Wireshark-bugs: [Wireshark-bugs] [Bug 11886] New: Capture filter applied on Capture Options page

Date: Tue, 15 Dec 2015 02:14:07 +0000
Bug ID 11886
Summary Capture filter applied on Capture Options page cannot be cleared
Product Wireshark
Version unspecified
Hardware x86-64
OS Windows 7
Status UNCONFIRMED
Severity Major
Priority Low
Component GTK+ UI
Assignee [email protected]
Reporter [email protected]

Build Information:
Version 2.0.0 (v2.0.0-0-g9a73b82 from master-2.0)

Copyright 1998-2015 Gerald Combs <[email protected]> and contributors.
License GPLv2+: GNU GPL version 2 or later
<http://www.gnu.org/licenses/old-licenses/gpl-2.0.html>
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

Compiled (64-bit) with Qt 5.3.2, with WinPcap (4_1_3), with libz 1.2.8, with
GLib 2.42.0, with SMI 0.4.8, with c-ares 1.9.1, with Lua 5.2, with GnuTLS
3.2.15, with Gcrypt 1.6.2, with MIT Kerberos, with GeoIP, with QtMultimedia,
with AirPcap.

Running on 64-bit Windows 7 Service Pack 1, build 7601, with locale C, with
WinPcap version 4.1.3 (packet.dll version 4.1.0.2980), based on libpcap version
1.0 branch 1_0_rel0b (20091008), with GnuTLS 3.2.15, with Gcrypt 1.6.2, without
AirPcap.
Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz (with SSE4.2), with 16300MB of physical
memory.

Built using Microsoft Visual C++ 12.0 build 31101
--
When a capture filter has been applied to an interface on the Capture Options
page, the capture filter will be in effect later for that interface when
capture is started from the Capture Options page, even if the capture filter
text is deleted from the "Capture filter for selected interfaces:" input box.

TO REPRODUCE:

Start a continuous ping from a command prompt.

Go to the Capture Options page, select an interface, enter "icmp" in the
capture filter input box, and click "Start." You will see only the ICMP
packets, and "(icmp)" will be in the title bar.

Stop the capture, go back to the Capture Options page, delete "icmp" from the
capture filter input box, and click "Start." You will still see "(icmp)" in the
Title Bar and will still see only the ICMP packets.

Shut down Wireshark and restart. Go to the Capture Options page, select the
same interface, make sure no capture filter is entered in the capture filter
input box, and click "Start." You will still see "(icmp)" in the Title Bar and
will still see only the ICMP packets.

This only applies when capturing is started from the Capture Options page, not
when it is started from the main Wireshark screen. The stuck capture filter can
be replaced with a different one, but not cleared by deleting the text. It is
sometimes possible to clear the capture filter by going to Capture Options,
selecting the interface, deleting the capture filter text, entering a space,
and then backspacing and deleting the space.


You are receiving this mail because:
  • You are watching all bug changes.