On Jan 29, 2013, at 1:39 PM, Wenfei Wu <[email protected]> wrote:
> I want to know how wireshark use the filter expression to filter packets. > Does it parse the packet first, and then use the filter expression to check? > If so, is there some intermediate data structure to store the filter > expression? What is the algorithm? > Is there some materials about this? See my reply on the tcpdump-workers mailing list. ___________________________________________________________________________ Sent via: Wireshark-dev mailing list <[email protected]> Archives: http://www.wireshark.org/lists/wireshark-dev Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev mailto:[email protected]?subject=unsubscribe
