On Jan 29, 2013, at 1:39 PM, Wenfei Wu <[email protected]> wrote:

>   I want to know how wireshark use the filter expression to filter packets. 
> Does it parse the packet first, and then use the filter expression to check? 
> If so, is there some intermediate data structure to store the filter 
> expression? What is the algorithm?
>   Is there some materials about this?

See my reply on the tcpdump-workers mailing list.

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <[email protected]>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:[email protected]?subject=unsubscribe

Reply via email to