tcpdump mailing list archives
Re: -i man "Ties are broken by choosing the earliest match."
From: Doru Georgescu <headset001 () yahoo com>
Date: Thu, 16 Jul 2009 19:49:27 +0000 (UTC)
No - that section of the manual refers to selecting an interface, not to matching packets when filtering. As far as I can tell, "ties are broken by choosing the earliest match" means "for some reason, we didn't just say that the first interface in the list is used".
Thanks. I knew that, but still I could not understand the statement.
I was able to add a new comment, so they don't appear to be completely disabled. Did you log in? You might want to log in and try again.
Indeed, I was not logged in. I don't know how to apologize.
Given that fixes would only be made in a 1.0.1 or 1.1 release, and that in that release, the problems you have mentioned in the tracker are libpcap bugs, not tcpdump bugs, as the description of libpcap filter expressions is in the pcap-filter man page, you should probably open a new tracker for libpcap, copying to it the stuff you already put in the existing tracker. Then you should open another new tracker against tcpdump, with the comment about the "-i" flag, as that's a problem in the tcpdump man page.
I will try to look into this. Am I supposed to close that 'bug', while allowing further comments? I mean, if you can't close it.
The entire chapter should do so, although it perhaps doesn't do so in a sufficiently rigorous form.
Yes, I can't point exactly the problem, excepting: - the wrong order of the three different kinds of modifiers/qualifiers - the lack of mention that a primitive only operates within one protocol level header - the lack of emphasis on the statement that proto dir type is only a general structure, not a definition of primitives - the lack of emphasis that the list of allowable primitives is actually the definition of primitives - the lack of explanation of when is ip an alias for ether proto \\ip and when it is a modifier. All these are more pedagogical issues rather than clear mistakes, but still, together with the lack of formality in presentation, they create real problems.
That's more up-to-date than the Fedora 11 manual, but - as somebody noted here - it's not completely up-to-date; it's not showing the libpcap 1.0 man pages (plural - I split the pcap man page into a general libpcap man page and a bunch of individual man pages for individual functions, as it was driving me crazy that, if I just wanted to look up one function, I had to do "man pcap" and scroll through it) or the tcpdump 4.0 man page.
So where are the up-to-date man's? Maybe they are not public yet. - This is the tcpdump-workers list. Visit https://cod.sandelman.ca/ to unsubscribe.
Current thread:
- -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Guy Harris (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Guy Harris (Jul 16)
- Re: -i man Doru Georgescu (Jul 21)
- Re: -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Guy Harris (Jul 16)
- <Possible follow-ups>
- -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Guy Harris (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 16)
- Re: -i man "Ties are broken by choosing the earliest match." Doru Georgescu (Jul 18)
- Re: -i man "Ties are broken by choosing the earliest match." Guy Harris (Jul 16)
