[tcpdump-workers] openssl 1.1 changes required for tcpdump: what minimum openssl?

2016-06-22 Thread Michael Richardson
e the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing list tcpdump-workers@lists.t

[tcpdump-workers] tcpdump for/from Laundry Files

2016-06-26 Thread Michael Richardson
gathered was a baseline anthropic calibration of the annual likelyhood of the sudden demise of a networked civilization. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m

[tcpdump-workers] tcpdump 4.8 soon

2016-07-13 Thread Michael Richardson
IETF96 is next week in Berlin. (unicast me if you want to connect...) As usual, the tcpdump releases tend to get done around an IETF meeting, but my life has been too hectic of recent. There will be a release next week. Probably WednesdayAny show stoppers?

[tcpdump-workers] CHANGES file for x.8.0

2016-08-01 Thread Michael Richardson
Hi, I was about to sign the 4.8.0 tarballs, when I realized that we haven't updated the CHANGES file. I will work on that later tonight, and sign things on Tuesday August 2. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sand

Re: [tcpdump-workers] [the-tcpdump-group/tcpdump] tcpdump fails to build when openssl-1.1 was built with --api=1.1.0 (#539)

2016-09-13 Thread Michael Richardson
packages, or can it be compiled with both APIs? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby

[tcpdump-workers] -fPIC for libnetdissect

2016-10-30 Thread Michael Richardson
ver tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing

Re: [tcpdump-workers] Multiple Needles in Multiple Haystacks.

2016-11-17 Thread Michael Richardson
fix MPD on FreeBSD. I'm a fully open-source ISP ... Yes, I live in Ottawa. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rail

Re: [tcpdump-workers] Request for link layer header type

2017-04-11 Thread Michael Richardson
cess, not ours. We'd love to have a stable URL to point to, but we'll settle for your email address :-) >> (https://github.com/eriknl/LoRaTap). This would be fine, if you put a git tag on it, since you might want to revise it later on. -- ] Never tell me the odds

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] on the fly decompression of savefiles named *.gz (#578)

2017-05-11 Thread Michael Richardson
gzip format from the outset. I have some concern with introducing a new libz.so or something dependancy to libpcap. I wonder if a popen("|gzip >") will work? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman S

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] on the fly decompression of savefiles named *.gz (#578)

2017-05-11 Thread Michael Richardson
it will be used. libz.so is probably pretty ubiquitous, so probably I'm just grasping at straws, but already have a bunch of annoying dependancies for libpcap... -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] [RFC] RDMA sniffing support for pcap (#585)

2017-05-19 Thread Michael Richardson
ung/blob/master/build-setup-travis.sh I build things, and then ask Travis to cache them. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.s

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Added a module definition file for wpcap.dll (#586)

2017-05-21 Thread Michael Richardson
of make release or something? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] One of these things is not like the others

2017-05-24 Thread Michael Richardson
pable output being the purpose of the flag), which puts the IPv4 > input back on one line: How can we move to this format? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ]

Re: [tcpdump-workers] One of these things is not like the others

2017-05-24 Thread Michael Richardson
> with a gflag field in the netdissect_options field. I'm thinking, can we just make it the default? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] libpcap.so file not always using OBJ_PIC during a make install (#589)

2017-05-25 Thread Michael Richardson
installing from a "/usr/src" that is NFS mounted or something. On the other hand, when developing, it's really a PITA if the object files do not get rebuilt when you expect them to be... -- ] Never tell me the odds! | ipv6 mesh networks [

[tcpdump-workers] Requesting linktype for AF_VSOCK

2017-07-05 Thread Michael Richardson
Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing li

Re: [tcpdump-workers] Merging RDMA sniffing support?

2017-07-22 Thread Michael Richardson
Roland Dreier wrote: > Is there anything further that needs to happen for RDMA sniffing > (https://github.com/the-tcpdump-group/libpcap/pull/585) to be merged > into pcap? I think just time. Few of us have the right equipment to test it (or to generate a large enough volume of traffi

Re: [tcpdump-workers] Merging RDMA sniffing support?

2017-07-31 Thread Michael Richardson
I didn't look. Such a variety doesn't help me... which one is the minimum I need in order to test the pcap interface? Will the $300 one do? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works

[tcpdump-workers] CPE

2017-10-01 Thread Michael Richardson
27;m unclear here. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ __

Re: [tcpdump-workers] let's learn tcpdump

2017-10-17 Thread Michael Richardson
) I found the twitter feed, but not an email (damn whois privacy), or I'd CC. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] tcpdump logo on GitHub

2017-10-29 Thread Michael Richardson
? > http://www.tcpdump.org/tcpdump_100x100.png Yes, sure, let's put that up. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] tcpdump logo on GitHub

2017-10-29 Thread Michael Richardson
ll me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing list tcpdump-workers@lis

Re: [tcpdump-workers] Request for link-layer header type (XRA)

2017-11-11 Thread Michael Richardson
the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.

Re: [tcpdump-workers] Time to enable GUESS_TSO by default?

2018-04-13 Thread Michael Richardson
Rick Jones wrote: > It has been a few years since GUESS_TSO was added. Might it be time to > enable it by default? send pull request... update documentation :-) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman So

Re: [tcpdump-workers] getting libpcap out the door

2018-06-24 Thread Michael Richardson
Michael Richardson wrote: > Since we now support building on windows, should we attempt to get > appveyor to do regular builds for windows? I see the .appveyor.yml now. I didn't see it integrations, because it's transitioned to webhooks. > Is there another cho

[tcpdump-workers] automating, or validating DLT_ vs LINKTYPE_ values

2018-06-24 Thread Michael Richardson
dlt.h and that new file from a third file (YAML or JSON or CSV format...) -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby

[tcpdump-workers] README.Win32 and INSTALL.md for libpcap

2018-06-24 Thread Michael Richardson
https://github.com/the-tcpdump-group/libpcap/blob/master/INSTALL.md and help us out... -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sa

Re: [tcpdump-workers] getting libpcap out the door

2018-06-24 Thread Michael Richardson
t know yet if it ran for any of the pushes I did. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

Re: [tcpdump-workers] README.Win32 and INSTALL.md for libpcap

2018-06-25 Thread Michael Richardson
attempts to support them, unless somebody *really* objects *and* > is willing to make sure they still work) > While we're at it, we should either commit to supporting the FILES section or remove it. I say remove it. I will clean the INSTALL.md down to: 1) ./configure instruction

[tcpdump-workers] garbage to list

2018-06-30 Thread Michael Richardson
ostfix.org/RESTRICTION_CLASS_README.html#internal][2] -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| rub

Re: [tcpdump-workers] tcpdump-workers Digest, Vol 72, Issue 3

2018-07-08 Thread Michael Richardson
Steve Bourland wrote: > If you have the server's certificate, wireshark has the capability to I think you mean the server's private key. > decrypt SSL traffic captured with tcpdump, but you must have the > certificate and the start of the tcp session. TLS 1.3 will break that as it a

[tcpdump-workers] Precompiled binaries or compile script needed for Android

2018-07-20 Thread Michael Richardson
secur...@tcpdump.org is not an appropriate place to ask about binaries. Sometime on tcpdump-workers might be able to help you. https://www.androidtcpdump.com/ also is around. I don't know who runs it. I spent some time trying to integrate the Android (ASOP) build system Makefiles into tcpdump, but

[tcpdump-workers] libpcap 1.9.0 released

2018-07-22 Thread Michael Richardson
e of tcpdump is coming very soon, and a 4.10 as well. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/|

[tcpdump-workers] [libpcap] Problem with version 1.9.0

2018-07-23 Thread Michael Richardson
penSSL 1.1.0f 25 May 2017 > libdnet unknown version > Compiled with AddressSanitizer/CLang. > Need autoreconf. > And 1.9.1 ? Let's do 1.9.1 in September. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman

Re: [tcpdump-workers] [tcpdump-security] [libpcap] Problem with version 1.9.0

2018-07-23 Thread Michael Richardson
7;s switch over to cmake as our official mechanism now... i.e. have travis, etc. use it in preference to configure. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m

Re: [tcpdump-workers] Should the tcpdump tests be run with TZ=GMT0, or should the AFS printer print time stamps in UTC?

2018-08-03 Thread Michael Richardson
ter dumps additional times from within the tickets or something? If so, they should definitely be in UTC... whether we do that with TZ=GMT0 or fix the printer, I'm not sure. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Softw

Re: [tcpdump-workers] Should the tcpdump tests be run with TZ=GMT0, or should the AFS printer print time stamps in UTC?

2018-08-08 Thread Michael Richardson
Francois-Xavier Le Bail wrote: >> 2) For tests in TESTLIST, we could build and check the output with TZ=GMT0 (in TESTrun.sh and >> update-test.sh). >> Like that, we could run the tests without the '-t' option and get problems/changes in time printing >> functions. Need an update

Re: [tcpdump-workers] DLT request for EBHSCR

2018-08-08 Thread Michael Richardson
specific URL? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby

Re: [tcpdump-workers] pcap_inject change?

2018-09-11 Thread Michael Richardson
Steve Bourland wrote: > Yes, things broke moving from 4.15.0-32 to 4.15.0-34, so it looks like > the change came with the move from -32 to -33 (the original machines > showing the problem have the -33 kernel installed). > These kernels are what come with Ubuntu 18.04 from Canonica

Re: [tcpdump-workers] [tcpdump] ndo_nflag in print-sl.c ?

2018-09-23 Thread Michael Richardson
g is the right flag to use. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/|

Re: [tcpdump-workers] DLT request for EBHSCR

2018-10-17 Thread Michael Richardson
I'll get you a DLT value by Friday! ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers

Re: [tcpdump-workers] tcpdump-workers subscription notification

2018-10-31 Thread Michael Richardson
mailman-boun...@lists.tcpdump.org wrote: > PcapPlusPlus Support has been successfully > subscribed to tcpdump-workers. What an interesting email address :-) ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.san

Re: [tcpdump-workers] Request for a new LINKTYPE_/DLT_ type.

2018-12-23 Thread Michael Richardson
records, and what they are used for? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/

[tcpdump-workers] Introducing Season of Docs [LWN.net]

2019-03-22 Thread Michael Richardson
https://lwn.net/Articles/782785/rss If tcpdump was to do this, what kind of things would you want to revise? Man page, web site, pcap API documents, API walkthrough, tuning, how to capture or analyze things... ___ tcpdump-workers mailing list tcpdump-wo

Re: [tcpdump-workers] Link-layer header type for unix domain sockets (UDS)

2019-03-25 Thread Michael Richardson
of thing. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___

[tcpdump-workers] libpcap logo?

2019-04-25 Thread Michael Richardson
9...1.0..0.856.5709.0j1j9j1j1j1j2..01..gws-wiz-img.0..0i8i30j0i24j0i10i24.whbzqDKWRMA -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sande

Re: [tcpdump-workers] New official link-layer type request

2019-05-18 Thread Michael Richardson
ed to be easily extensible. So, you'd create whatever blocks you needed. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/

Re: [tcpdump-workers] New official link-layer type request

2019-05-18 Thread Michael Richardson
intention to have it adopted there, there is no advantage to daking it hta tway. http://socket.hr/draft-dfranusic-elee-00.xml This URL is really good enough for me. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Softw

[tcpdump-workers] {clang, gcc} X {i386, x86_64} building, and docker/travis

2019-08-18 Thread Michael Richardson
, or is this going to be a four hour disaster? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ ___

[tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-18 Thread Michael Richardson
that Perl is now ubiquitous enough on Windows that we could just use one program to drive it all? OpenSSL uses the Perl unit test framework; I'm not sure I'd want to go that far, but I'd consider it. -- ] Never tell me the odds! | ipv6 mesh network

Re: [tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-18 Thread Michael Richardson
Guy Harris wrote: > If "make check" required *only* Perl, not a Bourne-compatible shell, > that might also make running "make check" on Windows easier. That's probably a good enough reason. ___ tcpdump-workers mailing list tcpdump-workers@lists

Re: [tcpdump-workers] TESTrun.sh and TESTonce -> combining into single perl driver?

2019-08-19 Thread Michael Richardson
enough reason. > Although there'd be more work required - TESTonce depends on having > cat, diff, and sed, and crypto.sh depends on grep, for example. cat and sed I can eliminate. probably the crypto.sh can be brought into the test structure. -- ] Never tell me the odds!

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] CVE-2018-16301 information (#855)

2019-10-06 Thread Michael Richardson
ship, and was not present in libpcap 1.8.x -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] CVE-2018-16301 information (#855)

2019-10-06 Thread Michael Richardson
t; column to my CSV file. I'm just still in a bit of PTSD from having worked on this stuff for too long :-( -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works| network architect [ ]

[tcpdump-workers] Re: mailman3 list imported

2023-02-15 Thread Michael Richardson
Michael Richardson via tcpdump-workers wrote: > --- Forwarded Message The DMARC mitigation was forced on, which is not what I wanted. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpd

[tcpdump-workers] more testing emails

2023-02-26 Thread Michael Richardson
I'm sorry for the troubles. We are still getting continuous attempts to send email subscribe (DDoS) spam via HTTP, even though mailman2 is gone, and the links are are 404, but the script kiddies continue. fail2ban is doing some things, needs further tuning. But overall, it's just annoying. _

[tcpdump-workers] more testing...

2023-03-13 Thread Michael Richardson
There are some problems on the list host where some files wind up root owned, when they shouldn't be. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpdump-workers-le...@lists.tcpdump.org %(web_p

[tcpdump-workers] Re: libpcap : An entry in the manual about multithreading

2023-05-07 Thread Michael Richardson
> handle. For example there could be a global map of pcap_t* handles to > thread ID's, something like: > struct Mapping { pcap_t *handle; pthread_t thread_id; }; > Mapping mappings[32u]; I could tolerate this. -- ] Never tell me the odds!

[tcpdump-workers] Re: [tcpdump] About PR 812

2023-08-22 Thread Michael Richardson
Francois-Xavier Le Bail wrote: > Does anyone see a problem with this change? (Answer on PR page.) > https://github.com/the-tcpdump-group/tcpdump/pull/812 It looks so simple, it's probably correct :-) -- Michael Richardson. o O ( IPv6 IøT consulting )

[tcpdump-workers] Re: Accurate ECN support in tcpdump/libpcap

2023-09-03 Thread Michael Richardson
Scheffenegger, Richard wrote: > Tcpdump - any every tool afterwards - has been using "." for ACKs. Hi, so there have been some tools which have parsed the tcpdump "TCP" output in the past, and there have been small variations in the output, and often we've broken those tools. One such tool w

[tcpdump-workers] Re: Request for Information: libpcap

2023-10-01 Thread Michael Richardson
Zhang, Cynthia X. (GSFC-710.0)[KPMG LLP] wrote: > Hello, my name is Cynthia Zhang and I am a Supply Chain Risk Management > Analyst at NASA. NASA is currently conducting a supply chain assessment > of libpcap. We are interested in confirming the following information: > 1. Is th

[tcpdump-workers] Re: Removing untested libpcap support for older platforms

2023-10-06 Thread Michael Richardson
Guy Harris wrote: > Should we also consider removing support for some older UN*X platforms, > such as: Yes. > SunOS prior to SunOS 4 - pcap-nit.c; the last such version, SunOS > 3.5, was released in January 1988 > SunOS 4.x - pcap-snit.c; the last such version, SunOS 4.

[tcpdump-workers] Re: Request for a LINKTYPE/DLT for DECT NR+ (ETSI TS 103 636)

2023-10-06 Thread Michael Richardson
Stig Bjørlykke via tcpdump-workers wrote: > We are in the process of making a trace tool and a Wireshark dissector > for DECT NR+ [1]. The "DECT-2020 New Radio (NR); Part 4: MAC layer" > chapter 6 defines PDU formats and parameters for this protocol. > Proposed name: LINKTYPE_DEC

[tcpdump-workers] upgrade to mailman3

2023-12-29 Thread Michael Richardson
We have gone from 3.3.3 to mailman3 3.3.8 with an operating system update to Debian 12 (Devuan 4). Missed the broken kernel (I checked). The previous system had numerous faults, particularly around archiving which I was unable to fix in the time I had available. This message is partly to see if

[tcpdump-workers] Re: upgrade to mailman3

2023-12-29 Thread Michael Richardson
Michael Richardson wrote: > This message is partly to see if anything is fixed. At least the emails went through, but did not get archived yet. Help sought. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe s

[tcpdump-workers] Re: upgrade to mailman3

2023-12-29 Thread Michael Richardson
Michael Richardson wrote: > Michael Richardson wrote: >> This message is partly to see if anything is fixed. > At least the emails went through, but did not get archived yet. > Help sought. maybe working now. ___

[tcpdump-workers] Re: Test

2024-02-24 Thread Michael Richardson
Guy Harris wrote: > Is the list working? It was not. I finally found the web process hanging onto a database lock, and cleared that. ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tcpdump-workers

[tcpdump-workers] openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
system. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ __

[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
Bill Fenner wrote: > mcr suggested: >> I wonder if we should nuke our own make tarball system. > The creation of a tarball and its signature gives a place to hang one's hat > about origin of code - "someone with the right key claims that this tarball > genuinely reflects wh

[tcpdump-workers] Re: openwrt Conclusions from CVE-2024-3094 (libxz disaster)

2024-04-01 Thread Michael Richardson
Guy Harris wrote: > If so, do we > 1) require people to have autotools installed and run ./autogen.sh > or > 2) generate the configure scripts on some standard platform and check it in 3) stop using autoconf, cmake only. ___ tcpdump

[tcpdump-workers] Re: Dropping support in tcpdump for older versions of libpcap?

2024-04-14 Thread Michael Richardson
nd pcap_activate(); those first appeared in libpcap 1.0, which was > released in 2008, almost 16 years ago. > Is there any reason not to require libpcap 1.0 or later? If there is, > is there any reason not to require libpcap 0.7 or later? I think libpcap 1.0 or later is good.

[tcpdump-workers] Re: Support for saving pcapng

2024-05-20 Thread Michael Richardson
se, I wonder if the community is > allowed to submit a pull request for it. Are there any restrictions or > guidelines we should be aware of in this regard? Thanks for your time > and patience. My understanding is that the APSL is not compatible with the BSD 2-clause. -- Michael Ri

[tcpdump-workers] Re: tcpdump. binary

2024-09-06 Thread Michael Richardson
Denis Ovsienko wrote: > To simplify the use of "make install", would it be a reasonable > trade-off to install the additional binary only when the .devel file > exists? That sounds like a good plan. ___ tcpdump-workers mailing list -- tcpdu

[tcpdump-workers] Re: upcoming tcpslice 1.8

2024-09-09 Thread Michael Richardson
Denis Ovsienko wrote: > Let me suggest making tcpslice 1.8 release in 1-2 weeks to avoid yet > another oversized change log section. If anyone sees a good reason not > to, please make your point before long. Who are the users of tcpslice? Are there any heavy users that would like to

[tcpdump-workers] Re: Assistance with Capturing cURL Request using tcpdump

2024-10-01 Thread Michael Richardson
s to dump things. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide ___ tcpdump-workers mailing list -- tcpdump-workers@lists.tcpdump.org To unsubscribe send an email to tc

[tcpdump-workers] Re: Assistance with Capturing cURL Request using tcpdump

2024-10-01 Thread Michael Richardson
Kaushal Shriyan wrote: > I am using Postman to invoke a REST API call. Is there a way to capture the > cURL (https://curl.se/) request (including headers and body) initiated by > the Postman REST API client to the application server running RHEL 8.10 OS, > and then to the backen

[tcpdump-workers] Re: capture and inject device capabilities in libpcap

2024-11-18 Thread Michael Richardson
Denis Ovsienko wrote: > One complication here is that in some cases libpcap may not be aware of > a device capability until it gets an error from the OS (as is the case > with PCAP_ERROR_CAPTURE_NOTSUP in pcap-linux.c), so pcap_findalldevs() > would not be able to set "this device

[tcpdump-workers] Re: Returned mail: Data format error

2024-11-18 Thread Michael Richardson
The message about the spam was in fact spam. But, it forged a valid From: so it got through. I'd like to fix the SPF/DKIM/spam-filter such that it more aggressively kills this kind of forgery, assuming that wireshark.org has the right policies set. This kind of thing is fraught with false-positiv

[tcpdump-workers] Re: tcpdump and pcapng with comments

2025-04-06 Thread Michael Richardson
Mahesh V wrote: > I added some code (modified) tcpdump to write the pcapng file. > while configuring/compiling the source code I get this error > This is a cross compilation for ARM platform Well, likely the resulting flex test can't be run, since it's cross-compiled. I suggest *NOT

[tcpdump-workers] Re: tcpdump and pcapng with comments

2025-04-04 Thread Michael Richardson
Mahesh V wrote: > I would like to know if > 1) tcpdump can write pcapng format (instead of just pcap) Not yet. > 3) read it later on. (I believe this functionality is available today or > alternatively even wireshark would be ok to do this for me) > Is this functionality ava

[tcpdump-workers] bringing in distro and embedded patches

2025-06-22 Thread Michael Richardson
The current set of patches that OpenWRT applies to tcpdump are at: > The current paches are here: > https://github.com/openwrt/openwrt/tree/master/package/libs/libpcap/patches There are no doubt Fedora/RPM, and Debian/DPKG patches too. I for one, would be very happy to see everything up

[tcpdump-workers] Re: v4/v6 packet length printing inconsistency

2025-07-02 Thread Michael Richardson
to show only the lines they care about. The -vv probably changes this too. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandel

[tcpdump-workers] Re: Setting BPF_SPECIAL_VLAN_HANDLING on a "dead" handle

2025-07-04 Thread Michael Richardson
like we ought to specify some kind of target BPF processor option. As you say, pcap mostly just adapts itself to the current kernel, and the dead version has no options. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandel

[tcpdump-workers] Re: Setting BPF_SPECIAL_VLAN_HANDLING on a "dead" handle

2025-07-04 Thread Michael Richardson
Guy Harris wrote: > In the longer term, the compilation process should probably be split > into: yes. > a phase that compiles a filter into a target-independent *and* > link-layer-independent *and* snapshot-length-independent intermediate > representation, optionally doing

[tcpdump-workers] snprintf in libpcap

2020-03-02 Thread Michael Richardson via tcpdump-workers
nk that we just use "snprintf()" now. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-19 Thread Michael Richardson via tcpdump-workers
eople to fix their whitespace settings? -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.ca/| ruby on rails[ --- End Messag

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-20 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Francois-Xavier Le Bail wrote: >> > If we do, we should replace all the tabs in pcap-int.h with spaces; we >> > should at least be consistent, and change #918 fixed one inconsistent >> > case. >> >> Let's agree that we are going towards spaces. >> I th

Re: [tcpdump-workers] [the-tcpdump-group/libpcap] Use tab instead of space in formatting pcap-int.h (#918)

2020-03-20 Thread Michael Richardson via tcpdump-workers
. I took it directly to the list to ask if this was right. You didn't miss anything. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works|IoT architect [ ] m...@sandelman.ca http://www.sandelman.

Re: [tcpdump-workers] [pcap-ng-format] "Custom" link-layer types for pcap and pcapng

2020-03-27 Thread Michael Richardson via tcpdump-workers
en that it's for *two* capture file formats, these lists are > probably better places for discussion than having two pull requests and > discussing them in comments there. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, San

Re: [tcpdump-workers] tcpslice licence

2020-08-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Denis Ovsienko via tcpdump-workers wrote: > [...] >> The first step I'd take would be to get rid of the GPLed headers in >> favor of BSD-licensed headers, e.g. taking the ip.h, tcp.h, and udp.h >> headers from tcpdump and changing the code to work with them.

Re: [tcpdump-workers] CVE-2020-8037: memory allocation in ppp decapsulator

2020-11-30 Thread Michael Richardson via tcpdump-workers
> fixes, or should we rely on Red Hat and others for that? I can strive to do better. I think that you are on the security@ list, and I think that this did go through that list at the time. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richa

[tcpdump-workers] sorry for all the testing

2020-12-19 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Simple tests like: echo "testing 1.2.3." | Mail -s "testing 1.2.3" tcpdump-workers@lists.tcpdump.org are working, but complex emails are not. --- End Message --- ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org

[tcpdump-workers] pcap_open_offline_... and options and the like

2020-12-19 Thread Michael Richardson via tcpdump-workers
3) more extensive rework so that pcap_create() could create handle for live and offline captures, and that specifying the capture type was just another set. These are not mutually exclusive. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael R

Re: [tcpdump-workers] pcap_open_offline_... and options and the like

2020-12-19 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- Michael Richardson via tcpdump-workers wrote: > trying without GPG signature YUP. That's it. So mailman2 will have to get replaced finally. It eats emails with signature attachments, I think. This is new. After a few hours thinking about my previous email I w

[tcpdump-workers] man pages... what's cool now? (fwd) Michael Richardson: man pages... what's cool now?

2020-12-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- I forgot not to PGP sign. --- End Message --- ___ tcpdump-workers mailing list tcpdump-workers@lists.tcpdump.org https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers

[tcpdump-workers] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-21 Thread Michael Richardson via tcpdump-workers
its. Is 0 valid? Or would that be indicated by LENGTH_PRESENT(x)==0? Or is 0 ==> 8 * 16-bits => 128 bits of FCS. I'm going to propose IANA considerations in a followup email and in -01. -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works

[tcpdump-workers] draft-gharris-opsawg-pcap.txt --- IANA considerations

2020-12-21 Thread Michael Richardson via tcpdump-workers
ls.ietf.org/html/draft-gharris-opsawg-pcap-01 Diff: https://www.ietf.org/rfcdiff?url2=draft-gharris-opsawg-pcap-01 -- Michael Richardson. o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide --- End Message --- ___

Re: [tcpdump-workers] [OPSAWG] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-21 Thread Michael Richardson via tcpdump-workers
--- Begin Message --- -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Carsten Bormann wrote: > On 2020-12-22, at 01:31, Michael Richardson wrote: >> >> #define LT_FCS_LENGTH(x) (((x) & 0xF000) >> 28) >> #define LT_FCS_DATALINK_EXT(x

Re: [tcpdump-workers] [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- IANA considerations

2020-12-22 Thread Michael Richardson via tcpdump-workers
PPPoE; per RFC 2516 > That one's there for NetBSD; I *think* the packet contains just a PPPoE > header and payload. I may have to dig into the NetBSD code to see what > they do. okay, but we don't have to get that perfect in the document. What matters is

Re: [tcpdump-workers] [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- FCS length description

2020-12-22 Thread Michael Richardson via tcpdump-workers
was, or whether > it's still supported. Wow, lots of ill-defined complexity here. I think that we should just regard this as water under the bridge. If NetBSD wants to propose a use for those empty bits, then a new specification could update that use case. -- Michael Richardson

<    1   2   3   4   5   6   7   >