Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 4465] ERF AAL2 preference

Date: Thu, 4 Feb 2010 18:35:14 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=4465

--- Comment #4 from Guy Harris <guy@xxxxxxxxxxxx> 2010-02-04 18:35:10 PST ---
> I would be happy with that, Anders preferred to consider it a preference of the ERF dissector I think?

In bug 4447 he said

    As the preference conserns erf files I would vote for packet-erf.c.

but the preference actually isn't specific to ERF captures - it potentially
applies to all capture file types that can contain AAL2 traffic.  He might have
thought it was ERF-related because bug 4447 talked about ERF captures.

> If this preference was moved to the atm dissector, we should perhaps change the description to "Decode unknown AAL2 as": Raw or UMTS FP for now.

Yes.

> Should 'Decode as' preferences override 'known' packets, or only apply to 'unknown' packets?

I'd say "only apply to 'unknown' packets".  "Known" packets should come from
capture files where the Wiretap code indicates (either explicitly, based on
packet metadata in the capture file, or implicitly, because, for example, the
capture hardware/software in question is only used to capture a particular type
of ATM traffic) that the traffic is of a particular  type.  If there are any
cases where Wiretap indicates a particular traffic type but that traffic
*isn't* always of that particular type, we should fix the Wiretap module to
leave it as "unknown".

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.