[pcap-ng-format] Should we add the "ntartest.c" file and some sample pcapng files from the Wireshark Wiki pcapng page to the repository?

Hadriel Kaplan the.real.hadriel at gmail.com
Tue Aug 25 11:12:24 UTC 2015


On Mon, Aug 24, 2015 at 11:53 PM, Guy Harris <guy at alum.mit.edu> wrote:
>
> ...and taken that dissector and turned it into a standalone verifying tool, for the benefit of those who, for whatever reason - whether we deem it legitimate or not - want a standalone tool rather than having to use Wireshark/TShark as such a tool.

Someone might want to NOT use Wireshark/tshark for *everything*? ...
does not compute ...
:)


> (Yes, I think it would be a good thing to have a verifier that's independent of libpcap's pcapng-reading code, Wireshark's pcapng-reading code, and Wireshark's pcapng-file-dissecting code.  So perhaps adding all the details would be a good thing, *even if it duplicates Michał's efforts*.  Sometimes duplication of effort is a Good Thing, especially when it comes to interoperability in a world where we expect duplicate implementations to exist, and this is such a world - I don't expect every packet sniffer either to use libpcap's code or to use Wireshark's code, especially not third-party commercial products.)

Yup, you're right.

-hadriel


More information about the pcap-ng-format mailing list