On Mar 4, 2013, at 10:24 PM, Ariel Burbaickij <ariel.burbaickij@xxxxxxxxx> wrote:
> I have several captures. One of them is definitely in rf5 format,
...which means it definitely is given the WTAP_ENCAP_ value of WTAP_ENCAP_K12, not WTAP_ENCAP_MTP2.
> another one is definitely in pcap format.
...which means it definitely is *not* given the WTAP_ENCAP_ value of WTAP_ENCAP_K12, although it could be given the WTAP_ENCAP_ value of WTAP_ENCAP_MTP2.
> What I meant is that from looking at supported DLT_TYPEs and then WTAP_ENCAP (sets of supported encapsulations are different) it appeared to me that development of wireshark and tcereplay happens totally independent from each other -- previously I thought/hoped that it happens in more coordinated way.
Nope. That would be like hoping that the development of Wireshark and snoop, or the development of Wireshark and tcpdump, or the development of Wireshark and any *other* libpcap-based application, happened in a more coordinated way.
Wireshark's development deliberately does *not* limit itself to what libpcap can read.