diff --git a/examples/captures/out.json b/examples/captures/out.json
index 1859041618..b9e18ab92d 100644
--- a/examples/captures/out.json
+++ b/examples/captures/out.json
@@ -16,12 +16,12 @@
"thiszone": 0,
"sigfigs": 0,
"snaplen": 262144,
- "network": "LinkType::ETHERNET [1]",
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
+ "network": "LinkType::ETHERNET [1]",
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
},
"Frame 1": {
"frame_info": {
@@ -30,7 +30,7 @@
"incl_len": 86,
"orig_len": 86
},
- "time": "2017-11-19T10:49:05.471719",
+ "time": "2017-11-19T15:49:05.471719",
"number": 1,
"time_epoch": "1511106545.471719",
"len": 86,
@@ -53,31 +53,31 @@
"protocol": "TransType::IPv6_ICMP [58]",
"raw": {
"protocol": "TransType::IPv6_ICMP [58]",
- "error": null,
- "packet": {
- "type": "bytes",
- "value": "\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
- "hex": "87000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
- "hex": "87000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "`\u0000\u0000\u0000\u0000 :\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
- "hex": "6000000000203afffe8000000000000000a687f9279316eefe800000000000001ccd7c77bac746b787000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
- }
- },
- "protocols": "Ethernet:IPv6:IPv6_ICMP",
- "packet": {
- "type": "bytes",
- "value": "\ufffd\u0011Z\u001e\ufffd\u0008\u0000N\u0000\u0000\u0000N\u0000\u0000\u0000\ufffd^`\ufffdk\ufffd@3\u001a\u0445\u001c\ufffd\ufffd`\u0000\u0000\u0000\u0000\u0018:\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000",
- "hex": "f1a7115a1ed208004e0000004e000000a45e60d96b9740331ad1851c86dd6000000000183afffe800000000000001ccd7c77bac746b7fe8000000000000000a687f9279316ee88003f8240000000fe80000000000000"
- }
+ "error": null,
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
+ "hex": "87000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
+ "hex": "87000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "`\u0000\u0000\u0000\u0000 :\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\u0000\u000e\ufffd\u0000\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\u0001\u0001\ufffd^`\ufffdk\ufffd",
+ "hex": "6000000000203afffe8000000000000000a687f9279316eefe800000000000001ccd7c77bac746b787000eaa00000000fe800000000000001ccd7c77bac746b70101a45e60d96b97"
+ }
+ },
+ "protocols": "Ethernet:IPv6:IPv6_ICMP",
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\u0011Z\u001e\ufffd\u0008\u0000N\u0000\u0000\u0000N\u0000\u0000\u0000\ufffd^`\ufffdk\ufffd@3\u001a\u0445\u001c\ufffd\ufffd`\u0000\u0000\u0000\u0000\u0018:\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000",
+ "hex": "f1a7115a1ed208004e0000004e000000a45e60d96b9740331ad1851c86dd6000000000183afffe800000000000001ccd7c77bac746b7fe8000000000000000a687f9279316ee88003f8240000000fe80000000000000"
+ }
},
"Frame 2": {
"frame_info": {
@@ -86,7 +86,7 @@
"incl_len": 78,
"orig_len": 78
},
- "time": "2017-11-19T10:49:05.578078",
+ "time": "2017-11-19T15:49:05.578078",
"number": 2,
"time_epoch": "1511106545.578078",
"len": 78,
@@ -109,31 +109,31 @@
"protocol": "TransType::IPv6_ICMP [58]",
"raw": {
"protocol": "TransType::IPv6_ICMP [58]",
- "error": null,
- "packet": {
- "type": "bytes",
- "value": "\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
- "hex": "88003f8240000000fe800000000000001ccd7c77bac746b7"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
- "hex": "88003f8240000000fe800000000000001ccd7c77bac746b7"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "`\u0000\u0000\u0000\u0000\u0018:\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
- "hex": "6000000000183afffe800000000000001ccd7c77bac746b7fe8000000000000000a687f9279316ee88003f8240000000fe800000000000001ccd7c77bac746b7"
- }
- },
- "protocols": "Ethernet:IPv6:IPv6_ICMP",
- "packet": {
- "type": "bytes",
- "value": "\ufffd\ufffd\u0011ZL\ufffd\u000b\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd^`\ufffdk\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdG\u0008\u0000E\u0000\u0000(\ufffd4@\u0000+\u0006z\ufffd{\ufffd\u0487\ufffd\ufffd\u0001d\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000\ufffd\ufffd\u0011Z\ufffd\ufffd\u000b\u0000",
- "hex": "f5a7115a4cde0b003600000036000000a45e60d96b97b8f883a5f947080045000028c53440002b067a867b81d287c0a801640050d7c0d59fb154a67aa0ff50117cb07c8e0000f5a7115a8cde0b00"
- }
+ "error": null,
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
+ "hex": "88003f8240000000fe800000000000001ccd7c77bac746b7"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
+ "hex": "88003f8240000000fe800000000000001ccd7c77bac746b7"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "`\u0000\u0000\u0000\u0000\u0018:\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u0000\ufffd\ufffd\ufffd'\ufffd\u0016\ufffd\u0000?\ufffd@\u0000\u0000\u0000\ufffd\ufffd\u0000\u0000\u0000\u0000\u0000\u0000\u001c\ufffd|w\ufffd\ufffdF\ufffd",
+ "hex": "6000000000183afffe800000000000001ccd7c77bac746b7fe8000000000000000a687f9279316ee88003f8240000000fe800000000000001ccd7c77bac746b7"
+ }
+ },
+ "protocols": "Ethernet:IPv6:IPv6_ICMP",
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\ufffd\u0011ZL\ufffd\u000b\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd^`\ufffdk\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdG\u0008\u0000E\u0000\u0000(\ufffd4@\u0000+\u0006z\ufffd{\ufffd\u0487\ufffd\ufffd\u0001d\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000\ufffd\ufffd\u0011Z\ufffd\ufffd\u000b\u0000",
+ "hex": "f5a7115a4cde0b003600000036000000a45e60d96b97b8f883a5f947080045000028c53440002b067a867b81d287c0a801640050d7c0d59fb154a67aa0ff50117cb07c8e0000f5a7115a8cde0b00"
+ }
},
"Frame 3": {
"frame_info": {
@@ -142,7 +142,7 @@
"incl_len": 54,
"orig_len": 54
},
- "time": "2017-11-19T10:49:09.777804",
+ "time": "2017-11-19T15:49:09.777804",
"number": 3,
"time_epoch": "1511106549.777804",
"len": 54,
@@ -177,71 +177,71 @@
},
"src": "123.129.210.135",
"dst": "192.168.1.100",
- "tcp": {
- "srcport": {
- "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
- "svc": "www-http",
- "port": 80,
- "proto": "TransportProtocol::tcp|udp [3]"
- },
- "dstport": {
- "enum": "AppType::PORT_55232_tcp [unknown [55232 - tcp]]",
- "svc": "unknown",
- "port": 55232,
- "proto": "TransportProtocol::tcp [1]"
- },
- "seq": 3584012628,
- "ack": 2793054463,
- "hdr_len": 20,
- "flags": {
- "cwr": false,
- "ece": false,
- "urg": false,
- "ack": true,
- "psh": false,
- "rst": false,
- "syn": false,
- "fin": true
- },
- "window_size": 31920,
- "checksum": {
- "type": "bytes",
- "value": "|\ufffd",
- "hex": "7c8e"
- },
- "urgent_pointer": 0,
- "connection": "Flags::ACK|FIN [34816]",
- "nopayload": {
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000",
- "hex": "0050d7c0d59fb154a67aa0ff50117cb07c8e0000"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "E\u0000\u0000(\ufffd4@\u0000+\u0006z\ufffd{\ufffd\u0487\ufffd\ufffd\u0001d\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000",
- "hex": "45000028c53440002b067a867b81d287c0a801640050d7c0d59fb154a67aa0ff50117cb07c8e0000"
- }
- },
- "protocols": "Ethernet:IPv4:TCP",
- "packet": {
- "type": "bytes",
- "value": "\ufffd\ufffd\u0011Z\ufffd\ufffd\u000b\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffdG\ufffd^`\ufffdk\ufffd\u0008\u0000E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\ufffd\ufffd\u0000P",
- "hex": "f5a7115a8cde0b003600000036000000b8f883a5f947a45e60d96b970800450000280000400040062abbc0a801647b81d287d7c00050"
- }
+ "tcp": {
+ "srcport": {
+ "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
+ "svc": "www-http",
+ "port": 80,
+ "proto": "TransportProtocol::tcp|udp [3]"
+ },
+ "dstport": {
+ "enum": "AppType::PORT_55232_tcp [unknown [55232 - tcp]]",
+ "svc": "unknown",
+ "port": 55232,
+ "proto": "TransportProtocol::tcp [1]"
+ },
+ "seq": 3584012628,
+ "ack": 2793054463,
+ "hdr_len": 20,
+ "flags": {
+ "cwr": false,
+ "ece": false,
+ "urg": false,
+ "ack": true,
+ "psh": false,
+ "rst": false,
+ "syn": false,
+ "fin": true
+ },
+ "window_size": 31920,
+ "checksum": {
+ "type": "bytes",
+ "value": "|\ufffd",
+ "hex": "7c8e"
+ },
+ "urgent_pointer": 0,
+ "connection": "Flags::ACK|FIN [34816]",
+ "nopayload": {
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000",
+ "hex": "0050d7c0d59fb154a67aa0ff50117cb07c8e0000"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "E\u0000\u0000(\ufffd4@\u0000+\u0006z\ufffd{\ufffd\u0487\ufffd\ufffd\u0001d\u0000P\ufffd\ufffd\u055f\ufffdT\ufffdz\ufffd\ufffdP\u0011|\ufffd|\ufffd\u0000\u0000",
+ "hex": "45000028c53440002b067a867b81d287c0a801640050d7c0d59fb154a67aa0ff50117cb07c8e0000"
+ }
+ },
+ "protocols": "Ethernet:IPv4:TCP",
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\ufffd\u0011Z\ufffd\ufffd\u000b\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffdG\ufffd^`\ufffdk\ufffd\u0008\u0000E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\ufffd\ufffd\u0000P",
+ "hex": "f5a7115a8cde0b003600000036000000b8f883a5f947a45e60d96b970800450000280000400040062abbc0a801647b81d287d7c00050"
+ }
},
"Frame 4": {
"frame_info": {
@@ -250,7 +250,7 @@
"incl_len": 54,
"orig_len": 54
},
- "time": "2017-11-19T10:49:09.777868",
+ "time": "2017-11-19T15:49:09.777868",
"number": 4,
"time_epoch": "1511106549.777868",
"len": 54,
@@ -285,71 +285,71 @@
},
"src": "192.168.1.100",
"dst": "123.129.210.135",
- "tcp": {
- "srcport": {
- "enum": "AppType::PORT_55232_tcp [unknown [55232 - tcp]]",
- "svc": "unknown",
- "port": 55232,
- "proto": "TransportProtocol::tcp [1]"
- },
- "dstport": {
- "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
- "svc": "www-http",
- "port": 80,
- "proto": "TransportProtocol::tcp|udp [3]"
- },
- "seq": 2793054463,
- "ack": 3584012629,
- "hdr_len": 20,
- "flags": {
- "cwr": false,
- "ece": false,
- "urg": false,
- "ack": true,
- "psh": false,
- "rst": false,
- "syn": false,
- "fin": false
- },
- "window_size": 65535,
- "checksum": {
- "type": "bytes",
- "value": "\ufffd>",
- "hex": "f93e"
- },
- "urgent_pointer": 0,
- "connection": "Flags::ACK [2048]",
- "nopayload": {
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\ufffd\ufffd\u0000P\ufffdz\ufffd\ufffd\u055f\ufffdUP\u0010\ufffd\ufffd\ufffd>\u0000\u0000",
- "hex": "d7c00050a67aa0ffd59fb1555010fffff93e0000"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\ufffd\ufffd\u0000P\ufffdz\ufffd\ufffd\u055f\ufffdUP\u0010\ufffd\ufffd\ufffd>\u0000\u0000",
- "hex": "450000280000400040062abbc0a801647b81d287d7c00050a67aa0ffd59fb1555010fffff93e0000"
- }
- },
- "protocols": "Ethernet:IPv4:TCP",
- "packet": {
- "type": "bytes",
- "value": "\ufffd\ufffd\u0011Z8\ufffd\r\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffdG\ufffd^`\ufffdk\ufffd\u0008\u0000E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\u05f0\u0000P",
- "hex": "f5a7115a38f10d003600000036000000b8f883a5f947a45e60d96b970800450000280000400040062abbc0a801647b81d287d7b00050"
- }
+ "tcp": {
+ "srcport": {
+ "enum": "AppType::PORT_55232_tcp [unknown [55232 - tcp]]",
+ "svc": "unknown",
+ "port": 55232,
+ "proto": "TransportProtocol::tcp [1]"
+ },
+ "dstport": {
+ "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
+ "svc": "www-http",
+ "port": 80,
+ "proto": "TransportProtocol::tcp|udp [3]"
+ },
+ "seq": 2793054463,
+ "ack": 3584012629,
+ "hdr_len": 20,
+ "flags": {
+ "cwr": false,
+ "ece": false,
+ "urg": false,
+ "ack": true,
+ "psh": false,
+ "rst": false,
+ "syn": false,
+ "fin": false
+ },
+ "window_size": 65535,
+ "checksum": {
+ "type": "bytes",
+ "value": "\ufffd>",
+ "hex": "f93e"
+ },
+ "urgent_pointer": 0,
+ "connection": "Flags::ACK [2048]",
+ "nopayload": {
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\ufffd\u0000P\ufffdz\ufffd\ufffd\u055f\ufffdUP\u0010\ufffd\ufffd\ufffd>\u0000\u0000",
+ "hex": "d7c00050a67aa0ffd59fb1555010fffff93e0000"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\ufffd\ufffd\u0000P\ufffdz\ufffd\ufffd\u055f\ufffdUP\u0010\ufffd\ufffd\ufffd>\u0000\u0000",
+ "hex": "450000280000400040062abbc0a801647b81d287d7c00050a67aa0ffd59fb1555010fffff93e0000"
+ }
+ },
+ "protocols": "Ethernet:IPv4:TCP",
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\ufffd\u0011Z8\ufffd\r\u00006\u0000\u0000\u00006\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffdG\ufffd^`\ufffdk\ufffd\u0008\u0000E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\u05f0\u0000P",
+ "hex": "f5a7115a38f10d003600000036000000b8f883a5f947a45e60d96b970800450000280000400040062abbc0a801647b81d287d7b00050"
+ }
},
"Frame 5": {
"frame_info": {
@@ -358,7 +358,7 @@
"incl_len": 54,
"orig_len": 54
},
- "time": "2017-11-19T10:49:09.913720",
+ "time": "2017-11-19T15:49:09.913720",
"number": 5,
"time_epoch": "1511106549.91372",
"len": 54,
@@ -393,71 +393,71 @@
},
"src": "192.168.1.100",
"dst": "123.129.210.135",
- "tcp": {
- "srcport": {
- "enum": "AppType::PORT_55216_tcp [unknown [55216 - tcp]]",
- "svc": "unknown",
- "port": 55216,
- "proto": "TransportProtocol::tcp [1]"
- },
- "dstport": {
- "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
- "svc": "www-http",
- "port": 80,
- "proto": "TransportProtocol::tcp|udp [3]"
- },
- "seq": 768904481,
- "ack": 1835365486,
- "hdr_len": 20,
- "flags": {
- "cwr": false,
- "ece": false,
- "urg": false,
- "ack": true,
- "psh": false,
- "rst": false,
- "syn": false,
- "fin": true
- },
- "window_size": 65535,
- "checksum": {
- "type": "bytes",
- "value": "*\ufffd",
- "hex": "2af4"
- },
- "urgent_pointer": 0,
- "connection": "Flags::ACK|FIN [34816]",
- "nopayload": {
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\u05f0\u0000P-\u050d!metnP\u0011\ufffd\ufffd*\ufffd\u0000\u0000",
- "hex": "d7b000502dd48d216d65746e5011ffff2af40000"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\u05f0\u0000P-\u050d!metnP\u0011\ufffd\ufffd*\ufffd\u0000\u0000",
- "hex": "450000280000400040062abbc0a801647b81d287d7b000502dd48d216d65746e5011ffff2af40000"
+ "tcp": {
+ "srcport": {
+ "enum": "AppType::PORT_55216_tcp [unknown [55216 - tcp]]",
+ "svc": "unknown",
+ "port": 55216,
+ "proto": "TransportProtocol::tcp [1]"
+ },
+ "dstport": {
+ "enum": "AppType::www_http [www-http [80 - tcp|udp]]",
+ "svc": "www-http",
+ "port": 80,
+ "proto": "TransportProtocol::tcp|udp [3]"
+ },
+ "seq": 768904481,
+ "ack": 1835365486,
+ "hdr_len": 20,
+ "flags": {
+ "cwr": false,
+ "ece": false,
+ "urg": false,
+ "ack": true,
+ "psh": false,
+ "rst": false,
+ "syn": false,
+ "fin": true
+ },
+ "window_size": 65535,
+ "checksum": {
+ "type": "bytes",
+ "value": "*\ufffd",
+ "hex": "2af4"
+ },
+ "urgent_pointer": 0,
+ "connection": "Flags::ACK|FIN [34816]",
+ "nopayload": {
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\u05f0\u0000P-\u050d!metnP\u0011\ufffd\ufffd*\ufffd\u0000\u0000",
+ "hex": "d7b000502dd48d216d65746e5011ffff2af40000"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "E\u0000\u0000(\u0000\u0000@\u0000@\u0006*\ufffd\ufffd\ufffd\u0001d{\ufffd\u0487\u05f0\u0000P-\u050d!metnP\u0011\ufffd\ufffd*\ufffd\u0000\u0000",
+ "hex": "450000280000400040062abbc0a801647b81d287d7b000502dd48d216d65746e5011ffff2af40000"
}
},
- "protocols": "Ethernet:IPv4:TCP",
- "packet": {
- "type": "bytes",
- "value": "\ufffd\ufffd\u0011Z\u0013\u0005\u0001\u0000\ufffd\u0000\u0000\u0000\ufffd\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdG\u0008\u0000E\u0000\u0000\ufffd\u0000\u0000@\u0000@\u0011x\ufffd\ufffd\ufffd\u0001\u0001\ufffd\ufffd\ufffd\ufffd\ufffdD\u0013\ufffd",
- "hex": "f7a7115a130501009f0000009f000000ffffffffffffb8f883a5f94708004500009100004000401178b3c0a80101ffffffff92441389"
- }
+ "protocols": "Ethernet:IPv4:TCP",
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffd\ufffd\u0011Z\u0013\u0005\u0001\u0000\ufffd\u0000\u0000\u0000\ufffd\u0000\u0000\u0000\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffd\ufffdG\u0008\u0000E\u0000\u0000\ufffd\u0000\u0000@\u0000@\u0011x\ufffd\ufffd\ufffd\u0001\u0001\ufffd\ufffd\ufffd\ufffd\ufffdD\u0013\ufffd",
+ "hex": "f7a7115a130501009f0000009f000000ffffffffffffb8f883a5f94708004500009100004000401178b3c0a80101ffffffff92441389"
+ }
},
"Frame 6": {
"frame_info": {
@@ -466,7 +466,7 @@
"incl_len": 159,
"orig_len": 159
},
- "time": "2017-11-19T10:49:11.066835",
+ "time": "2017-11-19T15:49:11.066835",
"number": 6,
"time_epoch": "1511106551.066835",
"len": 159,
@@ -501,57 +501,57 @@
},
"src": "192.168.1.1",
"dst": "255.255.255.255",
- "udp": {
- "srcport": {
- "enum": "AppType::unassigned_37444 [unassigned [37444 - undefined]]",
- "svc": "unassigned",
- "port": 37444,
- "proto": "TransportProtocol::undefined [0]"
- },
- "dstport": {
- "enum": "AppType::commplex_link [commplex-link [5001 - tcp|udp]]",
- "svc": "commplex-link",
- "port": 5001,
- "proto": "TransportProtocol::tcp|udp [3]"
- },
- "len": 125,
- "checksum": {
- "type": "bytes",
- "value": "c\ufffd",
- "hex": "63b1"
- },
- "raw": {
- "protocol": null,
- "error": null,
- "packet": {
- "type": "bytes",
- "value": "\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
- "hex": "01010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
- "hex": "01010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
- }
- },
- "packet": {
- "type": "bytes",
- "value": "\ufffdD\u0013\ufffd\u0000}c\ufffd\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
- "hex": "92441389007d63b101010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
+ "udp": {
+ "srcport": {
+ "enum": "AppType::unassigned_37444 [unassigned [37444 - undefined]]",
+ "svc": "unassigned",
+ "port": 37444,
+ "proto": "TransportProtocol::undefined [0]"
+ },
+ "dstport": {
+ "enum": "AppType::commplex_link [commplex-link [5001 - tcp|udp]]",
+ "svc": "commplex-link",
+ "port": 5001,
+ "proto": "TransportProtocol::tcp|udp [3]"
+ },
+ "len": 125,
+ "checksum": {
+ "type": "bytes",
+ "value": "c\ufffd",
+ "hex": "63b1"
+ },
+ "raw": {
+ "protocol": null,
+ "error": null,
+ "packet": {
+ "type": "bytes",
+ "value": "\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
+ "hex": "01010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
+ "hex": "01010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
+ }
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "\ufffdD\u0013\ufffd\u0000}c\ufffd\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
+ "hex": "92441389007d63b101010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
}
- },
- "packet": {
- "type": "bytes",
- "value": "E\u0000\u0000\ufffd\u0000\u0000@\u0000@\u0011x\ufffd\ufffd\ufffd\u0001\u0001\ufffd\ufffd\ufffd\ufffd\ufffdD\u0013\ufffd\u0000}c\ufffd\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
- "hex": "4500009100004000401178b3c0a80101ffffffff92441389007d63b101010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
+ },
+ "packet": {
+ "type": "bytes",
+ "value": "E\u0000\u0000\ufffd\u0000\u0000@\u0000@\u0011x\ufffd\ufffd\ufffd\u0001\u0001\ufffd\ufffd\ufffd\ufffd\ufffdD\u0013\ufffd\u0000}c\ufffd\u0001\u0001\u000e\u0000\ufffd+\ufffd\ufffd\ufffd\ufffd\u0000g\u0000\u0000\u0000\u0006\u0000\nTL-WDR6300\u0000\u000b\u0000\u00036.0\u0000\u0007\u0000\u0001\u0001\u0000\u0005\u0000\u0011B8-F8-83-A5-F9-47\u0000\u0008\u0000\u000b192.168.1.1\u0000\t\u0000\ntplogin.cn\u0000\n\u0000\u000eTL-WDR6300 6.0\u0000\f\u0000\u00051.7.4",
+ "hex": "4500009100004000401178b3c0a80101ffffffff92441389007d63b101010e00e12b83c7f98b006700000006000a544c2d57445236333030000b0003362e3000070001010005001142382d46382d38332d41352d46392d34370008000b3139322e3136382e312e310009000a74706c6f67696e2e636e000a000e544c2d5744523633303020362e30000c0005312e372e34"
}
},
- "protocols": "Ethernet:IPv4:UDP:Raw",
- "packet": {
- "type": "bytes",
- "value": "",
- "hex": ""
- }
+ "protocols": "Ethernet:IPv4:UDP:Raw",
+ "packet": {
+ "type": "bytes",
+ "value": "",
+ "hex": ""
+ }
}
-}
+}
\ No newline at end of file
diff --git a/examples/captures/out.plist b/examples/captures/out.plist
index 2c7f7eb842..815ece9fab 100644
--- a/examples/captures/out.plist
+++ b/examples/captures/out.plist
@@ -48,7 +48,7 @@
86
time
- 2017-11-19T10:49:05.471719Z
+ 2017-11-19T15:49:05.471719Z
number
1
time_epoch
@@ -121,7 +121,7 @@
78
time
- 2017-11-19T10:49:05.578078Z
+ 2017-11-19T15:49:05.578078Z
number
2
time_epoch
@@ -194,7 +194,7 @@
54
time
- 2017-11-19T10:49:09.777804Z
+ 2017-11-19T15:49:09.777804Z
number
3
time_epoch
@@ -343,7 +343,7 @@
54
time
- 2017-11-19T10:49:09.777868Z
+ 2017-11-19T15:49:09.777868Z
number
4
time_epoch
@@ -492,7 +492,7 @@
54
time
- 2017-11-19T10:49:09.913720Z
+ 2017-11-19T15:49:09.913720Z
number
5
time_epoch
@@ -641,7 +641,7 @@
159
time
- 2017-11-19T10:49:11.066835Z
+ 2017-11-19T15:49:11.066835Z
number
6
time_epoch
diff --git a/examples/captures/out.txt b/examples/captures/out.txt
index 687a5d20b6..824fb657b7 100644
--- a/examples/captures/out.txt
+++ b/examples/captures/out.txt
@@ -20,7 +20,7 @@ Frame 1
| |-- ts_usec -> 471719
| |-- incl_len -> 86
| |-- orig_len -> 86
- |-- time -> 2017-11-19T10:49:05.471719
+ |-- time -> 2017-11-19T15:49:05.471719
|-- number -> 1
|-- time_epoch -> 1511106545.471719
|-- len -> 86
@@ -73,7 +73,7 @@ Frame 2
| |-- ts_usec -> 578078
| |-- incl_len -> 78
| |-- orig_len -> 78
- |-- time -> 2017-11-19T10:49:05.578078
+ |-- time -> 2017-11-19T15:49:05.578078
|-- number -> 2
|-- time_epoch -> 1511106545.578078
|-- len -> 78
@@ -124,7 +124,7 @@ Frame 3
| |-- ts_usec -> 777804
| |-- incl_len -> 54
| |-- orig_len -> 54
- |-- time -> 2017-11-19T10:49:09.777804
+ |-- time -> 2017-11-19T15:49:09.777804
|-- number -> 3
|-- time_epoch -> 1511106549.777804
|-- len -> 54
@@ -209,7 +209,7 @@ Frame 4
| |-- ts_usec -> 777868
| |-- incl_len -> 54
| |-- orig_len -> 54
- |-- time -> 2017-11-19T10:49:09.777868
+ |-- time -> 2017-11-19T15:49:09.777868
|-- number -> 4
|-- time_epoch -> 1511106549.777868
|-- len -> 54
@@ -294,7 +294,7 @@ Frame 5
| |-- ts_usec -> 913720
| |-- incl_len -> 54
| |-- orig_len -> 54
- |-- time -> 2017-11-19T10:49:09.913720
+ |-- time -> 2017-11-19T15:49:09.913720
|-- number -> 5
|-- time_epoch -> 1511106549.91372
|-- len -> 54
@@ -379,7 +379,7 @@ Frame 6
| |-- ts_usec -> 66835
| |-- incl_len -> 159
| |-- orig_len -> 159
- |-- time -> 2017-11-19T10:49:11.066835
+ |-- time -> 2017-11-19T15:49:11.066835
|-- number -> 6
|-- time_epoch -> 1511106551.066835
|-- len -> 159
diff --git a/examples/captures/pcapng.txt b/examples/captures/pcapng.txt
index 0d7fa0bfeb..9c3c284174 100644
--- a/examples/captures/pcapng.txt
+++ b/examples/captures/pcapng.txt
@@ -11,6 +11,7 @@ Section Header 1
| |--> 0
|-- section_length -> -1
|-- options -> NIL
+ |-- packet -> NIL
Interface Description 1
|-- type
@@ -20,23 +21,24 @@ Interface Description 1
|-- linktype -> LinkType::ETHERNET [1]
|-- snaplen -> 65535
|-- options
- |-- OptionType::if_tsresol [if_tsresol [9]]
- | |--> --
- | |-- type
- | | |-- enum -> OptionType::if_tsresol [if_tsresol [9]]
- | | |-- opt_name -> if_tsresol
- | | |-- opt_value -> 9
- | |-- length -> 1
- | |-- resolution -> 1000000
- |-- OptionType::opt_endofopt [opt_endofopt [0]]
- |--> --
- |-- type
- | |-- enum
- | | |--> OptionType::opt_endofopt [opt_endofopt
- | | [0]]
- | |-- opt_name -> opt_endofopt
- | |-- opt_value -> 0
- |-- length -> 0
+ | |-- OptionType::if_tsresol [if_tsresol [9]]
+ | | |--> --
+ | | |-- type
+ | | | |-- enum -> OptionType::if_tsresol [if_tsresol [9]]
+ | | | |-- opt_name -> if_tsresol
+ | | | |-- opt_value -> 9
+ | | |-- length -> 1
+ | | |-- resolution -> 1000000
+ | |-- OptionType::opt_endofopt [opt_endofopt [0]]
+ | |--> --
+ | |-- type
+ | | |-- enum
+ | | | |--> OptionType::opt_endofopt [opt_endofopt
+ | | | [0]]
+ | | |-- opt_name -> opt_endofopt
+ | | |-- opt_value -> 0
+ | |-- length -> 0
+ |-- packet -> NIL
Frame 1
|-- type -> BlockType::Enhanced_Packet_Block [6]
@@ -44,8 +46,8 @@ Frame 1
|-- section_number -> 1
|-- number -> 1
|-- interface_id -> 0
- |-- timestamp -> 2004-12-06T03:16:24.317453+08:00
- |-- timestamp_epoch -> 1102302984.317453
+ |-- timestamp -> 2004-12-05T19:16:24.317453+00:00
+ |-- timestamp_epoch -> 1102274184.317453
|-- captured_len -> 314
|-- original_len -> 314
|-- options -> NIL
@@ -56,60 +58,118 @@ Frame 1
| | |--> EtherType::Internet_Protocol_version_4
| | [2048]
| |-- ipv4
- | |-- version -> 4
- | |-- hdr_len -> 20
- | |-- tos
- | | |-- pre -> ToSPrecedence::Routine [0]
- | | |-- del -> ToSDelay::NORMAL [0]
- | | |-- thr -> ToSThroughput::NORMAL [0]
- | | |-- rel -> ToSReliability::NORMAL [0]
- | | |-- ecn -> ToSECN::Not_ECT [0]
- | |-- len -> 300
- | |-- id -> 43062
- | |-- flags
- | | |-- df -> False
- | | |-- mf -> False
- | |-- offset -> 0
- | |-- ttl -> 250.0
- | |-- protocol -> TransType::UDP [17]
- | |-- checksum -> 17 8b
- | |-- src -> 0.0.0.0
- | |-- dst -> 255.255.255.255
- | |-- udp
- | |-- srcport
- | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
- | | |-- svc -> bootpc
- | | |-- port -> 68
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- dstport
- | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
- | | |-- svc -> bootps
- | | |-- port -> 67
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- len -> 280
- | |-- checksum -> 59 1f
- | |-- raw
- | |-- protocol -> NIL
- | |-- packet
- | | |--> 01 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
- | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
- | | 35 01 01 3d 07 01 00 0b 82 01 fc 42 32 04 00 00
- | | 00 00 37 04 01 03 06 2a ff 00 00 00 00 00 00 00
- | |-- error -> NIL
+ | | |-- version -> 4
+ | | |-- hdr_len -> 20
+ | | |-- tos
+ | | | |-- pre -> ToSPrecedence::Routine [0]
+ | | | |-- del -> ToSDelay::NORMAL [0]
+ | | | |-- thr -> ToSThroughput::NORMAL [0]
+ | | | |-- rel -> ToSReliability::NORMAL [0]
+ | | | |-- ecn -> ToSECN::Not_ECT [0]
+ | | |-- len -> 300
+ | | |-- id -> 43062
+ | | |-- flags
+ | | | |-- df -> False
+ | | | |-- mf -> False
+ | | |-- offset -> 0
+ | | |-- ttl -> 250.0
+ | | |-- protocol -> TransType::UDP [17]
+ | | |-- checksum -> 17 8b
+ | | |-- src -> 0.0.0.0
+ | | |-- dst -> 255.255.255.255
+ | | |-- udp
+ | | | |-- srcport
+ | | | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
+ | | | | |-- svc -> bootpc
+ | | | | |-- port -> 68
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- dstport
+ | | | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
+ | | | | |-- svc -> bootps
+ | | | | |-- port -> 67
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- len -> 280
+ | | | |-- checksum -> 59 1f
+ | | | |-- raw
+ | | | | |-- protocol -> NIL
+ | | | | |-- error -> NIL
+ | | | | |-- packet
+ | | | | |--> 01 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | | 35 01 01 3d 07 01 00 0b 82 01 fc 42 32 04 00 00
+ | | | | 00 00 37 04 01 03 06 2a ff 00 00 00 00 00 00 00
+ | | | |-- packet
+ | | | |--> 01 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | 35 01 01 3d 07 01 00 0b 82 01 fc 42 32 04 00 00
+ | | | 00 00 37 04 01 03 06 2a ff 00 00 00 00 00 00 00
+ | | |-- packet
+ | | |--> 00 44 00 43 01 18 59 1f 01 01 06 00 00 00 3d 1d
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 0b 82 01 fc 42 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 63 82 53 63 35 01 01 3d 07 01 00 0b
+ | | 82 01 fc 42 32 04 00 00 00 00 37 04 01 03 06 2a
+ | | ff 00 00 00 00 00 00 00
+ | |-- packet
+ | |--> 45 00 01 2c a8 36 00 00 fa 11 17 8b 00 00 00 00
+ | ff ff ff ff 00 44 00 43 01 18 59 1f 01 01 06 00
+ | 00 00 3d 1d 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 0b 82 01 fc 42 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 63 82 53 63 35 01 01 3d
+ | 07 01 00 0b 82 01 fc 42 32 04 00 00 00 00 37 04
+ | 01 03 06 2a ff 00 00 00 00 00 00 00
|-- protocols -> Ethernet:IPv4:UDP:Raw
+ |-- packet -> NIL
Frame 2
|-- type -> BlockType::Enhanced_Packet_Block [6]
@@ -117,8 +177,8 @@ Frame 2
|-- section_number -> 1
|-- number -> 2
|-- interface_id -> 0
- |-- timestamp -> 2004-12-06T03:16:24.317748+08:00
- |-- timestamp_epoch -> 1102302984.317748
+ |-- timestamp -> 2004-12-05T19:16:24.317748+00:00
+ |-- timestamp_epoch -> 1102274184.317748
|-- captured_len -> 342
|-- original_len -> 342
|-- options -> NIL
@@ -129,62 +189,126 @@ Frame 2
| | |--> EtherType::Internet_Protocol_version_4
| | [2048]
| |-- ipv4
- | |-- version -> 4
- | |-- hdr_len -> 20
- | |-- tos
- | | |-- pre -> ToSPrecedence::Routine [0]
- | | |-- del -> ToSDelay::NORMAL [0]
- | | |-- thr -> ToSThroughput::NORMAL [0]
- | | |-- rel -> ToSReliability::NORMAL [0]
- | | |-- ecn -> ToSECN::Not_ECT [0]
- | |-- len -> 328
- | |-- id -> 1093
- | |-- flags
- | | |-- df -> False
- | | |-- mf -> False
- | |-- offset -> 0
- | |-- ttl -> 128.0
- | |-- protocol -> TransType::UDP [17]
- | |-- checksum -> 00 00
- | |-- src -> 192.168.0.1
- | |-- dst -> 192.168.0.10
- | |-- udp
- | |-- srcport
- | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
- | | |-- svc -> bootps
- | | |-- port -> 67
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- dstport
- | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
- | | |-- svc -> bootpc
- | | |-- port -> 68
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- len -> 308
- | |-- checksum -> 22 33
- | |-- raw
- | |-- protocol -> NIL
- | |-- packet
- | | |--> 02 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
- | | c0 a8 00 0a c0 a8 00 01 00 00 00 00 00 0b 82 01
- | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
- | | 35 01 02 01 04 ff ff ff 00 3a 04 00 00 07 08 3b
- | | 04 00 00 0c 4e 33 04 00 00 0e 10 36 04 c0 a8 00
- | | 01 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00
- | |-- error -> NIL
+ | | |-- version -> 4
+ | | |-- hdr_len -> 20
+ | | |-- tos
+ | | | |-- pre -> ToSPrecedence::Routine [0]
+ | | | |-- del -> ToSDelay::NORMAL [0]
+ | | | |-- thr -> ToSThroughput::NORMAL [0]
+ | | | |-- rel -> ToSReliability::NORMAL [0]
+ | | | |-- ecn -> ToSECN::Not_ECT [0]
+ | | |-- len -> 328
+ | | |-- id -> 1093
+ | | |-- flags
+ | | | |-- df -> False
+ | | | |-- mf -> False
+ | | |-- offset -> 0
+ | | |-- ttl -> 128.0
+ | | |-- protocol -> TransType::UDP [17]
+ | | |-- checksum -> 00 00
+ | | |-- src -> 192.168.0.1
+ | | |-- dst -> 192.168.0.10
+ | | |-- udp
+ | | | |-- srcport
+ | | | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
+ | | | | |-- svc -> bootps
+ | | | | |-- port -> 67
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- dstport
+ | | | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
+ | | | | |-- svc -> bootpc
+ | | | | |-- port -> 68
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- len -> 308
+ | | | |-- checksum -> 22 33
+ | | | |-- raw
+ | | | | |-- protocol -> NIL
+ | | | | |-- error -> NIL
+ | | | | |-- packet
+ | | | | |--> 02 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
+ | | | | c0 a8 00 0a c0 a8 00 01 00 00 00 00 00 0b 82 01
+ | | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | | 35 01 02 01 04 ff ff ff 00 3a 04 00 00 07 08 3b
+ | | | | 04 00 00 0c 4e 33 04 00 00 0e 10 36 04 c0 a8 00
+ | | | | 01 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | |-- packet
+ | | | |--> 02 01 06 00 00 00 3d 1d 00 00 00 00 00 00 00 00
+ | | | c0 a8 00 0a c0 a8 00 01 00 00 00 00 00 0b 82 01
+ | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | 35 01 02 01 04 ff ff ff 00 3a 04 00 00 07 08 3b
+ | | | 04 00 00 0c 4e 33 04 00 00 0e 10 36 04 c0 a8 00
+ | | | 01 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00
+ | | |-- packet
+ | | |--> 00 43 00 44 01 34 22 33 02 01 06 00 00 00 3d 1d
+ | | 00 00 00 00 00 00 00 00 c0 a8 00 0a c0 a8 00 01
+ | | 00 00 00 00 00 0b 82 01 fc 42 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 63 82 53 63 35 01 02 01 04 ff ff ff
+ | | 00 3a 04 00 00 07 08 3b 04 00 00 0c 4e 33 04 00
+ | | 00 0e 10 36 04 c0 a8 00 01 ff 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00
+ | |-- packet
+ | |--> 45 00 01 48 04 45 00 00 80 11 00 00 c0 a8 00 01
+ | c0 a8 00 0a 00 43 00 44 01 34 22 33 02 01 06 00
+ | 00 00 3d 1d 00 00 00 00 00 00 00 00 c0 a8 00 0a
+ | c0 a8 00 01 00 00 00 00 00 0b 82 01 fc 42 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 63 82 53 63 35 01 02 01
+ | 04 ff ff ff 00 3a 04 00 00 07 08 3b 04 00 00 0c
+ | 4e 33 04 00 00 0e 10 36 04 c0 a8 00 01 ff 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00
|-- protocols -> Ethernet:IPv4:UDP:Raw
+ |-- packet -> NIL
Frame 3
|-- type -> BlockType::Enhanced_Packet_Block [6]
@@ -192,8 +316,8 @@ Frame 3
|-- section_number -> 1
|-- number -> 3
|-- interface_id -> 0
- |-- timestamp -> 2004-12-06T03:16:24.387484+08:00
- |-- timestamp_epoch -> 1102302984.387484
+ |-- timestamp -> 2004-12-05T19:16:24.387484+00:00
+ |-- timestamp_epoch -> 1102274184.387484
|-- captured_len -> 314
|-- original_len -> 314
|-- options -> NIL
@@ -204,60 +328,118 @@ Frame 3
| | |--> EtherType::Internet_Protocol_version_4
| | [2048]
| |-- ipv4
- | |-- version -> 4
- | |-- hdr_len -> 20
- | |-- tos
- | | |-- pre -> ToSPrecedence::Routine [0]
- | | |-- del -> ToSDelay::NORMAL [0]
- | | |-- thr -> ToSThroughput::NORMAL [0]
- | | |-- rel -> ToSReliability::NORMAL [0]
- | | |-- ecn -> ToSECN::Not_ECT [0]
- | |-- len -> 300
- | |-- id -> 43063
- | |-- flags
- | | |-- df -> False
- | | |-- mf -> False
- | |-- offset -> 0
- | |-- ttl -> 250.0
- | |-- protocol -> TransType::UDP [17]
- | |-- checksum -> 17 8a
- | |-- src -> 0.0.0.0
- | |-- dst -> 255.255.255.255
- | |-- udp
- | |-- srcport
- | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
- | | |-- svc -> bootpc
- | | |-- port -> 68
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- dstport
- | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
- | | |-- svc -> bootps
- | | |-- port -> 67
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- len -> 280
- | |-- checksum -> 9f bd
- | |-- raw
- | |-- protocol -> NIL
- | |-- packet
- | | |--> 01 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
- | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
- | | 35 01 03 3d 07 01 00 0b 82 01 fc 42 32 04 c0 a8
- | | 00 0a 36 04 c0 a8 00 01 37 04 01 03 06 2a ff 00
- | |-- error -> NIL
+ | | |-- version -> 4
+ | | |-- hdr_len -> 20
+ | | |-- tos
+ | | | |-- pre -> ToSPrecedence::Routine [0]
+ | | | |-- del -> ToSDelay::NORMAL [0]
+ | | | |-- thr -> ToSThroughput::NORMAL [0]
+ | | | |-- rel -> ToSReliability::NORMAL [0]
+ | | | |-- ecn -> ToSECN::Not_ECT [0]
+ | | |-- len -> 300
+ | | |-- id -> 43063
+ | | |-- flags
+ | | | |-- df -> False
+ | | | |-- mf -> False
+ | | |-- offset -> 0
+ | | |-- ttl -> 250.0
+ | | |-- protocol -> TransType::UDP [17]
+ | | |-- checksum -> 17 8a
+ | | |-- src -> 0.0.0.0
+ | | |-- dst -> 255.255.255.255
+ | | |-- udp
+ | | | |-- srcport
+ | | | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
+ | | | | |-- svc -> bootpc
+ | | | | |-- port -> 68
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- dstport
+ | | | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
+ | | | | |-- svc -> bootps
+ | | | | |-- port -> 67
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- len -> 280
+ | | | |-- checksum -> 9f bd
+ | | | |-- raw
+ | | | | |-- protocol -> NIL
+ | | | | |-- error -> NIL
+ | | | | |-- packet
+ | | | | |--> 01 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | | 35 01 03 3d 07 01 00 0b 82 01 fc 42 32 04 c0 a8
+ | | | | 00 0a 36 04 c0 a8 00 01 37 04 01 03 06 2a ff 00
+ | | | |-- packet
+ | | | |--> 01 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | 35 01 03 3d 07 01 00 0b 82 01 fc 42 32 04 c0 a8
+ | | | 00 0a 36 04 c0 a8 00 01 37 04 01 03 06 2a ff 00
+ | | |-- packet
+ | | |--> 00 44 00 43 01 18 9f bd 01 01 06 00 00 00 3d 1e
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 0b 82 01 fc 42 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 63 82 53 63 35 01 03 3d 07 01 00 0b
+ | | 82 01 fc 42 32 04 c0 a8 00 0a 36 04 c0 a8 00 01
+ | | 37 04 01 03 06 2a ff 00
+ | |-- packet
+ | |--> 45 00 01 2c a8 37 00 00 fa 11 17 8a 00 00 00 00
+ | ff ff ff ff 00 44 00 43 01 18 9f bd 01 01 06 00
+ | 00 00 3d 1e 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 0b 82 01 fc 42 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 63 82 53 63 35 01 03 3d
+ | 07 01 00 0b 82 01 fc 42 32 04 c0 a8 00 0a 36 04
+ | c0 a8 00 01 37 04 01 03 06 2a ff 00
|-- protocols -> Ethernet:IPv4:UDP:Raw
+ |-- packet -> NIL
Frame 4
|-- type -> BlockType::Enhanced_Packet_Block [6]
@@ -265,8 +447,8 @@ Frame 4
|-- section_number -> 1
|-- number -> 4
|-- interface_id -> 0
- |-- timestamp -> 2004-12-06T03:16:24.387798+08:00
- |-- timestamp_epoch -> 1102302984.387798
+ |-- timestamp -> 2004-12-05T19:16:24.387798+00:00
+ |-- timestamp_epoch -> 1102274184.387798
|-- captured_len -> 342
|-- original_len -> 342
|-- options -> NIL
@@ -277,59 +459,123 @@ Frame 4
| | |--> EtherType::Internet_Protocol_version_4
| | [2048]
| |-- ipv4
- | |-- version -> 4
- | |-- hdr_len -> 20
- | |-- tos
- | | |-- pre -> ToSPrecedence::Routine [0]
- | | |-- del -> ToSDelay::NORMAL [0]
- | | |-- thr -> ToSThroughput::NORMAL [0]
- | | |-- rel -> ToSReliability::NORMAL [0]
- | | |-- ecn -> ToSECN::Not_ECT [0]
- | |-- len -> 328
- | |-- id -> 1094
- | |-- flags
- | | |-- df -> False
- | | |-- mf -> False
- | |-- offset -> 0
- | |-- ttl -> 128.0
- | |-- protocol -> TransType::UDP [17]
- | |-- checksum -> 00 00
- | |-- src -> 192.168.0.1
- | |-- dst -> 192.168.0.10
- | |-- udp
- | |-- srcport
- | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
- | | |-- svc -> bootps
- | | |-- port -> 67
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- dstport
- | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
- | | |-- svc -> bootpc
- | | |-- port -> 68
- | | |-- proto -> TransportProtocol::tcp|udp [3]
- | |-- len -> 308
- | |-- checksum -> df db
- | |-- raw
- | |-- protocol -> NIL
- | |-- packet
- | | |--> 02 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
- | | c0 a8 00 0a 00 00 00 00 00 00 00 00 00 0b 82 01
- | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
- | | 35 01 05 3a 04 00 00 07 08 3b 04 00 00 0c 4e 33
- | | 04 00 00 0e 10 36 04 c0 a8 00 01 01 04 ff ff ff
- | | 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- | | 00 00 00 00 00 00 00 00 00 00 00 00
- | |-- error -> NIL
+ | | |-- version -> 4
+ | | |-- hdr_len -> 20
+ | | |-- tos
+ | | | |-- pre -> ToSPrecedence::Routine [0]
+ | | | |-- del -> ToSDelay::NORMAL [0]
+ | | | |-- thr -> ToSThroughput::NORMAL [0]
+ | | | |-- rel -> ToSReliability::NORMAL [0]
+ | | | |-- ecn -> ToSECN::Not_ECT [0]
+ | | |-- len -> 328
+ | | |-- id -> 1094
+ | | |-- flags
+ | | | |-- df -> False
+ | | | |-- mf -> False
+ | | |-- offset -> 0
+ | | |-- ttl -> 128.0
+ | | |-- protocol -> TransType::UDP [17]
+ | | |-- checksum -> 00 00
+ | | |-- src -> 192.168.0.1
+ | | |-- dst -> 192.168.0.10
+ | | |-- udp
+ | | | |-- srcport
+ | | | | |-- enum -> AppType::bootps [bootps [67 - tcp|udp]]
+ | | | | |-- svc -> bootps
+ | | | | |-- port -> 67
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- dstport
+ | | | | |-- enum -> AppType::bootpc [bootpc [68 - tcp|udp]]
+ | | | | |-- svc -> bootpc
+ | | | | |-- port -> 68
+ | | | | |-- proto -> TransportProtocol::tcp|udp [3]
+ | | | |-- len -> 308
+ | | | |-- checksum -> df db
+ | | | |-- raw
+ | | | | |-- protocol -> NIL
+ | | | | |-- error -> NIL
+ | | | | |-- packet
+ | | | | |--> 02 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
+ | | | | c0 a8 00 0a 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | | 35 01 05 3a 04 00 00 07 08 3b 04 00 00 0c 4e 33
+ | | | | 04 00 00 0e 10 36 04 c0 a8 00 01 01 04 ff ff ff
+ | | | | 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | | 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | |-- packet
+ | | | |--> 02 01 06 00 00 00 3d 1e 00 00 00 00 00 00 00 00
+ | | | c0 a8 00 0a 00 00 00 00 00 00 00 00 00 0b 82 01
+ | | | fc 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00 63 82 53 63
+ | | | 35 01 05 3a 04 00 00 07 08 3b 04 00 00 0c 4e 33
+ | | | 04 00 00 0e 10 36 04 c0 a8 00 01 01 04 ff ff ff
+ | | | 00 ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | | 00 00 00 00 00 00 00 00 00 00 00 00
+ | | |-- packet
+ | | |--> 00 43 00 44 01 34 df db 02 01 06 00 00 00 3d 1e
+ | | 00 00 00 00 00 00 00 00 c0 a8 00 0a 00 00 00 00
+ | | 00 00 00 00 00 0b 82 01 fc 42 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00 63 82 53 63 35 01 05 3a 04 00 00 07
+ | | 08 3b 04 00 00 0c 4e 33 04 00 00 0e 10 36 04 c0
+ | | a8 00 01 01 04 ff ff ff 00 ff 00 00 00 00 00 00
+ | | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | | 00 00 00 00
+ | |-- packet
+ | |--> 45 00 01 48 04 46 00 00 80 11 00 00 c0 a8 00 01
+ | c0 a8 00 0a 00 43 00 44 01 34 df db 02 01 06 00
+ | 00 00 3d 1e 00 00 00 00 00 00 00 00 c0 a8 00 0a
+ | 00 00 00 00 00 00 00 00 00 0b 82 01 fc 42 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00 63 82 53 63 35 01 05 3a
+ | 04 00 00 07 08 3b 04 00 00 0c 4e 33 04 00 00 0e
+ | 10 36 04 c0 a8 00 01 01 04 ff ff ff 00 ff 00 00
+ | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
+ | 00 00 00 00 00 00 00 00
|-- protocols -> Ethernet:IPv4:UDP:Raw
+ |-- packet -> NIL
diff --git a/examples/legacy_smoke/Makefile b/examples/legacy_smoke/Makefile
index baf5fc364e..e7b6bb4bd3 100644
--- a/examples/legacy_smoke/Makefile
+++ b/examples/legacy_smoke/Makefile
@@ -1,7 +1,28 @@
-.PHONY:
+.PHONY: fixtures profile
+#: Interpreter to run the demos with. Override for a virtualenv, e.g.
+#: `make fixtures PYTHON=../../.venv/bin/python`.
+PYTHON ?= python
+
+#: Timezone the committed fixtures are generated in. Pinned because pcapkit renders
+#: frame timestamps in the host's local zone, so an unpinned run rewrites every
+#: timestamp line with wherever it happened to be run. UTC is also the only zone in
+#: which PCAP-NG's `timestamp_epoch` comes out as the true UNIX epoch -- see the
+#: README for the reason.
+FIXTURE_TZ ?= UTC
+
+## Regenerate the four committed fixtures in ../captures/.
+## out.json, out.plist, out.txt <- test_extractor.py, from ../captures/in.pcap
+## pcapng.txt <- test_pcapng.py, from ../captures/dhcp.pcapng
+## Both inputs are committed, so this needs no `make samples` first.
+fixtures:
+ TZ=$(FIXTURE_TZ) $(PYTHON) test_extractor.py
+ TZ=$(FIXTURE_TZ) $(PYTHON) test_pcapng.py
+ @echo 'regenerated ../captures/{out.json,out.plist,out.txt,pcapng.txt}'
+
+## Profile one extraction and render the call graph.
profile:
mkdir -p temp
- python test_profile.py
+ $(PYTHON) test_profile.py
gprof2dot -f pstats temp/parse_pcap.pstats | dot -Tpng -o temp/parse_pcap.png
snakeviz temp/parse_pcap.pstats
diff --git a/examples/legacy_smoke/README.md b/examples/legacy_smoke/README.md
index 319debaf6b..e31a4cb616 100644
--- a/examples/legacy_smoke/README.md
+++ b/examples/legacy_smoke/README.md
@@ -1,13 +1,107 @@
-# Test Samples
-
- Here we provide several test samples. Though the original PCAP files are not uploaded due to restrictions on file size of GitHub, you may still easily get a simple but thorough view of `pcapkit`, either on how to use it or on what it can do.
-
- - [`test_extraction`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_extraction.py) -- samples on usage of `pcapkit.extract`, which extracts a PCAP file and dumps to a specificly formatted output file
- - [`test_ipv6`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_ipv6.py) -- samples on extraction of IPv6 packets, whilst dumping a tree-view text file
- - [`test_http`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_http.py) -- samples on extraction of HTTP packets, whilst checking if HTTP is `in` the frame
- - [`test_reassembly`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_reassembly.py) -- samples on reassembly of TCP payloads, whilst writing the reassembled payloads into an output file
- - [`test_analyse`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_analyse.py) -- samples on analysis of application layer after reassembly, which writes the extracted HTTP frame to `stdout`
- - [`test_time`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_time.py) -- samples on a minimum usage of `pcapkit.extract`, whilst timing the whole procedure
- - [`test_trace`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_trace.py) -- samples on tracing TCP flows
- - [`test_engine`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_engine.py) -- samples on different extraction engines
- - [`test_profile`](https://github.com/JarryShaw/pcapkit/tree/main/examples/legacy_smoke/test_profile.py) -- samples on performance analysis of `pcapkit`
+# Demonstration Scripts
+
+ A tour of `pcapkit` by example: each script here does one thing and prints or dumps the
+result, so you can get a thorough view of the library either on how to use it or on what it
+can do. They are demos rather than tests -- `pytest` does not collect this directory
+(`testpaths = ["tests"]`) and nothing in CI runs them, so they are also where API drift goes
+unnoticed the longest. Run them after changing anything public.
+
+## Running them
+
+ Every script reads its capture with a path relative to its own directory, so **run them
+from inside `examples/legacy_smoke/`**, not from the repository root:
+
+```shell
+cd examples/legacy_smoke
+python test_basic.py
+```
+
+ The captures live in `../captures/`. Only `in.pcap` and `dhcp.pcapng` are committed; the
+rest are generated, so build them once before running anything else:
+
+```shell
+python ../generators/make_samples.py # or: make samples, from the repository root
+```
+
+## The scripts
+
+| Script | What it demonstrates |
+|---|---|
+| [`test_basic`](test_basic.py) | the smallest useful call -- extract `in.pcap` to a tree-view text file |
+| [`test_extractor`](test_extractor.py) | `pcapkit.extract` dumping the same capture as plist, JSON and tree |
+| [`test_file`](test_file.py) | reading from an already-open binary file object rather than a path |
+| [`test_api`](test_api.py) | most of the keyword surface at once: per-frame files, reassembly and flow tracing |
+| [`test_tcp`](test_tcp.py) | extraction of TCP packets |
+| [`test_ipv6`](test_ipv6.py) | extraction of IPv6 packets, one output file per frame |
+| [`test_pcapng`](test_pcapng.py) | extraction of a PCAP-NG capture, which uses a different engine |
+| [`test_http`](test_http.py) | iterating frames manually and testing `pcapkit.HTTP in frame` |
+| [`test_reassembly`](test_reassembly.py) | TCP payload reassembly, writing the reassembled datagrams out |
+| [`test_ip_reasm`](test_ip_reasm.py) | IPv4 fragment reassembly |
+| [`test_ipv6_reasm`](test_ipv6_reasm.py) | IPv6 fragment reassembly |
+| [`test_analyse`](test_analyse.py) | analysis of the application layer *after* reassembly, printing the recovered HTTP messages |
+| [`test_trace`](test_trace.py) | tracing TCP flows and dumping the flow index |
+| [`test_engine`](test_engine.py) | the same capture through each extraction engine, side by side |
+| [`test_time`](test_time.py) | timing each engine, reported as milliseconds per packet |
+| [`test_profile`](test_profile.py) | cProfile stats for one extraction; `make profile` renders the call graph |
+| [`test_perf`](test_perf.py) | the same comparison under the `pyperf` benchmark harness |
+| [`test_stream`](test_stream.py) | extracting a live capture streamed from `tcpdump` on stdin |
+| [`test_stream_askpass`](test_stream_askpass.py) | the same, with `sudo -A` for a non-interactive password |
+
+ `_engine_support.py` is not a demo -- it is the shared helper the engine demos use to
+work out whether an engine can run on this host.
+
+## What needs more than pcapkit
+
+ Most of these run with nothing but `pcapkit`. These do not:
+
+- **`test_engine`, `test_time`, `test_perf`** exercise the `dpkt`, `scapy` and `pyshark`
+ engines. Those are optional packages, and `pyshark` additionally drives Wireshark's
+ `tshark` binary. An engine that is missing is reported as skipped, with the reason, and the
+ rest still run -- see `_engine_support.py`. Two things worth knowing:
+ - `pyshark` 0.6 does not work on Python 3.14 at all. It asks
+ `asyncio.get_event_loop_policy().get_event_loop()` for a loop on a thread that has none,
+ which 3.14 no longer creates implicitly, so every extraction through it raises
+ `RuntimeError: There is no current event loop in thread 'MainThread'` before `tshark` is
+ even reached. That is a pyshark bug, not a pcapkit one, and there is nothing to configure
+ around it.
+ - When an engine's *package* is missing, `pcapkit.extract` does not fail. It warns and
+ falls back to pcapkit's own parser, so the extraction succeeds under the wrong engine.
+ The demos name the driver that actually ran, so a fallback is visible rather than being
+ reported as a healthy result.
+- **`test_perf`** needs the `pyperf` harness, which `pcapkit` does not depend on:
+ `python -m pip install pyperf`. Without it the script says so and stops. `test_time.py`
+ does the same comparison with no extra dependency.
+- **`test_profile`**'s `make profile` target needs `gprof2dot`, `graphviz` and `snakeviz` to
+ render the call graph. The script itself only needs `pcapkit`.
+- **`test_stream`, `test_stream_askpass`** run `sudo tcpdump` against a live interface, so
+ they need root and cannot run unattended. `INTERFACE` at the top of each is `en0` (macOS);
+ on Linux it is usually `eth0` or `wlan0`. They buffer the live capture into a temporary
+ file -- never into `../captures/`, which holds generated captures the test suite pins.
+
+## Regenerating the committed fixtures
+
+ Four files in `../captures/` are committed outputs rather than inputs, and they are
+produced by two of the scripts here. To refresh them after a change to how `pcapkit` renders
+a capture:
+
+```shell
+cd examples/legacy_smoke && make fixtures
+```
+
+ That is the whole recipe. It runs, equivalently:
+
+```shell
+TZ=UTC python test_extractor.py # ../captures/out.json, out.plist, out.txt <- in.pcap
+TZ=UTC python test_pcapng.py # ../captures/pcapng.txt <- dhcp.pcapng
+```
+
+ Both inputs are committed, so this works on a fresh clone with no `make samples` first.
+Use `make fixtures PYTHON=../../.venv/bin/python` to pick a specific interpreter.
+
+ **`TZ=UTC` is not decoration.** `pcapkit` renders frame timestamps in the host's local
+zone, so an unpinned run rewrites every timestamp line in all four files with wherever it
+happened to be run -- which is how these fixtures came to disagree with each other, the PCAP
+three having been generated at UTC-05:00 and `pcapng.txt` at UTC+08:00. Pinning UTC makes the
+output reproducible on any host. It also happens to be the only zone in which PCAP-NG's
+`timestamp_epoch` is the true UNIX epoch: `PCAPNG._read_timestamp` adds the zone's UTC offset
+to the value it returns, so a fixture generated anywhere else bakes in that offset.
diff --git a/examples/legacy_smoke/_engine_support.py b/examples/legacy_smoke/_engine_support.py
new file mode 100644
index 0000000000..7fbd1e4bed
--- /dev/null
+++ b/examples/legacy_smoke/_engine_support.py
@@ -0,0 +1,149 @@
+# -*- coding: utf-8 -*-
+"""Which extraction engines can actually run on this host.
+
+``pcapkit`` ships four extraction engines and three of them lean on something the
+host may simply not have: ``dpkt``, ``scapy`` and ``pyshark`` are optional
+third-party packages, and ``pyshark`` additionally drives the external ``tshark``
+binary from Wireshark. On top of that, ``pyshark`` 0.6 calls
+``asyncio.get_event_loop_policy().get_event_loop()`` on a thread with no running
+loop. Creating one implicitly there was deprecated years ago and Python 3.14 no
+longer does it, raising ``RuntimeError: There is no current event loop in thread
+'MainThread'`` instead -- so on 3.14 ``pyshark`` cannot be used at all, whatever else
+is installed.
+
+None of those is a ``pcapkit`` defect, and the demos in this directory should not
+die on any of them. So they call :func:`unavailable` on whatever the engine raised:
+it returns a human-readable reason when the engine is merely unavailable here, and
+:data:`None` when the failure is real and must be allowed to propagate.
+
+There is a quieter failure to account for as well. When an engine's package is not
+installed at all, ``Extractor`` does *not* raise -- it emits an ``EngineWarning``
+and falls back to pcapkit's own parser, so the extraction succeeds and reports a
+frame count that has nothing to do with the engine that was asked for.
+:func:`ran_as_asked` is how the demos tell the two apart.
+
+This module is a helper for the demos, not a demo itself.
+
+"""
+
+import sys
+from typing import TYPE_CHECKING
+
+if TYPE_CHECKING:
+ from pcapkit.foundation.extraction import Extractor
+
+__all__ = ['ENGINES', 'unavailable', 'ran_as_asked', 'report', 'preflight']
+
+#: The extraction engines ``pcapkit.extract(engine=...)`` accepts, in the order the
+#: demos exercise them. ``'default'`` is pcapkit's own parser (also spelled
+#: ``'pcapkit'``) and is the only one with no third-party requirement; further
+#: engines can be added at runtime with
+#: :func:`pcapkit.foundation.registry.foundation.register_extractor_engine`.
+ENGINES = ('default', 'pyshark', 'scapy', 'dpkt')
+
+#: ``__engine_name__`` of the driver each ``engine=`` value should end up using.
+#: ``'default'`` and ``'pcapkit'`` pick their parser from the file's magic number,
+#: so either of two names is correct for them.
+ENGINE_DRIVERS = {
+ 'default': ('PCAP', 'PCAP-NG'),
+ 'pcapkit': ('PCAP', 'PCAP-NG'),
+ 'dpkt': ('DPKT',),
+ 'scapy': ('Scapy',),
+ 'pyshark': ('PyShark',),
+}
+
+
+def unavailable(exc: 'Exception') -> 'str | None':
+ """Explain *exc* if it means the engine cannot run on this host.
+
+ Args:
+ exc: Exception the engine raised.
+
+ Returns:
+ A reason to report the engine as skipped, or :data:`None` if *exc* is a
+ genuine failure that the caller should re-raise.
+
+ """
+ # A missing optional package. pcapkit raises its own ModuleNotFound, which
+ # derives from ImportError, so one check covers both it and a plain import.
+ if isinstance(exc, ImportError):
+ return f'{exc.name or exc} is not installed'
+
+ # pyshark needs Wireshark's tshark on PATH. Matched by name rather than
+ # imported, since pyshark itself may be the thing that is missing.
+ if type(exc).__name__ == 'TSharkNotFoundException':
+ return 'the tshark binary from Wireshark is not installed'
+
+ # pyshark 0.6 on Python 3.14: it asks the event loop policy for the current
+ # loop on a thread that has none. Not something pcapkit can work around.
+ if isinstance(exc, RuntimeError) and 'event loop' in str(exc):
+ version = '.'.join(str(part) for part in sys.version_info[:3])
+ return (f'{exc} -- pyshark asks for an implicit asyncio event loop, '
+ f'which Python {version} no longer provides (pyshark bug, not pcapkit)')
+
+ return None
+
+
+def ran_as_asked(engine: 'str', extraction: 'Extractor') -> 'tuple[str, bool]':
+ """Which driver *extraction* really used, and whether it is the one asked for.
+
+ Args:
+ engine: Engine name that was passed to ``pcapkit.extract``.
+ extraction: The resulting extractor.
+
+ Returns:
+ The driver's ``__engine_name__`` and whether it matches *engine*. A
+ mismatch means the engine's package is not installed and ``Extractor``
+ fell back to its own parser, having only warned about it.
+
+ """
+ driver = extraction.engine.__engine_name__
+ return driver, driver in ENGINE_DRIVERS.get(engine, (engine,))
+
+
+def report(engine: 'str', detail: 'str') -> 'None':
+ """Print one line of an engine report.
+
+ Args:
+ engine: Engine name.
+ detail: What happened, e.g. ``'6 frames'`` or ``'skipped -- ...'``.
+
+ """
+ print(f'{engine:>8}: {detail}', flush=True)
+
+
+def preflight(engine: 'str', fin: 'str') -> 'str | None':
+ """Try *engine* once on *fin* and report whether it works here.
+
+ Useful before a timing or benchmarking run, where the extraction itself is
+ repeated thousands of times and a failure on the first round would throw the
+ whole measurement away.
+
+ Args:
+ engine: Engine name to try.
+ fin: Capture file to read.
+
+ Returns:
+ :data:`None` if the engine works, else the reason it is unavailable.
+
+ Raises:
+ Exception: Whatever the engine raised, if it is a real failure rather than
+ the engine being unavailable on this host.
+
+ """
+ import pcapkit # imported here so this module stays importable on its own
+
+ try:
+ extraction = pcapkit.extract(fin=fin, store=False, nofile=True, verbose=False,
+ engine=engine) # type: ignore[arg-type]
+ except Exception as exc: # pylint: disable=broad-except
+ reason = unavailable(exc)
+ if reason is None:
+ raise
+ return reason
+
+ driver, asked = ran_as_asked(engine, extraction)
+ if not asked:
+ return (f'its package is not installed -- pcapkit fell back to its own '
+ f'{driver} parser, so timing it would measure the wrong thing')
+ return None
diff --git a/examples/legacy_smoke/test_analyse.py b/examples/legacy_smoke/test_analyse.py
index 765fd93fe6..2b017d8297 100644
--- a/examples/legacy_smoke/test_analyse.py
+++ b/examples/legacy_smoke/test_analyse.py
@@ -4,9 +4,14 @@
import pcapkit
+# NOTE: ``reassembly=True`` is what turns reassembly on; ``tcp=True`` only selects
+# which protocol to reassemble, and ``reasm_strict`` only tunes it. Without it the
+# extraction runs to completion and then ``extraction.reassembly`` raises
+# ``UnsupportedCall``, since the attribute is gated on the reassembly flag.
extraction = pcapkit.extract(
fin='../captures/http6.cap', # fout='../captures/http.txt', format='tree',
- store=False, tcp=True, verbose=True, nofile=True, reasm_strict=True, extension=False
+ store=False, tcp=True, verbose=True, nofile=True, reassembly=True,
+ reasm_strict=True, extension=False
)
# pprint.pprint(extraction.reassembly.tcp)
print()
diff --git a/examples/legacy_smoke/test_api.py b/examples/legacy_smoke/test_api.py
index 3d254c9590..68f6f6af92 100644
--- a/examples/legacy_smoke/test_api.py
+++ b/examples/legacy_smoke/test_api.py
@@ -2,6 +2,10 @@
import pcapkit
+# NOTE: ``ip``, ``tcp`` and ``reasm_strict`` are reassembly knobs and do nothing on
+# their own -- ``reassembly=True`` is the flag that switches reassembly on, just as
+# ``trace=True`` switches flow tracing on. ``tcp=True`` feeds both.
json = pcapkit.extract(fin='../captures/http.pcap', fout='../captures/http', format='json', files=True,
- store=True, verbose=True, ip=True, tcp=True, reasm_strict=False, trace=True,
+ store=True, verbose=True, reassembly=True, ip=True, tcp=True,
+ reasm_strict=False, trace=True,
trace_format='json', trace_fout='../captures/trace')
diff --git a/examples/legacy_smoke/test_engine.py b/examples/legacy_smoke/test_engine.py
index fde59cf7be..c4e110751b 100644
--- a/examples/legacy_smoke/test_engine.py
+++ b/examples/legacy_smoke/test_engine.py
@@ -1,16 +1,45 @@
# -*- coding: utf-8 -*-
+"""Extract one capture with each of pcapkit's extraction engines.
+
+Every engine is asked for the same tree-view dump of the same file, so the outputs
+under ``../captures/engines/`` can be compared side by side.
+
+An engine that is not available on this host is reported as skipped, with the
+reason, and the rest of the demo carries on -- see :mod:`_engine_support` for what
+counts as unavailable. Anything else is a real failure and is left to propagate.
+
+Each line also names the driver that actually ran, because an engine whose package
+is missing does not fail: ``Extractor`` warns and quietly uses pcapkit's own parser
+instead, which would otherwise show up here as a healthy frame count.
+
+"""
+
+import os
import pcapkit
+from _engine_support import ENGINES, ran_as_asked, report, unavailable
+
+for engine in ENGINES:
+ fout = f'../captures/engines/{engine}.txt'
+
+ try:
+ extraction = pcapkit.extract(fin='../captures/in.pcap', fout=fout,
+ format='tree', engine=engine) # type: ignore[arg-type]
+ except Exception as exc: # pylint: disable=broad-except
+ reason = unavailable(exc)
+ if reason is None:
+ raise
+ report(engine, f'skipped -- {reason}')
-default = pcapkit.extract(fin='../captures/in.pcap',
- fout='../captures/engines/default.txt', format='tree', engine='default')
-pyshark = pcapkit.extract(fin='../captures/in.pcap',
- fout='../captures/engines/pyshark.txt', format='tree', engine='pyshark')
-scapy = pcapkit.extract(fin='../captures/in.pcap',
- fout='../captures/engines/scapy.txt', format='tree', engine='scapy')
-dpkt = pcapkit.extract(fin='../captures/in.pcap',
- fout='../captures/engines/dpkt.txt', format='tree', engine='dpkt')
-
-# pipeline = pcapkit.extract(fin='../captures/in.pcap',
-# nofile=True, engine='pipeline')
-# server = pcapkit.extract(fin='../captures/in.pcap', nofile=True, engine='server')
+ # The dump file is opened before the engine runs, so a skipped engine
+ # leaves an empty one behind. Drop it: a 0-byte engines/pyshark.txt next
+ # to a full engines/default.txt reads as "pyshark parsed nothing".
+ if os.path.exists(fout) and os.path.getsize(fout) == 0:
+ os.remove(fout)
+ else:
+ driver, asked = ran_as_asked(engine, extraction)
+ if asked:
+ report(engine, f'{extraction.length} frames via {driver} -> {fout}')
+ else:
+ report(engine, f'its package is not installed -- pcapkit fell back to '
+ f'{driver}; {extraction.length} frames -> {fout}')
diff --git a/examples/legacy_smoke/test_perf.py b/examples/legacy_smoke/test_perf.py
index e81444e50c..ffe6ab42e9 100644
--- a/examples/legacy_smoke/test_perf.py
+++ b/examples/legacy_smoke/test_perf.py
@@ -1,8 +1,37 @@
# -*- coding: utf-8 -*-
+"""Benchmark ``pcapkit.extract`` across engines with pyperf.
-import pyperf
+``pyperf`` is not a pcapkit dependency -- it is a benchmarking harness this one demo
+uses -- so it will not be present in a plain ``pip install pcapkit`` environment.
+When it is missing the demo says how to get it and stops there rather than dying on
+an import traceback.
-from pcapkit import extract
+An engine that is not available on this host is reported as skipped, with the
+reason, and only the engines that work are handed to the benchmark runner: pyperf
+re-runs each benchmark in worker processes dozens of times, so an engine that
+raises would fail the whole run rather than just its own row. See
+:mod:`_engine_support` for what counts as unavailable.
+
+"""
+
+import sys
+
+from _engine_support import ENGINES, preflight, report
+
+try:
+ import pyperf
+except ImportError:
+ print('test_perf: skipped -- pyperf is not installed.\n'
+ '\n'
+ ' This demo needs the pyperf benchmarking harness, which pcapkit does\n'
+ ' not depend on. Install it into the same environment as pcapkit:\n'
+ '\n'
+ ' python -m pip install pyperf\n'
+ '\n'
+ ' For a timing run with no extra dependency, use test_time.py instead.')
+ sys.exit(0)
+
+from pcapkit import extract # noqa: E402 # pylint: disable=wrong-import-position
def default() -> 'None':
@@ -25,8 +54,25 @@ def pyshark() -> 'None':
format='tree', engine='pyshark')
+#: The benchmark for each engine name in :data:`_engine_support.ENGINES`.
+BENCHMARKS = {
+ 'default': default,
+ 'pyshark': pyshark,
+ 'scapy': scapy,
+ 'dpkt': dpkt,
+}
+
runner = pyperf.Runner()
-runner.bench_func('default', default)
-runner.bench_func('scapy', scapy)
-runner.bench_func('dpkt', dpkt)
-runner.bench_func('pyshark', pyshark)
+
+benched = 0
+for engine in ENGINES:
+ reason = preflight(engine, '../captures/in.pcap')
+ if reason is not None:
+ report(engine, f'skipped -- {reason}')
+ continue
+
+ runner.bench_func(engine, BENCHMARKS[engine])
+ benched += 1
+
+if not benched:
+ print('test_perf: nothing to benchmark -- every engine was skipped above.')
diff --git a/examples/legacy_smoke/test_profile.py b/examples/legacy_smoke/test_profile.py
index 7fbcfeff5f..f341d03b32 100644
--- a/examples/legacy_smoke/test_profile.py
+++ b/examples/legacy_smoke/test_profile.py
@@ -1,9 +1,14 @@
# -*- coding: utf-8 -*-
+"""Profile a ``pcapkit.extract`` run and write cProfile stats for ``make profile``."""
import cProfile
+import os
import pcapkit
+#: Where cProfile writes its stats. ``make profile`` renders this into a call graph.
+STATS = os.path.join('temp', 'parse_pcap.pstats')
+
def test() -> 'None':
pcapkit.extract(fin='../captures/http.pcap', store=True,
@@ -11,7 +16,14 @@ def test() -> 'None':
if __name__ == '__main__':
+ # cProfile will not create the directory it dumps into, so `python
+ # test_profile.py` on a fresh checkout used to profile the whole run and then
+ # die with FileNotFoundError. `make profile` does mkdir first; the script
+ # should not need it to.
+ os.makedirs(os.path.dirname(STATS), exist_ok=True)
+
cProfile.run(
'test()',
- 'temp/parse_pcap.pstats',
+ STATS,
)
+ print(f'test_profile: wrote {STATS}')
diff --git a/examples/legacy_smoke/test_stream.py b/examples/legacy_smoke/test_stream.py
index c0b4aab8da..78a00e4565 100644
--- a/examples/legacy_smoke/test_stream.py
+++ b/examples/legacy_smoke/test_stream.py
@@ -1,11 +1,31 @@
# -*- coding: utf-8 -*-
+"""Extract a live capture streamed from ``tcpdump`` on stdin.
+Needs root, since it shells out to ``sudo tcpdump``, so it cannot run unattended.
+Use :file:`test_stream_askpass.py` where ``sudo`` is configured with an askpass
+helper.
+
+"""
+
+import os
import shlex
import subprocess # nosec: B404
+import tempfile
import pcapkit
-with subprocess.Popen(shlex.split('sudo tcpdump -i en0 -s 0 -w - -U'), # nosec: B603
+#: Interface to capture on. ``en0`` is macOS; on Linux this is usually ``eth0``
+#: or ``wlan0`` -- see ``ip link`` or ``tcpdump -D``.
+INTERFACE = 'en0'
+
+# NOTE: buffer_path must not point inside ../captures/. That directory holds generated
+# captures -- ../captures/stream.pcap among them -- which the runtime tests read and
+# pin byte for byte, so buffering a live capture over it would quietly break the
+# test suite. Buffer into a throwaway temporary file instead.
+BUFFER = os.path.join(tempfile.mkdtemp(prefix='pcapkit-stream-'), 'stream.pcap')
+print(f'buffering the live capture to {BUFFER}')
+
+with subprocess.Popen(shlex.split(f'sudo tcpdump -i {INTERFACE} -s 0 -w - -U'), # nosec: B603
stdout=subprocess.PIPE) as file:
pcapkit.extract(fin=file.stdout, fout='../captures/stream.txt', format='tree', no_eof=True,
- verbose=True, buffer_save=True, buffer_path='../captures/stream.pcap')
+ verbose=True, buffer_save=True, buffer_path=BUFFER)
diff --git a/examples/legacy_smoke/test_stream_askpass.py b/examples/legacy_smoke/test_stream_askpass.py
index 2312d4dc1d..f835b239df 100644
--- a/examples/legacy_smoke/test_stream_askpass.py
+++ b/examples/legacy_smoke/test_stream_askpass.py
@@ -1,11 +1,31 @@
# -*- coding: utf-8 -*-
+"""Extract a live capture streamed from ``tcpdump``, with ``sudo -A``.
+Same as :file:`test_stream.py`, but uses ``sudo -A`` so the password comes from the
+``SUDO_ASKPASS`` helper rather than a terminal prompt. Still needs root, so it
+cannot run unattended.
+
+"""
+
+import os
import shlex
import subprocess # nosec: B404
+import tempfile
import pcapkit
-with subprocess.Popen(shlex.split('sudo -A tcpdump -i en0 -s 0 -w - -U'), # nosec: B603
+#: Interface to capture on. ``en0`` is macOS; on Linux this is usually ``eth0``
+#: or ``wlan0`` -- see ``ip link`` or ``tcpdump -D``.
+INTERFACE = 'en0'
+
+# NOTE: buffer_path must not point inside ../captures/. That directory holds generated
+# captures -- ../captures/stream.pcap among them -- which the runtime tests read and
+# pin byte for byte, so buffering a live capture over it would quietly break the
+# test suite. Buffer into a throwaway temporary file instead.
+BUFFER = os.path.join(tempfile.mkdtemp(prefix='pcapkit-stream-'), 'stream.pcap')
+print(f'buffering the live capture to {BUFFER}')
+
+with subprocess.Popen(shlex.split(f'sudo -A tcpdump -i {INTERFACE} -s 0 -w - -U'), # nosec: B603
stdout=subprocess.PIPE) as file:
pcapkit.extract(fin=file.stdout, fout='../captures/stream.txt', format='tree', no_eof=True,
- verbose=True, buffer_save=True, buffer_path='../captures/stream.pcap')
+ verbose=True, buffer_save=True, buffer_path=BUFFER)
diff --git a/examples/legacy_smoke/test_time.py b/examples/legacy_smoke/test_time.py
index 13b94a490f..3a150ca74c 100644
--- a/examples/legacy_smoke/test_time.py
+++ b/examples/legacy_smoke/test_time.py
@@ -1,27 +1,46 @@
# -*- coding: utf-8 -*-
+"""Time ``pcapkit.extract`` on each engine and report milliseconds per packet.
+
+An engine that is not available on this host is reported as skipped, with the
+reason, and the remaining engines are still timed -- see :mod:`_engine_support` for
+what counts as unavailable. Anything else is a real failure and is left to
+propagate.
+
+Note that the engines are tried once each before being timed: a failure halfway
+through a thousand rounds throws the whole measurement away, and an engine this
+host does not have is not a result worth measuring.
+
+"""
import statistics
import time
-import dpkt
-import pyshark
-import scapy.all
-
import pcapkit
+from _engine_support import ENGINES, preflight
from pcapkit.utilities.logging import logger
logger.setLevel('INFO')
-for engine in ['default', 'dpkt', 'scapy', 'pyshark']:
+#: Timed extractions per engine. The first is discarded as a warm-up round.
+ROUNDS = 1_000
+
+for engine in ENGINES:
+ reason = preflight(engine, '../captures/in.pcap')
+ if reason is not None:
+ print(f'Report: [{engine}] skipped -- {reason}')
+ continue
+
print(f'Testing: [{engine}] starting...', end='', flush=True)
- lid = []
- for index in range(0, 1_000):
- now = time.time_ns()
+ lid = [] # type: list[float]
+ for index in range(0, ROUNDS):
+ # NOTE: perf_counter_ns is monotonic; time_ns is wall clock and can step
+ # backwards under an NTP adjustment, which would give a negative delta.
+ now = time.perf_counter_ns()
extraction = pcapkit.extract(fin='../captures/in.pcap', store=False, nofile=True, verbose=False, engine=engine) # type: ignore[arg-type]
- delta = time.time_ns() - now
+ delta = time.perf_counter_ns() - now
# print(f'[{engine}] No. {index:>3d}: {extraction.length} packets extracted in {delta} seconds.')
lid.append(float(delta))