Wireshark-bugs: [Wireshark-bugs] [Bug 7376] New: Expert Info (Warn/Undecoded): Unknown AVP 872 (
Date: Sat, 16 Jun 2012 17:07:40 -0700 (PDT)

           Summary: Expert Info (Warn/Undecoded): Unknown AVP 872
           Product: Wireshark
           Version: 1.8.0
          Platform: x86
        OS/Version: Windows 7
            Status: NEW
          Severity: Major
          Priority: Low
         Component: Wireshark
        AssignedTo: [email protected]
        ReportedBy: [email protected]

Created attachment 8615
  --> https://bugs.wireshark.org/bugzilla/attachment.cgi?id=8615
diameter tcpdump file

Build Information:
Version 1.8.0rc1 (SVN Rev 43134 from /trunk-1.8)

Copyright 1998-2012 Gerald Combs and contributors.
This is free software; see the source for copying conditions.

Compiled (32-bit) with GTK+ 2.24.10, with Cairo 1.10.2, with Pango 1.30.0, with
GLib 2.32.2, with WinPcap (4_1_2), with libz 1.2.5, without POSIX capabilities,
with SMI 0.4.8, with c-ares 1.7.1, with Lua 5.1, without Python, with GnuTLS
2.12.18, with Gcrypt 1.4.6, with MIT Kerberos, with GeoIP, with PortAudio
V19-devel (built Jun  6 2012), with AirPcap.

Running on 32-bit Windows 7, build 7600, with WinPcap version 4.0.2 (packet.dll
version, based on libpcap version 0.9.5, GnuTLS 2.12.18, Gcrypt
1.4.6, without AirPcap.

Built using Microsoft Visual C++ 10.0 build 40219

Wireshark is Open Source Software released under the GNU General Public License.

Check the man page and http://www.wireshark.org for more information.
By some reason AVP 872 is not recognized by Wireshark (actually I see the same
issue for some others AVP, but I think root cause is the same)

AVP: Unknown(872) l=12 f=--- val=00000003
AVP Code: 872 Unknown
Unknown AVP, if you know what this is you can add it to dictionary.xml
Expert Info (Warn/Undecoded): Unknown AVP 872 (vendor=Reserved)
Message: Unknown AVP 872 (vendor=Reserved)
Severity level: Warn
Group: Undecoded

even this AVP already presents in dictionary.xml:
        <avp name="Reporting-Reason" code="872" mandatory="must"
may-encrypt="no" protected="mustnot" vendor-bit="must" vendor-id="TGPP">
            <type type-name="Enumerated"/>
            <enum name="THRESHOLD" code="0"/>
            <enum name="QHT" code="1"/>
            <enum name="FINAL" code="2"/>
            <enum name="QUOTA_EXHAUSTED" code="3"/>
            <enum name="VALIDITY_TIME" code="4"/>
            <enum name="OTHER_QUOTA_TYPE" code="5"/>
            <enum name="RATING_CONDITION_CHANGE" code="6"/>
            <enum name="FORCED_REAUTHORISATION" code="7"/>
            <enum name="POOL_EXHAUSTED" code="8"/>

Pls advise what can be the reason and how to fix it.
I tested Wireshark 1.6.8 and 1.8rc1

