ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] FT_BYTES hf with len==0

From: Guy Harris <guy@xxxxxxxxxxxx>
Date: Mon, 16 Dec 2013 12:13:39 -0800
On Dec 16, 2013, at 8:48 AM, Martin Kaiser <lists@xxxxxxxxx> wrote:

> The idea would be to allow filtering for this element although it has no
> value (it's just there).

Do you mean "this is a byte array field that has a length that can range from 0 to {some maximum value}", so that the field might have some value in some packets, or do you mean "I just want to add a flag to a packet, carrying one bit's worth of information by its presence or absence"?

In the latter case, a (computed) FT_NONE or FT_BOOLEAN field would be more appropriate than an FT_BYTES field.

(Or perhaps what you really want is an expert info item.)