[tcpdump-workers] Re: Setting BPF_SPECIAL_VLAN_HANDLING on a "dead" handle

2025-07-04 Thread Michael Richardson
Guy Harris wrote: > In the longer term, the compilation process should probably be split > into: yes. > a phase that compiles a filter into a target-independent *and* > link-layer-independent *and* snapshot-length-independent intermediate > representation, optionally doing

[tcpdump-workers] Re: Setting BPF_SPECIAL_VLAN_HANDLING on a "dead" handle

2025-07-04 Thread Michael Richardson
like we ought to specify some kind of target BPF processor option. As you say, pcap mostly just adapts itself to the current kernel, and the dead version has no options. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandel

[tcpdump-workers] Re: v4/v6 packet length printing inconsistency

2025-07-02 Thread Michael Richardson
to show only the lines they care about. The -vv probably changes this too. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandel

[tcpdump-workers] bringing in distro and embedded patches

2025-06-22 Thread Michael Richardson
The current set of patches that OpenWRT applies to tcpdump are at: > The current paches are here: > https://github.com/openwrt/openwrt/tree/master/package/libs/libpcap/patches There are no doubt Fedora/RPM, and Debian/DPKG patches too. I for one, would be very happy to see everything up

[tcpdump-workers] Re: tcpdump and pcapng with comments

2025-04-06 Thread Michael Richardson
Mahesh V wrote: > I added some code (modified) tcpdump to write the pcapng file. > while configuring/compiling the source code I get this error > This is a cross compilation for ARM platform Well, likely the resulting flex test can't be run, since it's cross-compiled. I suggest *NOT

[tcpdump-workers] Re: tcpdump and pcapng with comments

2025-04-04 Thread Michael Richardson
Mahesh V wrote: > I would like to know if > 1) tcpdump can write pcapng format (instead of just pcap) Not yet. > 3) read it later on. (I believe this functionality is available today or > alternatively even wireshark would be ok to do this for me) > Is this functionality ava

[tcpdump-workers] Re: Returned mail: Data format error

2024-11-18 Thread Michael Richardson
The message about the spam was in fact spam. But, it forged a valid From: so it got through. I'd like to fix the SPF/DKIM/spam-filter such that it more aggressively kills this kind of forgery, assuming that wireshark.org has the right policies set. This kind of thing is fraught with false-positiv

[tcpdump-workers] Re: capture and inject device capabilities in libpcap

2024-11-18 Thread Michael Richardson
Denis Ovsienko wrote: > One complication here is that in some cases libpcap may not be aware of > a device capability until it gets an error from the OS (as is the case > with PCAP_ERROR_CAPTURE_NOTSUP in pcap-linux.c), so pcap_findalldevs() > would not be able to set "this device

[tcpdump-workers] Re: Assistance with Capturing cURL Request using tcpdump

2024-10-01 Thread Michael Richardson
s to dump things. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tc

[tcpdump-workers] Re: Assistance with Capturing cURL Request using tcpdump

2024-10-01 Thread Michael Richardson
Kaushal Shriyan wrote: > I am using Postman to invoke a REST API call. Is there a way to capture the > cURL (https://curl.se/) request (including headers and body) initiated by > the Postman REST API client to the application server running RHEL 8.10 OS, > and then to the backen

[tcpdump-workers] Re: upcoming tcpslice 1.8

2024-09-09 Thread Michael Richardson
Denis Ovsienko wrote: > Let me suggest making tcpslice 1.8 release in 1-2 weeks to avoid yet > another oversized change log section. If anyone sees a good reason not > to, please make your point before long. Who are the users of tcpslice? Are there any heavy users that would like to

[tcpdump-workers] Re: tcpdump. binary

2024-09-06 Thread Michael Richardson
Denis Ovsienko wrote: > To simplify the use of "make install", would it be a reasonable > trade-off to install the additional binary only when the .devel file > exists? That sounds like a good plan. ___ tcpdump-workers mailing list -- tcpdu

[tcpdump-workers] Re: Support for saving pcapng

2024-05-20 Thread Michael Richardson
se, I wonder if the community is > allowed to submit a pull request for it. Are there any restrictions or > guidelines we should be aware of in this regard? Thanks for your time > and patience. My understanding is that the APSL is not compatible with the BSD 2-clause. -- Michael Ri

[tcpdump-workers] Re: Dropping support in tcpdump for older versions of libpcap?

2024-04-14 Thread Michael Richardson
nd pcap_activate(); those first appeared in libpcap 1.0, which was > released in 2008, almost 16 years ago. > Is there any reason not to require libpcap 1.0 or later? If there is, > is there any reason not to require libpcap 0.7 or later? I think libpcap 1.0 or later is good.

[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
Guy Harris wrote: > If so, do we > 1) require people to have autotools installed and run ./autogen.sh > or > 2) generate the configure scripts on some standard platform and check it in 3) stop using autoconf, cmake only. ___ tcpdump

[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
Bill Fenner wrote: > mcr suggested: >> I wonder if we should nuke our own make tarball system. > The creation of a tarball and its signature gives a place to hang one's hat > about origin of code - "someone with the right key claims that this tarball > genuinely reflects wh

[tcpdump-workers] openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
system. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ __

[tcpdump-workers] Re: Test

2024-02-24 Thread Michael Richardson
Guy Harris wrote: > Is the list working? It was not. I finally found the web process hanging onto a database lock, and cleared that. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpdump-workers

[tcpdump-workers] Re: upgrade to mailman3

2023-12-29 Thread Michael Richardson
Michael Richardson wrote: > Michael Richardson wrote: >> This message is partly to see if anything is fixed. > At least the emails went through, but did not get archived yet. > Help sought. maybe working now. ___

[tcpdump-workers] Re: upgrade to mailman3

2023-12-29 Thread Michael Richardson
Michael Richardson wrote: > This message is partly to see if anything is fixed. At least the emails went through, but did not get archived yet. Help sought. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe s

[tcpdump-workers] upgrade to mailman3

2023-12-29 Thread Michael Richardson
We have gone from 3.3.3 to mailman3 3.3.8 with an operating system update to Debian 12 (Devuan 4). Missed the broken kernel (I checked). The previous system had numerous faults, particularly around archiving which I was unable to fix in the time I had available. This message is partly to see if

[tcpdump-workers] Re: Request for a LINKTYPE/DLT for DECT NR+ (ETSI TS 103 636)

2023-10-06 Thread Michael Richardson
Stig Bjørlykke via tcpdump-workers wrote: > We are in the process of making a trace tool and a Wireshark dissector > for DECT NR+ [1]. The "DECT-2020 New Radio (NR); Part 4: MAC layer" > chapter 6 defines PDU formats and parameters for this protocol. > Proposed name: LINKTYPE_DEC

[tcpdump-workers] Re: Removing untested libpcap support for older platforms

2023-10-06 Thread Michael Richardson
Guy Harris wrote: > Should we also consider removing support for some older UN*X platforms, > such as: Yes. > SunOS prior to SunOS 4 - pcap-nit.c; the last such version, SunOS > 3.5, was released in January 1988 > SunOS 4.x - pcap-snit.c; the last such version, SunOS 4.

[tcpdump-workers] Re: Request for Information: libpcap

2023-10-01 Thread Michael Richardson
Zhang, Cynthia X. (GSFC-710.0)[KPMG LLP] wrote: > Hello, my name is Cynthia Zhang and I am a Supply Chain Risk Management > Analyst at NASA. NASA is currently conducting a supply chain assessment > of libpcap. We are interested in confirming the following information: > 1. Is th

[tcpdump-workers] Re: Accurate ECN support in tcpdump/libpcap

2023-09-03 Thread Michael Richardson
Scheffenegger, Richard wrote: > Tcpdump - any every tool afterwards - has been using "." for ACKs. Hi, so there have been some tools which have parsed the tcpdump "TCP" output in the past, and there have been small variations in the output, and often we've broken those tools. One such tool w

[tcpdump-workers] Re: [tcpdump] About PR 812

2023-08-22 Thread Michael Richardson
Francois-Xavier Le Bail wrote: > Does anyone see a problem with this change? (Answer on PR page.) > https://github.com/the-tcpdump-group/tcpdump/pull/812 It looks so simple, it's probably correct :-) -- Michael Richardson. o O ( IPv6 IøT consulting )

[tcpdump-workers] Re: libpcap : An entry in the manual about multithreading

2023-05-07 Thread Michael Richardson
> handle. For example there could be a global map of pcap_t* handles to > thread ID's, something like: > struct Mapping { pcap_t *handle; pthread_t thread_id; }; > Mapping mappings[32u]; I could tolerate this. -- ] Never tell me the odds!

[tcpdump-workers] more testing...

2023-03-13 Thread Michael Richardson
There are some problems on the list host where some files wind up root owned, when they shouldn't be. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpdump-workers-le...@lists.tcpdump.org %(web_p

[tcpdump-workers] more testing emails

2023-02-26 Thread Michael Richardson
I'm sorry for the troubles. We are still getting continuous attempts to send email subscribe (DDoS) spam via HTTP, even though mailman2 is gone, and the links are are 404, but the script kiddies continue. fail2ban is doing some things, needs further tuning. But overall, it's just annoying. _

[tcpdump-workers] Re: mailman3 list imported

2023-02-15 Thread Michael Richardson
Michael Richardson via tcpdump-workers wrote: > --- Forwarded Message The DMARC mitigation was forced on, which is not what I wanted. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpd

[tcpdump-workers] mailman3 list imported

2023-02-15 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- The mailing list has been moved from a mailman2 host to a mailman3 host. I had subscribed everyone with an option to confirm, but that was a bad idea. I have now found the import21 command, and imported the "pickle" file from the mailman2 installation. I hope that this email

Re: [tcpdump-workers] Speed specific Link-Layer Header Types for USB 2.0

2022-06-14 Thread Michael Richardson via tcpdump-workers
YPE with a subtype header, but if you want to go with three, I don't object. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http

Re: [tcpdump-workers] Request for new LINKTYPE_* code LINKTYPE_AUERSWALD_LOG

2021-02-03 Thread Michael Richardson via tcpdump-workers
provide further information. > Best regards > Frank Gorgas-Waller Software Architect > Auerswald Gesellschaft für Datensysteme mbH Vor den Grashöfen 1 38162 > Cremlingen Germany -- ] Never tell me the odds! | ipv6 mesh networks [

Re: [tcpdump-workers] Stick with Travis for continuous integration, or switch?

2021-02-03 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Francois-Xavier Le Bail via tcpdump-workers wrote: > To save CI runtime, I have committed > a063c2d21417345ee583551ef2c07a0be6b32696 for libpcap. > This will currently run only five builders (amd64, arm64, ppc64le, > s390x and osx) and do the matrix processing

Re: [tcpdump-workers] Stick with Travis for continuous integration, or switch?

2021-01-28 Thread Michael Richardson via tcpdump-workers
the "migrate" button. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ --- End Message --- _

Re: [tcpdump-workers] Request to add MCTP and PCI_DOE to PCAP link type

2021-01-25 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Yao, Jiewen wrote: > Thank you. I will file a Pull-Request. > The DOE header definition can be found > https://github.com/jyao1/openspdm/blob/master/Include/IndustryStandard/PciDoeBinding.h > It starts from PCI_DOE_DATA_OBJECT_HEADER. That sounds like enou

Re: [tcpdump-workers] Request to add MCTP and PCI_DOE to PCAP link type

2021-01-25 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Yao, Jiewen via tcpdump-workers wrote: > Hello Any response ? > Thank you Yao Jiewen ... Hi, sorry abotu that. > Hi I write this email to request to below 2 link types. > 1. MCTP > Management Component Transport Protocol (MCTP) is an industry stan

Re: [tcpdump-workers] libpcap detection and linking in tcpdump

2021-01-23 Thread Michael Richardson via tcpdump-workers
ly-installed tcpdump. Effectively, this is what libtool tries to do. I would rather just be explicit about it somehow. Maybe that goes into how we use "make check", but I'm not sure where else it matters. -- ] Never tell me the odds! | ipv6

Re: [tcpdump-workers] libpcap detection and linking in tcpdump

2021-01-23 Thread Michael Richardson via tcpdump-workers
ne of my Ubuntu VMs. > In the meantime, for some fun head-exploding reading, take a look at > https://en.wikipedia.org/wiki/Rpath > and perhaps some other documents found by a search for Yeah... I don't even know what to say. -- ] Never tell me the odds!

Re: [tcpdump-workers] Any way to filter ether address when type is LINUX_SLL?

2021-01-23 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Guy Harris via tcpdump-workers wrote: > I've been thinking about a world in which we have more pcapng-style > APIs. With a capture API that can deliver, for each packet, something > similar to a pcapng Enhanced Packet Block, with an interface number > from th

Re: [tcpdump-workers] bpf.tcpdump.org updates

2021-01-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Michael Richardson via tcpdump-workers wrote: > bpf.tcpdump.org is being updated from devuan ascii (2.0) to devuan > beowolf (3.1). (Equvialent to Debian buster). > I've doing this to upgrade git to the version that supports --mirror, >

[tcpdump-workers] bpf.tcpdump.org updates

2021-01-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- bpf.tcpdump.org is being updated from devuan ascii (2.0) to devuan beowolf (3.1). (Equvialent to Debian buster). I've doing this to upgrade git to the version that supports --mirror, which is not the right thing for the local repositories. (I was, you know, reading the man p

Re: [tcpdump-workers] Any way to filter ether address when type is LINUX_SLL?

2021-01-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Bill Fenner via tcpdump-workers wrote: > It would be perfectly reasonable (and fairly straightforward) to update > libpcap to be able to filter on the Ethernet address in DLT_LINUX_SLL > or DLT_LINUX_SLL2 mode. There are already filters that match other > off

Re: [tcpdump-workers] [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- IANA considerations

2020-12-22 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- wrote: >> -Message d'origine- >> De : OPSAWG [mailto:opsawg-boun...@ietf.org] De la part de Michael >> Richardson >> Envoyé : mardi 22 décembre 2020 17:36 >> À : Guy Harris >> Cc : Pcap-ng file

Re: [tcpdump-workers] [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-22 Thread Michael Richardson via tcpdump-workers
was, or whether > it's still supported. Wow, lots of ill-defined complexity here. I think that we should just regard this as water under the bridge. If NetBSD wants to propose a use for those empty bits, then a new specification could update that use case. -- Michael Richardson

Re: [tcpdump-workers] [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- IANA considerations

2020-12-22 Thread Michael Richardson via tcpdump-workers
PPPoE; per RFC 2516 > That one's there for NetBSD; I *think* the packet contains just a PPPoE > header and payload. I may have to dig into the NetBSD code to see what > they do. okay, but we don't have to get that perfect in the document. What matters is

Re: [tcpdump-workers] [OPSAWG] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Carsten Bormann wrote: > On 2020-12-22, at 01:31, Michael Richardson wrote: >> >> #define LT_FCS_LENGTH(x) (((x) & 0xF000) >> 28) >> #define LT_FCS_DATALINK_EXT(x

[tcpdump-workers] draft-gharris-opsawg-pcap.txt --- IANA considerations

2020-12-21 Thread Michael Richardson via tcpdump-workers
ls.ietf.org/html/draft-gharris-opsawg-pcap-01 Diff: https://www.ietf.org/rfcdiff?url2=draft-gharris-opsawg-pcap-01 -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide --- End Message --- ___

[tcpdump-workers] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-21 Thread Michael Richardson via tcpdump-workers
its. Is 0 valid? Or would that be indicated by LENGTH_PRESENT(x)==0? Or is 0 ==> 8 * 16-bits => 128 bits of FCS. I'm going to propose IANA considerations in a followup email and in -01. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works

[tcpdump-workers] man pages... what's cool now? (fwd) Michael Richardson: man pages... what's cool now?

2020-12-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- I forgot not to PGP sign. --- End Message --- ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers

Re: [tcpdump-workers] pcap_open_offline_... and options and the like

2020-12-19 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Michael Richardson via tcpdump-workers wrote: > trying without GPG signature YUP. That's it. So mailman2 will have to get replaced finally. It eats emails with signature attachments, I think. This is new. After a few hours thinking about my previous email I w

[tcpdump-workers] pcap_open_offline_... and options and the like

2020-12-19 Thread Michael Richardson via tcpdump-workers
3) more extensive rework so that pcap_create() could create handle for live and offline captures, and that specifying the capture type was just another set. These are not mutually exclusive. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael R

[tcpdump-workers] sorry for all the testing

2020-12-19 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Simple tests like: echo "testing 1.2.3." | Mail -s "testing 1.2.3" tcpdump-workers@lists.tcpdump.org are working, but complex emails are not. --- End Message --- ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org

Re: [tcpdump-workers] CVE-2020-8037: memory allocation in ppp decapsulator

2020-11-30 Thread Michael Richardson via tcpdump-workers
> fixes, or should we rely on Red Hat and others for that? I can strive to do better. I think that you are on the security@ list, and I think that this did go through that list at the time. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richa

Re: [tcpdump-workers] tcpslice licence

2020-08-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Denis Ovsienko via tcpdump-workers wrote: > [...] >> The first step I'd take would be to get rid of the GPLed headers in >> favor of BSD-licensed headers, e.g. taking the ip.h, tcp.h, and udp.h >> headers from tcpdump and changing the code to work with them.

Re: [tcpdump-workers] [pcap-ng-format] "Custom" link-layer types for pcap and pcapng

2020-03-27 Thread Michael Richardson via tcpdump-workers
en that it's for *two* capture file formats, these lists are > probably better places for discussion than having two pull requests and > discussing them in comments there. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, San

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-20 Thread Michael Richardson via tcpdump-workers
. I took it directly to the list to ask if this was right. You didn't miss anything. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-20 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Francois-Xavier Le Bail wrote: >> > If we do, we should replace all the tabs in pcap-int.h with spaces; we >> > should at least be consistent, and change #918 fixed one inconsistent >> > case. >> >> Let's agree that we are going towards spaces. >> I th

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-19 Thread Michael Richardson via tcpdump-workers
eople to fix their whitespace settings? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ --- End Messag

[tcpdump-workers] snprintf in libpcap

2020-03-02 Thread Michael Richardson via tcpdump-workers
nk that we just use "snprintf()" now. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] CVE-2018-16301 information (#855)

2019-10-06 Thread Michael Richardson
t; column to my CSV file. I'm just still in a bit of PTSD from having worked on this stuff for too long :-( -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ]

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] CVE-2018-16301 information (#855)

2019-10-06 Thread Michael Richardson
ship, and was not present in libpcap 1.8.x -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

Re: [tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-19 Thread Michael Richardson
enough reason. > Although there'd be more work required - TESTonce depends on having > cat, diff, and sed, and crypto.sh depends on grep, for example. cat and sed I can eliminate. probably the crypto.sh can be brought into the test structure. -- ] Never tell me the odds!

Re: [tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-18 Thread Michael Richardson
Guy Harris wrote: > If "make check" required *only* Perl, not a Bourne-compatible shell, > that might also make running "make check" on Windows easier. That's probably a good enough reason. ___ tcpdump-workers mailing list tcpdump-workers@lists

[tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-18 Thread Michael Richardson
that Perl is now ubiquitous enough on Windows that we could just use one program to drive it all? OpenSSL uses the Perl unit test framework; I'm not sure I'd want to go that far, but I'd consider it. -- ] Never tell me the odds! | ipv6 mesh network

[tcpdump-workers] {clang, gcc} X {i386, x86_64} building, and docker/travis

2019-08-18 Thread Michael Richardson
, or is this going to be a four hour disaster? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___

Re: [tcpdump-workers] New official link-layer type request

2019-05-18 Thread Michael Richardson
intention to have it adopted there, there is no advantage to daking it hta tway. http://socket.hr/draft-dfranusic-elee-00.xml This URL is really good enough for me. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Softw

Re: [tcpdump-workers] New official link-layer type request

2019-05-18 Thread Michael Richardson
ed to be easily extensible. So, you'd create whatever blocks you needed. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/

[tcpdump-workers] libpcap logo?

2019-04-25 Thread Michael Richardson
9...1.0..0.856.5709.0j1j9j1j1j1j2..01..gws-wiz-img.0..0i8i30j0i24j0i10i24.whbzqDKWRMA -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sande

Re: [tcpdump-workers] Link-layer header type for unix domain sockets (UDS)

2019-03-25 Thread Michael Richardson
of thing. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___

[tcpdump-workers] Introducing Season of Docs [LWN.net]

2019-03-22 Thread Michael Richardson
https://lwn.net/Articles/782785/rss If tcpdump was to do this, what kind of things would you want to revise? Man page, web site, pcap API documents, API walkthrough, tuning, how to capture or analyze things... ___ tcpdump-workers mailing list tcpdump-wo

Re: [tcpdump-workers] Request for a new LINKTYPE_/DLT_ type.

2018-12-23 Thread Michael Richardson
records, and what they are used for? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] tcpdump-workers subscription notification

2018-10-31 Thread Michael Richardson
mailman-boun...@lists.tcpdump.org wrote: > PcapPlusPlus Support has been successfully > subscribed to tcpdump-workers. What an interesting email address :-) ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.san

Re: [tcpdump-workers] DLT request for EBHSCR

2018-10-17 Thread Michael Richardson
I'll get you a DLT value by Friday! ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers

Re: [tcpdump-workers] [tcpdump] ndo_nflag in print-sl.c ?

2018-09-23 Thread Michael Richardson
g is the right flag to use. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/|

Re: [tcpdump-workers] pcap_inject change?

2018-09-11 Thread Michael Richardson
Steve Bourland wrote: > Yes, things broke moving from 4.15.0-32 to 4.15.0-34, so it looks like > the change came with the move from -32 to -33 (the original machines > showing the problem have the -33 kernel installed). > These kernels are what come with Ubuntu 18.04 from Canonica

Re: [tcpdump-workers] DLT request for EBHSCR

2018-08-08 Thread Michael Richardson
specific URL? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby

Re: [tcpdump-workers] Should the tcpdump tests be run with TZ=GMT0, or should the AFS printer print time stamps in UTC?

2018-08-08 Thread Michael Richardson
Francois-Xavier Le Bail wrote: >> 2) For tests in TESTLIST, we could build and check the output with TZ=GMT0 (in TESTrun.sh and >> update-test.sh). >> Like that, we could run the tests without the '-t' option and get problems/changes in time printing >> functions. Need an update

Re: [tcpdump-workers] Should the tcpdump tests be run with TZ=GMT0, or should the AFS printer print time stamps in UTC?

2018-08-03 Thread Michael Richardson
ter dumps additional times from within the tickets or something? If so, they should definitely be in UTC... whether we do that with TZ=GMT0 or fix the printer, I'm not sure. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Softw

Re: [tcpdump-workers] [tcpdump-security] [libpcap] Problem with version 1.9.0

2018-07-23 Thread Michael Richardson
7;s switch over to cmake as our official mechanism now... i.e. have travis, etc. use it in preference to configure. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m

[tcpdump-workers] [libpcap] Problem with version 1.9.0

2018-07-23 Thread Michael Richardson
penSSL 1.1.0f 25 May 2017 > libdnet unknown version > Compiled with AddressSanitizer/CLang. > Need autoreconf. > And 1.9.1 ? Let's do 1.9.1 in September. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman

[tcpdump-workers] libpcap 1.9.0 released

2018-07-22 Thread Michael Richardson
e of tcpdump is coming very soon, and a 4.10 as well. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/|

[tcpdump-workers] Precompiled binaries or compile script needed for Android

2018-07-20 Thread Michael Richardson
secur...@tcpdump.org is not an appropriate place to ask about binaries. Sometime on tcpdump-workers might be able to help you. https://www.androidtcpdump.com/ also is around. I don't know who runs it. I spent some time trying to integrate the Android (ASOP) build system Makefiles into tcpdump, but

Re: [tcpdump-workers] tcpdump-workers Digest, Vol 72, Issue 3

2018-07-08 Thread Michael Richardson
Steve Bourland wrote: > If you have the server's certificate, wireshark has the capability to I think you mean the server's private key. > decrypt SSL traffic captured with tcpdump, but you must have the > certificate and the start of the tcp session. TLS 1.3 will break that as it a

[tcpdump-workers] garbage to list

2018-06-30 Thread Michael Richardson
ostfix.org/RESTRICTION_CLASS_README.html#internal][2] -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| rub

Re: [tcpdump-workers] README.Win32 and INSTALL.md for libpcap

2018-06-25 Thread Michael Richardson
attempts to support them, unless somebody *really* objects *and* > is willing to make sure they still work) > While we're at it, we should either commit to supporting the FILES section or remove it. I say remove it. I will clean the INSTALL.md down to: 1) ./configure instruction

Re: [tcpdump-workers] getting libpcap out the door

2018-06-24 Thread Michael Richardson
t know yet if it ran for any of the pushes I did. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

[tcpdump-workers] README.Win32 and INSTALL.md for libpcap

2018-06-24 Thread Michael Richardson
https://github.com/the-tcpdump-group/libpcap/blob/master/INSTALL.md and help us out... -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sa

[tcpdump-workers] automating, or validating DLT_ vs LINKTYPE_ values

2018-06-24 Thread Michael Richardson
dlt.h and that new file from a third file (YAML or JSON or CSV format...) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby

Re: [tcpdump-workers] getting libpcap out the door

2018-06-24 Thread Michael Richardson
Michael Richardson wrote: > Since we now support building on windows, should we attempt to get > appveyor to do regular builds for windows? I see the .appveyor.yml now. I didn't see it integrations, because it's transitioned to webhooks. > Is there another cho

Re: [tcpdump-workers] Time to enable GUESS_TSO by default?

2018-04-13 Thread Michael Richardson
Rick Jones wrote: > It has been a few years since GUESS_TSO was added. Might it be time to > enable it by default? send pull request... update documentation :-) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman So

Re: [tcpdump-workers] Request for link-layer header type (XRA)

2017-11-11 Thread Michael Richardson
the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.

Re: [tcpdump-workers] tcpdump logo on GitHub

2017-10-29 Thread Michael Richardson
ll me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing list tcpdump-workers@lis

Re: [tcpdump-workers] tcpdump logo on GitHub

2017-10-29 Thread Michael Richardson
? > http://www.tcpdump.org/tcpdump_100x100.png Yes, sure, let's put that up. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] let's learn tcpdump

2017-10-17 Thread Michael Richardson
) I found the twitter feed, but not an email (damn whois privacy), or I'd CC. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

[tcpdump-workers] CPE

2017-10-01 Thread Michael Richardson
27;m unclear here. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ __

Re: [tcpdump-workers] Merging RDMA sniffing support?

2017-07-31 Thread Michael Richardson
I didn't look. Such a variety doesn't help me... which one is the minimum I need in order to test the pcap interface? Will the $300 one do? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

Re: [tcpdump-workers] Merging RDMA sniffing support?

2017-07-22 Thread Michael Richardson
Roland Dreier wrote: > Is there anything further that needs to happen for RDMA sniffing > (https://github.com/the-tcpdump-group/libpcap/pull/585) to be merged > into pcap? I think just time. Few of us have the right equipment to test it (or to generate a large enough volume of traffi

[tcpdump-workers] Requesting linktype for AF_VSOCK

2017-07-05 Thread Michael Richardson
Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing li

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] libpcap.so file not always using OBJ_PIC during a make install (#589)

2017-05-25 Thread Michael Richardson
installing from a "/usr/src" that is NFS mounted or something. On the other hand, when developing, it's really a PITA if the object files do not get rebuilt when you expect them to be... -- ] Never tell me the odds! | ipv6 mesh networks [

  1   2   3   4   5   6   7   >