This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi, I was reading packet-udp.c and I encountered the following code that I do not understand

capture_dissector_handle_t udp_cap_handle;

dissector_add_uint("ip.proto", IP_PROTO_UDP, udp_handle);
dissector_add_uint("ip.proto", IP_PROTO_UDPLITE, udplite_handle);

udp_cap_handle = create_capture_dissector_handle(capture_udp, hfi_udp->id);
capture_dissector_add_uint("ip.proto", IP_PROTO_UDP, udp_cap_handle);
udp_cap_handle = create_capture_dissector_handle(capture_udp, hfi_udplite->id);
capture_dissector_add_uint("ip.proto", IP_PROTO_UDPLITE, udp_cap_handle);

The dissector_add_uint, as I understand, register the udp dissector in the sub-dissector table ip.proto However, I fail to understand what the capture_dissector_add_uint does. I read no information about "capture dissector" in README.dissector, and capture_dissector.h did not answer the question either.

Is it creating udp's own sub-dissector table? if so, why is "ip.proto" in the argument field?

Could someone clear things up for me? Thank you very much!

Nick

asked 13 Jul, 17:57

nickzhang's gravatar image

nickzhang
1638
accept rate: 0%


This is part of a feature in the the GTK (so called legacy) interface which has not (yet?) been implemented in the Qt interface. While doing a capture you can choose to have the packet list updated in real time or not, and you can choose to have a capture info dialog presented or not. To update the capture info dialog the incoming packets need to be dissected at a very high level. This is performed by these so called capture dissectors. Through this dialog you can see that the packet types which you expect are coming in, while not burdening the capture platform with detailed packet dissection, which may prove too time consuming for the rate of incoming packets.

permanent link

answered 14 Jul, 09:53

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

edited 16 Jul, 08:51

sindy's gravatar image

sindy
6.0k4850

Thank you, this answers my question clearly.

(15 Jul, 19:34) nickzhang

These came in via change 12607. It appears their purpose is lightweight dissection for statistics purposes (look at the packet-ethertype.c capture dissector for an example).

permanent link

answered 14 Jul, 06:58

JeffMorriss's gravatar image

JeffMorriss ♦
6.2k572
accept rate: 27%

Thank you for the helpful information.

(15 Jul, 19:35) nickzhang
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×19
×3

question asked: 13 Jul, 17:57

question was seen: 264 times

last updated: 16 Jul, 08:51

p​o​w​e​r​e​d by O​S​Q​A