https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16664

--- Comment #1 from gwaeber <li...@gilleswaeber.ch> ---
Related, the PCAP NG spec draft specifies that the entry must contain a
__REALTIME_TIMESTAMP field and that it "could potentially be used to include
arbitrary key-value data", but Wireshark currently enforces a minimum size of
212 bytes for this block (MIN_SYSTEMD_JOURNAL_EXPORT_ENTRY_SIZE = 200).

The error dialog is:

  The capture file appears to be damaged or corrupt.
  (pcapng_read_systemd_journal_export_block: total block length 72 is too small
(< 212))

  [ OK ]

-- 
You are receiving this mail because:
You are watching all bug changes.
___________________________________________________________________________
Sent via:    Wireshark-bugs mailing list <wireshark-bugs@wireshark.org>
Archives:    https://www.wireshark.org/lists/wireshark-bugs
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-bugs
             mailto:wireshark-bugs-requ...@wireshark.org?subject=unsubscribe

Reply via email to