subscribe: https://www.wireshark.org/mailman/options/wireshark-dev > mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:

Re: [Wireshark-dev] Can the OSS-FUZZ tool be modified to generate a pcap test file?

2021-05-27 Thread Richard Sharpe
On Thu, May 27, 2021 at 10:16 AM Moshe Kaplan wrote: > > I believe Peter Wu created a script a while back to do that and published it > here: https://github.com/Lekensteyn/wireshark-fuzztools Thanks for that. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传

[Wireshark-dev] Can the OSS-FUZZ tool be modified to generate a pcap test file?

2021-05-27 Thread Richard Sharpe
Hi folks, It seems like the OSS-FUZZ tool is very useful in finding certain types of problems, but it would be even more useful if it could generate a pcap file of the packets it used to find a problem. Does anyone know how hard it would be to modify to do that? -- Regards, Richard Sharpe (何以解

Re: [Wireshark-dev] Ethernet dissector

2021-05-23 Thread Richard Sharpe
dd_uint("ethertype", ETHERTYPE_IEEE_1905, ieee1905_handle); eapol_handle = find_dissector("eapol"); } You can ignore the eapol_handle stuff unless you also plan to use EAPOL (ieee801.X) in your protocol. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者)

[Wireshark-dev] Should we be dynamically allocating the hash buf below?

2021-05-14 Thread Richard Sharpe
y, I guess. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailm

[Wireshark-dev] packet-rpc.c failing find rpc_call info when the capture file is large enough

2021-04-25 Thread Richard Sharpe
. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev

Re: [Wireshark-dev] Who introduced these failures?

2021-04-21 Thread Richard Sharpe
On Wed, Apr 21, 2021 at 10:47 AM Pascal Quantin wrote: > > Hi Richard, > > Le mer. 21 avr. 2021 à 19:43, Richard Sharpe a > écrit : >> >> My latest MR failed with these errors: >> >> - >> C:\builds\wireshark\wireshark\ep

[Wireshark-dev] Who introduced these failures?

2021-04-21 Thread Richard Sharpe
: '=': conversion from 'double' to 'float', possible loss of data [C:\builds\wireshark\wireshark\build\epan\dissectors\dissectors.vcxproj] --- They are not in packet-ieee80211.c where my changes were. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

Re: [Wireshark-dev] Writing a wtap module for CommView WLAN Analyzer and Decoder NCFX format files

2021-04-19 Thread Richard Sharpe
On Sun, Apr 18, 2021 at 9:30 PM Guy Harris wrote: > > On Apr 18, 2021, at 2:33 PM, Richard Sharpe > wrote: > > > I am thinking of writing a wtap module to read ComView WLAN Analyzer > > and Decoder NCFS format files. > > > > They are a little li

[Wireshark-dev] Clearly, someone thought no one should be using CommView after 2038

2021-04-18 Thread Richard Sharpe
Hi folks, I just came across this validation check in the commview wiretap code: if (... cv_hdr.year < 1970 || cv_hdr.year >= 2038 || ...) -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wir

[Wireshark-dev] Writing a wtap module for CommView WLAN Analyzer and Decoder NCFX format files

2021-04-18 Thread Richard Sharpe
or different WTAP type and write a separate dissector for those headers. Any thoughts? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org

Re: [Wireshark-dev] (1) building Wireshark in build.wireshark fails, (2) how to get dissector details without packet

2021-04-15 Thread Richard Sharpe
east if the name is all ASCII printable characters and > contains no spaces); if it doesn't, that's a sign that the build process > isn't robust enough. Indeed, I routinely build in directories like wireshark-build or wireshark--build and I have never

[Wireshark-dev] Wireshark not dissecting ONC RPC on a different port in build 3.4.4 and an older build but OK on Master?

2021-04-15 Thread Richard Sharpe
on a Fedora 31 system. Has anyone seen this before? I am currently building 3.4.4 on Fedora to see if the problem is across more than one build of 3.4.4, -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via

[Wireshark-dev] Hitting a weird error in a MR pipeline

2021-04-13 Thread Richard Sharpe
did not touch those files ... what is going on? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https

[Wireshark-dev] Support for searching in FT_BYTES or longer bit fields

2021-04-01 Thread Richard Sharpe
wlan.ftm.ista.availability_block_2 == 0x1ff37 or whatever. 2. Insert the whole lot as an FT_BYTES field but then it seems like the user will have to enter the whole value, up to 32 bytes if it is that long. 3. ??? Is there a better way? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

[Wireshark-dev] Is there a way to easily go to the next packet that satisfies a filter string without filtering the packets

2021-03-20 Thread Richard Sharpe
on. The workflow is quite painful. Is there a simpler way to do this? If not, could we add a button for Next packet satisfying filter? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list

Re: [Wireshark-dev] Problems with passing g_free to g_slist_foreach?

2021-03-17 Thread Richard Sharpe
On Tue, Mar 16, 2021 at 9:23 PM Richard Sharpe wrote: > > Hi folks, > > I have been seeing some compiler errors on CentOS 8 like the following: > > --- > /home/rsharpe/src/wireshark/epan/packet.c:142:25: error: > cast between incompatible f

[Wireshark-dev] Problems with passing g_free to g_slist_foreach?

2021-03-16 Thread Richard Sharpe
two arguments, while g_free takes only one argument. How do I avoid the warning/error? Also, should we fix these things up? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list

Re: [Wireshark-dev] Is gitlab having problems?

2021-03-14 Thread Richard Sharpe
On Sun, Mar 14, 2021 at 4:43 PM Richard Sharpe wrote: > > Hi folks, > > I am trying to sign into the gitlab UI and it just sits there saying > it is checking my browser and telling me it may take up to 5 seconds > but never gets there. Seems to be a browser issue. I tried a

[Wireshark-dev] Is gitlab having problems?

2021-03-14 Thread Richard Sharpe
Hi folks, I am trying to sign into the gitlab UI and it just sits there saying it is checking my browser and telling me it may take up to 5 seconds but never gets there. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

Re: [Wireshark-dev] 90GB pcap file get last frame time stamp

2021-02-26 Thread Richard Sharpe
n appropriate record header ... On the other hand, I am unaware of any code that does that. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/list

Re: [Wireshark-dev] warning: unused parameter

2021-02-07 Thread Richard Sharpe
ters? Do you really need the parameter? If so, does adding _U_ after it not fix the problem? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:h

Re: [Wireshark-dev] Do we see false positives on the prechecks in merge-request runners

2021-02-01 Thread Richard Sharpe
On Mon, Feb 1, 2021 at 7:22 AM Pascal Quantin wrote: > > Hi Richard, > > Le lun. 1 févr. 2021 à 16:09, Richard Sharpe a > écrit : >> >> Hi folks, >> >> In one of the builds for my merge request around Robust AV Streaming, >> I got this: >&g

[Wireshark-dev] Do we see false positives on the prechecks in merge-request runners

2021-02-01 Thread Richard Sharpe
(but perhaps the original code was wrong.) -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https

Re: [Wireshark-dev] [Outreachy] Internship blog 2020 post #3

2021-01-07 Thread Richard Sharpe
reak in between posts as usual). Hi Joey, Is there any code we can look at? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wire

Re: [Wireshark-dev] Branch name issues ...

2021-01-03 Thread Richard Sharpe
On Sat, Jan 2, 2021 at 11:07 PM Pascal Quantin wrote: > > Hi Richard, > > Le dim. 3 janv. 2021 à 01:01, Richard Sharpe a > écrit : >> >> Hi folks, >> >> I just tried to push some changes to my upstream repo prior to >> creating a merge reque

[Wireshark-dev] Branch name issues ...

2021-01-02 Thread Richard Sharpe
branch is called ieee80211-PV1 ... Is this something I can change in my fork or do I have to use something like cherry-pick-.xxx? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing

[Wireshark-dev] The ultimate networking hacker's device!

2020-11-24 Thread Richard Sharpe
Hi folks, I came across this: https://www.crowdsupply.com/traverse-technologies/ten64/updates/10g-options-and-performance -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list

Re: [Wireshark-dev] Handling malformed packet exceptions from within ASN.1 dissectors

2020-11-03 Thread Richard Sharpe
ation and my problem was elsewhere :-) -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.w

[Wireshark-dev] Handling malformed packet exceptions from within ASN.1 dissectors

2020-11-02 Thread Richard Sharpe
and then keep dissecting. How can I handle this? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https

Re: [Wireshark-dev] Possible regression in Version 3.3.1 (v3.3.1-0-gd64aca7966e2)

2020-10-18 Thread Richard Sharpe
both looking at the same capture, I think, when he hit the problem. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Un

Re: [Wireshark-dev] Possible regression in Version 3.3.1 (v3.3.1-0-gd64aca7966e2)

2020-10-18 Thread Richard Sharpe
apply as a column? It was the SMB2 Time from request field in responses. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wiresha

Re: [Wireshark-dev] Do Lua Postdissectors still work with the most recent versions of Wireshark

2020-10-16 Thread Richard Sharpe
Mac OS X? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wire

[Wireshark-dev] Possible regression in Version 3.3.1 (v3.3.1-0-gd64aca7966e2)

2020-10-16 Thread Richard Sharpe
tallation and then re-adding it all worked correctly. My colleague is using a Mac. Not sure if this is relevant. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:

[Wireshark-dev] Do Lua Postdissectors still work with the most recent versions of Wireshark

2020-10-16 Thread Richard Sharpe
, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev

Re: [Wireshark-dev] Introduction - An Outreachy 2020 Applicant

2020-10-09 Thread Richard Sharpe
es. Welcome. There are many helpful people on the list. It would be useful if you can point us to a protocol description document but that can wait until help is needed. It may be that all the online resources are sufficient, but if not, do not hesitate to use this list to ask questions.

Re: [Wireshark-dev] Introduction - An Outreachy 2020 Applicant

2020-10-09 Thread Richard Sharpe
contribute to the "Add Git protocol support to Wireshark" project. Perhaps Amanda could resend her introduction on the wireshark-dev mailing list because this is the list for development type questions and will get better responses for developer-type

Re: [Wireshark-dev] Joint project with Git for outreachy

2020-09-21 Thread Richard Sharpe
.* files. There is also a sample dissector in doc/packet-PROTOABBREV.c However, it can all be a bit daunting for a beginner so I am willing to help get things started. I should also point out that there are many people on the wireshark-developer mailing list who will be more than happy to help

Re: [Wireshark-dev] Joint project with Git for outreachy

2020-09-19 Thread Richard Sharpe
I am more than happy to offer advice and ideas and look at code to get new Wireshark developers going. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://w

Re: [Wireshark-dev] Joint project with Git for outreachy

2020-09-19 Thread Richard Sharpe
rs, and I am sure many other developers are as well. -- Regards Richard Sharpe ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/opti

[Wireshark-dev] The QT-5.15 disaster and an issue with multi-monitor setups, Windows and Wireshark

2020-08-28 Thread Richard Sharpe
on the first monitor (and other craziness can occur as well.) Are these related at all? Do we plan to skip Qt 5.15? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives

[Wireshark-dev] Have we already switched over to gitlab?

2020-08-23 Thread Richard Sharpe
Hi folks, Has the switchover occurred? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https

Re: [Wireshark-dev] Filtering on a field when there is more than one such field in a Wi-Fi packet

2020-08-14 Thread Richard Sharpe
tching against some obscure protocol, or perhaps it should be: wlan.tag.number == and found:wlan.tag.length >= -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:ht

[Wireshark-dev] Filtering on a field when there is more than one such field in a Wi-Fi packet

2020-08-13 Thread Richard Sharpe
lue is prone to false positives if any tagged field in the frame has that number and any other tagged field in the frame has a length ge the value. How can I limit the length comparison to the tag found in the first comparison? Do we even have that concept? -- Regards, Richard Sharpe (何以解憂?唯有杜康。

Re: [Wireshark-dev] Code of Conduct for our community

2020-08-05 Thread Richard Sharpe
_ > Sent via:Wireshark-dev mailing list > Archives:https://www.wireshark.org/lists/wireshark-dev > Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev >

Re: [Wireshark-dev] Capturing 10GbE on a Linux laptop?

2020-08-05 Thread Richard Sharpe
much data to disk is > something I do with small portable servers (about the size of a small shoe > box) > with a FPGA based capture card. NVMe can handle it ... -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___

[Wireshark-dev] Capturing 10GbE on a Linux laptop?

2020-08-02 Thread Richard Sharpe
looked at System 76 and Librem but it does not seem they are capable of handling the load. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org

Re: [Wireshark-dev] WLAN bug?

2020-07-05 Thread Richard Sharpe
On Sun, Jul 5, 2020 at 5:29 AM Richard Sharpe wrote: > > On Sun, Jul 5, 2020 at 5:30 AM Jaap Keuter wrote: > > > > Hi Richard, > > > > Have you seen these entries from conflict check: > > > > ** (process:12824): WARNING **: 08:16:29.502: Field 'Stat

Re: [Wireshark-dev] WLAN bug?

2020-07-05 Thread Richard Sharpe
st is inconsistent with local MAC address > policy) > > Do you know how to address this? Probably. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:http

[Wireshark-dev] Seems I can no longer submit changes for review

2020-06-28 Thread Richard Sharpe
Hi folks, I tried to submit a change for review but got: remote: Unauthorized fatal: Authentication failed for 'https://code.wireshark.org/review/wireshark/' What is going on? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

[Wireshark-dev] Wireshark and Kerberos keytabs?

2020-06-18 Thread Richard Sharpe
, the enc part is not being busted out for me. Does anyone know how to do this? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists

Re: [Wireshark-dev] Gaining access to ff_pa_action_codes_ext from other protocols

2020-06-04 Thread Richard Sharpe
On Thu, Jun 4, 2020 at 3:09 AM Peter Wu wrote: > > On Wed, Jun 03, 2020 at 11:17:01AM -0700, Richard Sharpe wrote: > > Hi folks, > > > > Some protocols define status values etc in terms of 802.11. > > > > I am trying to get the latest changes for IEEE1905

[Wireshark-dev] Gaining access to ff_pa_action_codes_ext from other protocols

2020-06-03 Thread Richard Sharpe
and allow the linker to deal with it? 2. Provide a function that retrieves a pointer to it? 3. Some other mechanism? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-16 Thread Richard Sharpe
On Sat, May 16, 2020 at 8:51 AM Pascal Quantin wrote: > > Hi Richard, > > Le sam. 16 mai 2020 à 17:34, Richard Sharpe a > écrit : >> >> On Sat, May 16, 2020 at 6:00 AM João Valverde >> wrote: >> > >> > Hi Richard, >> > >> >

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-16 Thread Richard Sharpe
On Sat, May 16, 2020 at 6:00 AM João Valverde wrote: > > Hi Richard, > > On 15/05/20 23:46, Richard Sharpe wrote: > > On Fri, May 15, 2020 at 3:33 PM Peter Wu wrote: > >> The "asn1" target rebuilds all asn1 dissectors. > >> Alterna

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-15 Thread Richard Sharpe
gt; cmake .. > cmake --build . --target generate_dissector-pkcs1 > > Or if you use ninja: > > mkdir build > cd build > cmake -GNinja .. > ninja generate_dissector-pkcs1 -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-15 Thread Richard Sharpe
On Fri, May 15, 2020 at 2:29 PM Richard Sharpe wrote: > > On Fri, May 15, 2020 at 2:30 PM Peter Wu wrote: > > > > Hi Richard, > > > > On Fri, May 08, 2020 at 08:54:58AM -0700, Richard Sharpe wrote: > > [..] > > > It doesn't look like it was manuall

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-15 Thread Richard Sharpe
On Fri, May 15, 2020 at 2:30 PM Peter Wu wrote: > > Hi Richard, > > On Fri, May 08, 2020 at 08:54:58AM -0700, Richard Sharpe wrote: > [..] > > It doesn't look like it was manually modified. The last person who > > touched that file was Peter Wu, it seems, so maybe

Re: [Wireshark-dev] Cannot Decrypt Fast BSS Transition (802.11r) Packets

2020-05-15 Thread Richard Sharpe
vation is not handled by the decryption > engine so PTK remains unknown which makes decryption fail. And unfortunately > directly entering PTK for decryption is not supported either. It could be but it would take some work :-) -- Regards, Richard Sharpe

Re: [Wireshark-dev] Cannot Decrypt Fast BSS Transition (802.11r) Packets

2020-05-15 Thread Richard Sharpe
able. > > Is decryption of fast BSS transition data packets supported by Wireshark? If > so, could you please suggest what we can do to investigate what is going on? It is not currently supported. The WFA uses an external tool to decrypt those packet

[Wireshark-dev] Does a filter expression allow searching with a string of bytes as decimal numbers?

2020-05-09 Thread Richard Sharpe
- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://www.wireshark.org/mailman/options/wir

Re: [Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-08 Thread Richard Sharpe
On Fri, May 8, 2020 at 8:43 AM Pascal Quantin wrote: > > Hi Richard, It doesn't look like it was manually modified. The last person who touched that file was Peter Wu, it seems, so maybe he can shed some light on it. > Le ven. 8 mai 2020 à 17:08, Richard Sharpe a > écrit : &g

[Wireshark-dev] asn2wrs.py no longer seems to generate the same code ...

2020-05-08 Thread Richard Sharpe
, BER_FLAGS_NOOWNTAG, dissect_pkcs1_Digest }, { NULL, 0, 0, 0, NULL } }; ... --- This seems like a problem ... Perhaps I should file a bugzilla bug. -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

Re: [Wireshark-dev] How do I expose ECDSA-Sig-Value as a dissect function in pkcs1?

2020-05-07 Thread Richard Sharpe
On Thu, May 7, 2020 at 8:04 AM Pascal Quantin wrote: > > Hi Richard, > > Le jeu. 7 mai 2020 à 17:01, Richard Sharpe a > écrit : >> >> Hi folks, >> >> I need a dissector for an EDCSA-Sig-Value, and it is nicely defined in >>

[Wireshark-dev] How do I expose ECDSA-Sig-Value as a dissect function in pkcs1?

2020-05-07 Thread Richard Sharpe
it as an export to the pkcs1.cnf file by adding it to the .EXPORTS section but perhaps I forgot to remove it from the .NO_EMIT section ... Is that all I need to do (and then re-run the command to generate the new packet-pcks1.c file?) -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

[Wireshark-dev] Has anything changed with respect to contributing changes to Wireshark after github?

2020-04-14 Thread Richard Sharpe
Hi folks, I think I saw an email about things moving to github or gitlab and wondered if they meant any changes to my workflow around submitting changes? If so, is there a link I can use to see what they are? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者

Re: [Wireshark-dev] "Custom" link-layer types for pcap and pcapng

2020-03-27 Thread Richard Sharpe
in pcapng file, if the link-layer type in an IDB is 0x, the IDB > *MUST* contain a new option, containing the PEN and vendor-specific > link-layer type. > > Given that it's for *two* capture file formats, these lists are probably > better

[Wireshark-dev] I have some captures from Jouni's hwsim for 802.11 with Anti-Clogging tokens

2020-02-16 Thread Richard Sharpe
Hi folks, How do I get these into the collection? -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent via:Wireshark-dev mailing list Archives:https://www.wireshark.org/lists/wireshark-dev Unsubscribe

Re: [Wireshark-dev] Request for a Wireshark Update to support TEAP traffic analysis.

2020-02-07 Thread Richard Sharpe
ed eap_type_vals. 3. Add the new entry or entries to that table. 4. Rebuild. Probably on Linux because building on Windows is hard. 5. Feed the capture into the new build. 6. Feel a burst of joy at making your first change to Wireshark. 7. Add any new attributes or whatever is needed to properly dissect th

Re: [Wireshark-dev] PIM: Support for dissection of PIM Flooding Mechanisme (PFM)

2019-12-25 Thread Richard Sharpe
his is of interest to > include into the source base or not? If someone would find it useful then you should submit it. https://code.wireshark.org/review -- Regards, Richard Sharpe (何以解憂?唯有杜康。--曹操)(传说杜康是酒的发明者) ___ Sent

  1   2   3   4   5   6   >