tcpdump mailing list archives

Re: -i man "Ties are broken by choosing the earliest match."


From: Doru Georgescu <headset001 () yahoo com>
Date: Thu, 16 Jul 2009 19:49:27 +0000 (UTC)

No - that section of the manual refers to selecting an interface, not  
to matching packets when filtering.

As far as I can tell, "ties are broken by choosing the earliest match"  
means "for some reason, we didn't just say that the first interface in  
the list is used".


Thanks. I knew that, but still I could not understand the statement. 

I was able to add a new comment, so they don't appear to be completely  
disabled.  Did you log in?  You might want to log in and try again.

Indeed, I was not logged in. I don't know how to apologize. 

Given that fixes would only be made in a 1.0.1 or 1.1 release, and  
that in that release, the problems you have mentioned in the tracker  
are libpcap bugs, not tcpdump bugs, as the description of libpcap  
filter expressions is in the pcap-filter man page, you should probably  
open a new tracker for libpcap, copying to it the stuff you already  
put in the existing tracker.

Then you should open another new tracker against tcpdump, with the  
comment about the "-i" flag, as that's a problem in the tcpdump man  
page.


I will try to look into this. 
Am I supposed to close that 'bug', while allowing further comments? I mean, if
you can't close it. 

The entire chapter should do so, although it perhaps doesn't do so in  
a sufficiently rigorous form.

Yes, I can't point exactly the problem, excepting: 
- the wrong order of the three different kinds of modifiers/qualifiers 
- the lack of mention that a primitive only operates within one protocol level
header 
- the lack of emphasis on the statement that proto dir type is only a general
structure, not a definition of primitives 
- the lack of emphasis that the list of allowable primitives is actually the
definition of primitives 
- the lack of explanation of when is ip an alias for ether proto \\ip and when
it is a modifier. 

All these are more pedagogical issues rather than clear mistakes, but still,
together with the lack of formality in presentation, they create real problems. 

That's more up-to-date than the Fedora 11 manual, but - as somebody  
noted here - it's not completely up-to-date; it's not showing the  
libpcap 1.0 man pages (plural - I split the pcap man page into a  
general libpcap man page and a bunch of individual man pages for  
individual functions, as it was driving me crazy that, if I just  
wanted to look up one function, I had to do "man pcap" and scroll  
through it) or the tcpdump 4.0 man page.


So where are the up-to-date man's? Maybe they are not public yet. 



-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: