Wireshark-users: Re: [Wireshark-users] Wireshark 1.8.1 Duplicate protocol name "Coseventcomm Diss

From: "YJZ" <vollkommen@xxxxxxx>
Date: Thu, 26 Jul 2012 21:22:59 +0200
-------- Original-Nachricht --------
> Am 25.07.2012 21:39, schrieb YJZ:
>  > After installing Wireshark 1.8.1 for "OS X 10.6 and later Intel 
> 64-bit" last night, tshark coredumps with:
>  >
>  > Duplicate protocol name "Coseventcomm Dissector Using GIOP API"! This 
> might be caused by an inappropriate plugin or a development error.
>  >
>  > The only plugin I have installed is cloudshark 1.0.1-162, in 
> ~/.wireshark/plugins/. Removing that doesn't make any difference.
> 
> Have you checked _all_ plug-in directories?
> 
> 

Of course, a "find / -name plugins" followed by a trip inside /Applications/Wireshark.app application bundle. The only two locations found were:

/Applications/Wireshark.app/Contents/Resources/lib/wireshark/plugins
~/.wireshark/plugins

There's no "plugins" in /usr/.

/usr/local/bin/tshark (a symlink to ./wireshark) apparently expects the wireshark binary to be located at /Applications/Wireshark.app.

Anyhow, now that problem has been resolved, even though it's still not clear where exactly the duplicates were.