Comment # 3
on bug 9838
from Guy Harris
(In reply to comment #2)
> @Guy, thank you for the quick response.
> I understand the restrictions you describe at the kernel level, but I agree
> that since WireShark knows what the compiled BPF is, it should at lest offer
> to run it as a userland "post-Capture" filter.
It would have to know that the problem is that the filter can't be run in the
kernel in order to do that.
That functionality belongs in libpcap/WinPcap, so that it works for *all*
programs using them, not just Wireshark.
You are receiving this mail because:
- You are watching all bug changes.