Wireshark mailing list archives

pcapng decoding error when preamble is shortened


From: Timmy Brolin <tib () hms se>
Date: Tue, 9 Feb 2021 10:21:39 +0000

Hi,

It seems Wireshark fails to decode captured packets with shortened preamble?

Normally Ethernet packets have a preamble and SFD like this:
55555555555555D5
But during transmission over Ethernet, sometimes the preamble arrives slightly shorter at the receiving end. Some 
bytes, or even half a byte(!), at the start of the preamble can go missing for various technical reasons.
This is considered normal, and all Ethernet MACs are required to properly decode packets with shortened preamble, as 
well as packets where the preamble is a non-integer number of bytes.

But it seems Wireshark does not?


Decoding failure when preamble is shortened:
[cid:image002.png@01D6FED5.BB3DFFA0]


Normal preamble, decoding successful:
[cid:image003.png@01D6FED5.BB3DFFA0]


I have attached a pcapng file with these two packets.


Timmy Brolin
M.SC. Computer Systems Engineering

HMS Industrial Networks AB
Stationsgatan 37, Box 4126
300 04 Halmstad, Sweden

Email: tib () hms se<mailto:tib () hms se>
Direct: +46 35 17 29 32

[cid:image001.png@01D6FED3.ADC71BB0]
HALMSTAD | BARCELONA | BEIJING | BOSTON | BUCHEN | CHICAGO | COVENTRY | DUBAI | HEDEL | IGUALADA |
KARLSRUHE | MILAN | MULHOUSE | NIVELLES | PUNE | RAVENSBURG | SEOUL | SINGAPORE | TOKYO | WETZLAR

www.hms-networks.com

Attachment: shortened_preamble.pcapng
Description: shortened_preamble.pcapng

___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request () wireshark org?subject=unsubscribe

Current thread: