Debian Bug report logs - #617344
wireshark: "follow TCP stream" doesn't indicate truncated data

version graph

Package: wireshark; Maintainer for wireshark is Balint Reczey <[email protected]>; Source for wireshark is src:wireshark (PTS, buildd, popcon).

Reported by: "Ph. Marek" <[email protected]>

Date: Tue, 8 Mar 2011 09:51:01 UTC

Severity: wishlist

Tags: moreinfo

Found in version wireshark/1.4.4-1

Full log


Message #10 received at [email protected] (full text, mbox, reply):

Received: (at 617344-quiet) by bugs.debian.org; 8 Mar 2011 10:35:39 +0000
From [email protected] Tue Mar 08 10:35:39 2011
X-Spam-Checker-Version: SpamAssassin 3.2.5-bugs.debian.org_2005_01_02
	(2008-06-10) on busoni.debian.org
X-Spam-Level: 
X-Spam-Bayes: score:0.0000 Tokens: new, 13; hammy, 134; neutral, 51; spammy,
	1. spammytokens:0.919-+--limited hammytokens:0.000-+--H*UA:1.13.5,
	0.000-+--H*u:1.13.5, 0.000-+--H*UA:4.4.5, 0.000-+--H*u:4.4.5,
	0.000-+--H*i:sk:2011030
X-Spam-Status: No, score=-7.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER
	autolearn=ham version=3.2.5-bugs.debian.org_2005_01_02
Return-path: <[email protected]>
Received: from mail09.linbit.com ([212.69.161.110])
	by busoni.debian.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)
	(Exim 4.69)
	(envelope-from <[email protected]>)
	id 1PwuGR-0007DL-7r
	for [email protected]; Tue, 08 Mar 2011 10:35:39 +0000
Received: from cacao.localnet (unknown [10.9.9.57])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by mail09.linbit.com (LINBIT Mail Daemon) with ESMTPSA id 00B0510571C9
	for <[email protected]>; Tue,  8 Mar 2011 11:29:51 +0100 (CET)
From: Philipp Marek <[email protected]>
Organization: Linbit HA GmbH
To: [email protected]
Subject: Re: Bug#617344: wireshark: "follow TCP stream" doesn't indicate truncated data
Date: Tue, 8 Mar 2011 11:29:48 +0100
User-Agent: KMail/1.13.5 (Linux/2.6.34-1-amd64; KDE/4.4.5; x86_64; ; )
References: <[email protected]>
In-Reply-To: <[email protected]>
MIME-Version: 1.0
Content-Type: Text/Plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id: <[email protected]>
X-Greylist: delayed 342 seconds by postgrey-1.31 at busoni; Tue, 08 Mar 2011 10:35:39 UTC
On Tuesday 08 March 2011, Ph. Marek wrote:
> When using a limited capture length "Follow TCP stream" shows no
> indicator that there's data missing.
> Not even the "Save to File" in hexdump gives holes in the addresses.
> 
> I'd expect some visually marked hint "<data missing>" or something like
> that, in both packet loss and truncated captures.
Correction: It *does* show truncations (at least sometimes - I've surely had 
data missing and didn't see the indicator).



> The hexdump should at least show correct addresses for the data - holes
> in the dump would be unavoidable anyway.
The indicator in the hexdump is a string like this:

 [2169 bytes missing in capture file]

This has neither the correct length (even more so if only a few bytes are 
missing!!), and the addresses are still wrong.

The "Flow Graph" shows no missing data, though??



> Another, smaller nuisance are the empty lines in hexdump output.
This is still true.




Send a report that this bug log contains spam.


Debian bug tracking system administrator <[email protected]>. Last modified: Tue May 13 17:39:02 2025; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.