ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-bugs: [Wireshark-bugs] [Bug 4503] ERF file starting with record with timestamp=0, 1 or

Date: Mon, 5 Apr 2010 17:21:05 -0700 (PDT)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4503

Guy Harris <guy@xxxxxxxxxxxx> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |FIXED

--- Comment #2 from Guy Harris <guy@xxxxxxxxxxxx> 2010-04-05 17:20:55 PDT ---
The pcap-ng bug is probably the source of the crash with timestamps of 1 and 2.

The problem with a timestamp of 0 is probably that the heuristics for
recognizing Bluetooth captures from Apple's PacketLogger are too weak; that was
fixed by a change in the main branch, but that change wasn't propagated to the
1.2.x branch.  I've marked that for propagation as well.

Currently, the main branch correctly handles the files, and the two fixes have
been put on the list to propagate to the 1.2.x branch, so I'm marking this as
fixed.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.