Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-bugs: [Wireshark-bugs] [Bug 3096] Ability to annotate packet captures

Date: Tue, 14 Feb 2012 10:54:06 -0800 (PST)
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3096

--- Comment #49 from Guy Harris <guy@xxxxxxxxxxxx> 2012-02-14 10:54:04 PST ---
(In reply to comment #48)
> (In reply to comment #46)
> > so it explicitly speaks of multiple IDBs.  (Arguably, "dumpcap -i any -w
> > file.pcapng" should write IDBs for the real interfaces rather than the "any"
> > interface, but that's a bit more work; what's really wanted there is some help
> > from libpcap.)
> I think dumpcap -i any -w file.pcapng should only use a single IDB specifying
> the any interface (only on Linux, of course). Since this is what the user
> specifies

What the user specified is "capture on all interfaces", not "capture on the
'any' interface"; there is no network interface named "any".

Think of it as being like "ls *".  "ls *" doesn't just print "*", it prints the
names of all files it matches; similarly users might want - and at least some
*do* want, as expressed by messages to tcpdump-workers and libpcap/tcpdump bugs
- to know which particular real interface packets came in on.

-- 
Configure bugmail: https://bugs.wireshark.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are watching all bug changes.