tcpdump mailing list archives

Re: What is the main reason in absent append


From: Guy Harris <guy () alum mit edu>
Date: Thu, 16 Feb 2006 12:42:52 -0800


On Feb 16, 2006, at 12:06 PM, Stephen Donnelly wrote:

The biggest problem I imagine is that the resulting file would have only
one header block, so the configuration of the capture for the appended
records would have to be the same as for the original file.

I'm not sure how you could check for or enforce this?

Require read and write access for appending, open for reading and writing, read the header, make sure the link-layer type and snapshot length are the same (and fail if they're not), and then seek to the end and start writing.

-
This is the tcpdump-workers list.
Visit https://lists.sandelman.ca/ to unsubscribe.


Current thread: