ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
April 17th, 2024 | 14:30-16:00 SGT (UTC+8) | Online

Wireshark-dev: Re: [Wireshark-dev] [Wireshark-commits] rev 30076: /trunk/ /trunk/tools/: fuzz-t

From: Joerg Mayer <jmayer@xxxxxxxxx>
Date: Wed, 23 Sep 2009 06:13:14 +0200
On Tue, Sep 22, 2009 at 07:28:01PM +0000, krj@xxxxxxxxxxxxx wrote:
> http://anonsvn.wireshark.org/viewvc/viewvc.cgi?view=rev&revision=30076
> 
> User: krj
> Date: 2009/09/22 12:28 PM
> 
> Log:
>  Add initial support for "two pass analysis" in tshark. This allows tshark to arrive at the same protocol tree as the Wireshark GUI. Before this change tshark only supported a single scan over the file. This effectively means that packets cannot use data that are gathered from frames that appear after the current frame. By scanning twice we give the dissector the opportunity to make forward references.

How about making -P a numbered option like -P1 and -P2 and then add
a -P1 option to wireshark as well, making things similar with both
executables?

Ciao
     Joerg
-- 
Joerg Mayer                                           <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.