tcpdump mailing list archives

Re: [tcpdump] tcpdump displays a dot('.') for an Ack flag. (#319)


From: Michael Richardson <mcr () sandelman ca>
Date: Mon, 17 Jun 2013 15:41:03 -0400

    pjp> Yesterday while looking through a packet dump, we realised that while
    pjp> showing TCP hand shake, tcpdump(8) displays a dot('.') for an
    pjp> Acknowledgement flag. The tcpdump(8) manual explains this under the

...

    pjp> Why not display letter 'A' for acknowledgement flag? How does this
    pjp> dot('.') help??

In general, we attempt to avoid gratuitous changes in output like this.
We are out of options as well.. It was my intention that things like this
would come with a name change to pktdump.  pktdump would use all the same
code, but have a different main(), which different (saner) options, and
different defaults.

So, a patch to change this, optionally by flag in ndo->ndo_NEWFLAG would be
welcome, but I don't think we are going to change the default.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        | network architect  [
]     mcr () sandelman ca  http://www.sandelman.ca/        |   ruby on rails    [

_______________________________________________
tcpdump-workers mailing list
tcpdump-workers () lists tcpdump org
https://lists.sandelman.ca/mailman/listinfo/tcpdump-workers


Current thread: