ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 4625] New: tshark (or wireshark) stops capture

Date: Sun, 28 Mar 2010 19:57:05 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4625

           Summary: tshark (or wireshark) stops capture
           Product: Wireshark
           Version: 1.2.6
          Platform: x86-64
        OS/Version: Gentoo
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: wireshark-bugs@xxxxxxxxxxxxx
        ReportedBy: vladimir.a.vasilenko@xxxxxxxxx


Build Information:
TShark 1.2.6

Copyright 1998-2010 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

here gentoo build USE flags:
[I] net-analyzer/wireshark
     Available versions:  (~)0.99.7-r1[1] 1.2.6 {adns ares +caps gcrypt geoip
gnutls gtk ipv6 kerberos lua +pcap pcre portaudio profile selinux smi snmp ssl
threads zlib}                                              
     Installed versions:  1.2.6(08:50:43 29.03.2010)(adns ares caps gcrypt
geoip gnutls gtk ipv6 kerberos lua pcap pcre portaudio profile smi threads zlib
-selinux)                                                    
     Homepage:            http://www.wireshark.org/
     Description:         A network protocol analyzer formerly known as
ethereal

Compiled with GLib 2.23.5, with libpcap 1.0.1_pre20090812, with libz 1.2.4,
with
POSIX capabilities (Linux), with libpcre 8.0, with SMI 0.4.8, with c-ares
1.7.0,
with Lua 5.1, with GnuTLS 2.8.6, with Gcrypt 1.4.5, with MIT Kerberos, with
GeoIP.

Running on Linux 2.6.33-gentoo, with libpcap version 1.0.1_pre20090812, GnuTLS
2.8.6, Gcrypt 1.4.5.

Built using gcc 4.3.3.

--
When I start tshark either wireshark it capture FEW packets and then stops.
Here below is the output:
"tshark -i eth0
Capturing on eth0
  0.000000 3Com_9a:95:3a -> Broadcast    ARP Who has 10.53.0.152?  Tell
10.53.0.151
  0.072694 Cisco_78:e5:d8 -> Broadcast    ARP Who has 10.53.3.53?  Tell
10.53.3.203
  0.085098 00001100.001a4b1eb82f -> 00001100.ffffffffffff IPX SAP General
Response
  0.176934 Micro-St_d7:62:c1 -> Broadcast    ARP Who has 10.53.0.1?  Tell
10.53.0.129
  0.299884 Vmware_5c:5c:a4 -> Broadcast    LLC U, func=UI; DSAP NULL LSAP
Individual, SSAP NULL LSAP Command
5 packets captured"

I've tried use development version 1.3.3 and received the same results.
Re-compilation of libpcap and wireshark did not solve the problem.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.