pcap-bpf silently ignores failures to put the interface in promiscuous mode. I was trying to dump on an interface that doesn't support promiscuous mode (a FreeBSD 802.1Q VLAN sub-interface), but I wasn't aware of that fact, and was confused by the fact that I wasn't seeing everything. I understand not wanting it to be a fatal error, but I'd like to know about it. What do people think about making ebuf always valid, whether pcap_open_live() returns NULL or not, and if ebuf is full but pcap_open_live() also succeeded then it's a warning? Thanks, Bill - This is the TCPDUMP workers list. It is archived at http://www.tcpdump.org/lists/workers/index.html To unsubscribe use mailto:[EMAIL PROTECTED]?body=unsubscribe
