On Tue, Sep 22, 2009 at 07:28:01PM +0000, krj@xxxxxxxxxxxxx wrote:
> http://anonsvn.wireshark.org/viewvc/viewvc.cgi?view=rev&revision=30076
>
> User: krj
> Date: 2009/09/22 12:28 PM
>
> Log:
> Add initial support for "two pass analysis" in tshark. This allows tshark to arrive at the same protocol tree as the Wireshark GUI. Before this change tshark only supported a single scan over the file. This effectively means that packets cannot use data that are gathered from frames that appear after the current frame. By scanning twice we give the dissector the opportunity to make forward references.
How about making -P a numbered option like -P1 and -P2 and then add
a -P1 option to wireshark as well, making things similar with both
executables?
Ciao
Joerg
--
Joerg Mayer <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.