Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: Re: [Wireshark-dev] Adding support for pcap-ng to dumpcap or reading from pipes

From: Richard Sharpe <realrichardsharpe@xxxxxxxxx>
Date: Sat, 12 May 2012 12:56:58 -0700
On Sat, May 12, 2012 at 12:43 PM, Jakub Zawadzki
<darkjames-ws@xxxxxxxxxxxx> wrote:
> Hi,
>
> On Mon, May 07, 2012 at 08:24:10AM -0700, Richard Sharpe wrote:
>> I am looking at adding support for pcap-ng to dumpcap.c so it can be
>> read directly from pipes.
>
> I have question :)
>
> Do we really need to "capture" from pipes in dumpcap?
> Wiretap already support reading pcap-ng, and many other file formats.
> It doesn't support reading from pipes, but implementing it in dumpcap
> just because of it looks like workaround for me.

There are some differences in reading from pipes ... in particular,
the state machine is somewhat interesting.

> So is it *really* needed feature or just workaroud for wiretap?
>
> If workaround, wouldn't be better to add support for pipes in wiretap?

If it can be done, sure ... meanwhile, since I think I know what to
do, I will continue with my efforts :-)

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)