Wireshark-dev: Re: [Wireshark-dev] Regarding wireshark design
From: Richard Sharpe <[email protected]>
Date: Thu, 10 May 2012 04:37:47 -0700
On Thu, May 10, 2012 at 4:28 AM, Singh, Anand <[email protected]> wrote:
> Hi,
>                Can you please let me know how does it talk with raw packets. Is it using existing
> TCP stack or is it directly communication with lower level drivers like phy/Mac layer. &
> Where do I find that code section where we accessing raw buffers.

Sigh. It is all in the documentation.

If we are capturing off the wire, then I believe that it uses
dumpcap.c and does not talk to packet sockets or anything like that.
It actually links to libpcap.

Richard Sharpe