Re: [Wireshark-dev] tpdu_data missing in gtp packet

2020-12-26 Thread Ranjeet kumar singh
Thanks,
It worked after setting "Dissect T-PDU as None" GTP preference.
Though in previous versions it worked with default settings.

Regards
Ranjeet S

On Fri, Dec 25, 2020 at 2:56 PM Pascal Quantin  wrote:
>
> Hi,
>
> Le ven. 25 déc. 2020 à 06:02, Ranjeet kumar singh  a 
> écrit :
>>
>> it is present in 3.25 and missing in 3.4.2.
>>
>> Please see attached images. in one this field is present and in other
>> it's missing.
>>
>> I have not made any setting changes. Just installed released wireshark
>> and opened a captured file with gtp packet.
>
>
> I cannot reproduce your issue: by setting the "Dissect T-PDU as None" GTP 
> preference, I do get the T-PDU data payload displayed with 3.4.2. If I let 
> the default value (TPDU Heuristic) it properly identifies the payload as IP.
> So it could be related to your GTP-U PDU where the heuristic fails for 
> example. Please check the behavior if you sendure to set the preference to 
> None and share the packet if it still fails.
>
> Best regards.
>
>>
>>
>> Regards
>> Ranjeet S
>>
>> On Thu, Dec 24, 2020 at 1:46 PM Dario Lombardo  wrote:
>> >
>> > Can you please tell a version in which is present and a version in which 
>> > is not?
>> >
>> > On Thu, Dec 24, 2020 at 8:54 AM Ranjeet kumar singh  
>> > wrote:
>> >>
>> >> Hi
>> >>
>> >> Gtp packets used to have a tpdu_data field.
>> >>
>> >> I don't see it in the latest wireshark.
>> >>
>> >> This is causing my lua plugins to break.
>> >>
>> >> Can someone please fix it.
>> >>
>> >> Regards
>> >> Ranjeet S
>> >> ___
>> >> Sent via:Wireshark-dev mailing list 
>> >> Archives:https://www.wireshark.org/lists/wireshark-dev
>> >> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >>  
>> >> mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> >
>> >
>> >
>> > --
>> >
>> > Naima is online.
>> >
>> > ___
>> > Sent via:Wireshark-dev mailing list 
>> > Archives:https://www.wireshark.org/lists/wireshark-dev
>> > Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> ___
>> Sent via:Wireshark-dev mailing list 
>> Archives:https://www.wireshark.org/lists/wireshark-dev
>> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>
> ___
> Sent via:Wireshark-dev mailing list 
> Archives:https://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

Re: [Wireshark-dev] tpdu_data missing in gtp packet

2020-12-24 Thread Ranjeet kumar singh
it is present in 3.25 and missing in 3.4.2.

Please see attached images. in one this field is present and in other
it's missing.

I have not made any setting changes. Just installed released wireshark
and opened a captured file with gtp packet.

Regards
Ranjeet S

On Thu, Dec 24, 2020 at 1:46 PM Dario Lombardo  wrote:
>
> Can you please tell a version in which is present and a version in which is 
> not?
>
> On Thu, Dec 24, 2020 at 8:54 AM Ranjeet kumar singh  
> wrote:
>>
>> Hi
>>
>> Gtp packets used to have a tpdu_data field.
>>
>> I don't see it in the latest wireshark.
>>
>> This is causing my lua plugins to break.
>>
>> Can someone please fix it.
>>
>> Regards
>> Ranjeet S
>> ___
>> Sent via:Wireshark-dev mailing list 
>> Archives:https://www.wireshark.org/lists/wireshark-dev
>> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>
>
>
> --
>
> Naima is online.
>
> ___
> Sent via:Wireshark-dev mailing list 
> Archives:https://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

[Wireshark-dev] tpdu_data missing in gtp packet

2020-12-23 Thread Ranjeet kumar singh
Hi

Gtp packets used to have a tpdu_data field.

I don't see it in the latest wireshark.

This is causing my lua plugins to break.

Can someone please fix it.

Regards
Ranjeet S
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

[Wireshark-dev] pfcp seid decode error

2020-09-12 Thread Ranjeet kumar singh
Hi

Seeing "IE wrongly encoded" error while decoding F-SEID in a pfcp
session establishment response.

Please see attached screenshot and pcap.

Please let me know if it is a bug.

Regards
Ranjeet S


seidbug.pcapng
Description: Binary data
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

Re: [Wireshark-dev] pfcp ctag decode bug

2020-09-12 Thread Ranjeet kumar singh
I tested Wireshark-win64-3.3.0rc0-2029-g272502790bf1.msi.
It's working fine.

Thanks a lot.

Regards
Ranjeet S



On Sat, Sep 12, 2020 at 10:25 PM Pascal Quantin  wrote:
>
> Hi Ranjeet,
>
> Le sam. 12 sept. 2020 à 18:45, Ranjeet kumar singh  a 
> écrit :
>>
>> PFA wireshark file.
>
>
> Thanks. The current MR gives the following decoding:
> C-TAG :
> IE Type: C-TAG (134)
> IE Length: 3
> Flags: 0x04, VID
>  0... = Spare: 0
>  .1.. = VID: True
>  ..0. = DEI: False
>  ...0 = PCP: False
>   1100 1000 = C-VID: 0x00c8
>  0... = Drop eligible indicator (DEI): Ineligible
>  .000 = Priority code point (PCP): Best Effort (default), Drop 
> Eligible (0)
>
> Best regards,
> Pascal.
>
>>
>> Regards
>> Ranjeet S
>>
>> On Sat, Sep 12, 2020 at 9:31 PM Pascal Quantin  wrote:
>> >
>> > Hi Ranjeet,
>> >
>> > Le sam. 12 sept. 2020 à 17:58, Ranjeet kumar singh  
>> > a écrit :
>> >>
>> >> Hi Pascal
>> >>
>> >> Please find the attached image that shows the byte dump of the c-tag IE.
>> >
>> >
>> > Please provide a full packet if you want the bug to be fixed. Thanks for 
>> > your understanding.
>> >
>> >>
>> >> Regards
>> >> Ranjeet Singh
>> >>
>> >> On Sat, Sep 12, 2020 at 9:08 PM Pascal Quantin  
>> >> wrote:
>> >> >
>> >> > Hi Ranjeet,
>> >> >
>> >> > Le sam. 12 sept. 2020 à 10:16, Pascal Quantin  a 
>> >> > écrit :
>> >> >>
>> >> >> Le sam. 12 sept. 2020 à 04:40, Guy Harris  a écrit :
>> >> >>>
>> >> >>> On Sep 11, 2020, at 7:04 PM, Ranjeet kumar singh 
>> >> >>>  wrote:
>> >> >>>
>> >> >>> > I am seeing following error
>> >> >>> >
>> >> >>> > [Dissector bug, protocol PFCP:
>> >> >>> > C:\buildbot\builders\wireshark-3.2-64\windows-2019-x64\build\epan\proto.c:11594:
>> >> >>> > field pfcp.c_tag.dei_flag is not of type FT_CHAR or an FT_{U}INTn
>> >> >>> > type]
>> >> >>> >
>> >> >>> > with a pfcp session establishment request.
>> >> >>> >
>> >> >>> > Can someone please confirm if it is a bug.
>> >> >>>
>> >> >>> Yes, Wireshark confirmed it, by saying "Dissector bug".  That's what 
>> >> >>> the "bug" in "Dissector bug" means.
>> >> >>>
>> >> >>> The right place to report Wireshark bugs is
>> >> >>>
>> >> >>> https://gitlab.com/wireshark/wireshark/-/issues
>> >> >>
>> >> >>
>> >> >> See https://gitlab.com/wireshark/wireshark/-/merge_requests/227
>> >> >>
>> >> >> I still have a doubt regarding the C-VID / S-VID encoding. See the MR 
>> >> >> comment for more details.
>> >> >
>> >> >
>> >> > it would be great if you could share a pcap containing a packet with a 
>> >> > C-TAG or S-TAG IE so as to verify the fix.
>> >> >
>> >> > Thanks,
>> >> > Pascal.
>> >> > ___
>> >> > Sent via:Wireshark-dev mailing list 
>> >> > Archives:https://www.wireshark.org/lists/wireshark-dev
>> >> > Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >> >  
>> >> > mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> >> ___
>> >> Sent via:Wireshark-dev mailing list 
>> >> Archives:https://www.wireshark.org/lists/wireshark-dev
>> >> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >>  
>> >> mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> >
>> > ___
>> > Sent via:Wireshark-dev mailing list 
>> > Archives:https://www.wireshark.org/lists/wireshark-dev
>> > Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> ___
>> Sent via:Wireshark-dev mailing list 
>> Archives:https://www.wireshark.org/lists/wireshark-dev
>> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>
> ___
> Sent via:Wireshark-dev mailing list 
> Archives:https://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

Re: [Wireshark-dev] pfcp ctag decode bug

2020-09-12 Thread Ranjeet kumar singh
PFA wireshark file.

Regards
Ranjeet S

On Sat, Sep 12, 2020 at 9:31 PM Pascal Quantin  wrote:
>
> Hi Ranjeet,
>
> Le sam. 12 sept. 2020 à 17:58, Ranjeet kumar singh  a 
> écrit :
>>
>> Hi Pascal
>>
>> Please find the attached image that shows the byte dump of the c-tag IE.
>
>
> Please provide a full packet if you want the bug to be fixed. Thanks for your 
> understanding.
>
>>
>> Regards
>> Ranjeet Singh
>>
>> On Sat, Sep 12, 2020 at 9:08 PM Pascal Quantin  wrote:
>> >
>> > Hi Ranjeet,
>> >
>> > Le sam. 12 sept. 2020 à 10:16, Pascal Quantin  a 
>> > écrit :
>> >>
>> >> Le sam. 12 sept. 2020 à 04:40, Guy Harris  a écrit :
>> >>>
>> >>> On Sep 11, 2020, at 7:04 PM, Ranjeet kumar singh  
>> >>> wrote:
>> >>>
>> >>> > I am seeing following error
>> >>> >
>> >>> > [Dissector bug, protocol PFCP:
>> >>> > C:\buildbot\builders\wireshark-3.2-64\windows-2019-x64\build\epan\proto.c:11594:
>> >>> > field pfcp.c_tag.dei_flag is not of type FT_CHAR or an FT_{U}INTn
>> >>> > type]
>> >>> >
>> >>> > with a pfcp session establishment request.
>> >>> >
>> >>> > Can someone please confirm if it is a bug.
>> >>>
>> >>> Yes, Wireshark confirmed it, by saying "Dissector bug".  That's what the 
>> >>> "bug" in "Dissector bug" means.
>> >>>
>> >>> The right place to report Wireshark bugs is
>> >>>
>> >>> https://gitlab.com/wireshark/wireshark/-/issues
>> >>
>> >>
>> >> See https://gitlab.com/wireshark/wireshark/-/merge_requests/227
>> >>
>> >> I still have a doubt regarding the C-VID / S-VID encoding. See the MR 
>> >> comment for more details.
>> >
>> >
>> > it would be great if you could share a pcap containing a packet with a 
>> > C-TAG or S-TAG IE so as to verify the fix.
>> >
>> > Thanks,
>> > Pascal.
>> > ___
>> > Sent via:Wireshark-dev mailing list 
>> > Archives:https://www.wireshark.org/lists/wireshark-dev
>> > Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>> >  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>> ___
>> Sent via:Wireshark-dev mailing list 
>> Archives:https://www.wireshark.org/lists/wireshark-dev
>> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
>
> ___
> Sent via:Wireshark-dev mailing list 
> Archives:https://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe


pfcpbug.pcap
Description: Binary data
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

Re: [Wireshark-dev] pfcp ctag decode bug

2020-09-12 Thread Ranjeet kumar singh
Hi Pascal

Please find the attached image that shows the byte dump of the c-tag IE.

Regards
Ranjeet Singh

On Sat, Sep 12, 2020 at 9:08 PM Pascal Quantin  wrote:
>
> Hi Ranjeet,
>
> Le sam. 12 sept. 2020 à 10:16, Pascal Quantin  a écrit :
>>
>> Le sam. 12 sept. 2020 à 04:40, Guy Harris  a écrit :
>>>
>>> On Sep 11, 2020, at 7:04 PM, Ranjeet kumar singh  
>>> wrote:
>>>
>>> > I am seeing following error
>>> >
>>> > [Dissector bug, protocol PFCP:
>>> > C:\buildbot\builders\wireshark-3.2-64\windows-2019-x64\build\epan\proto.c:11594:
>>> > field pfcp.c_tag.dei_flag is not of type FT_CHAR or an FT_{U}INTn
>>> > type]
>>> >
>>> > with a pfcp session establishment request.
>>> >
>>> > Can someone please confirm if it is a bug.
>>>
>>> Yes, Wireshark confirmed it, by saying "Dissector bug".  That's what the 
>>> "bug" in "Dissector bug" means.
>>>
>>> The right place to report Wireshark bugs is
>>>
>>> https://gitlab.com/wireshark/wireshark/-/issues
>>
>>
>> See https://gitlab.com/wireshark/wireshark/-/merge_requests/227
>>
>> I still have a doubt regarding the C-VID / S-VID encoding. See the MR 
>> comment for more details.
>
>
> it would be great if you could share a pcap containing a packet with a C-TAG 
> or S-TAG IE so as to verify the fix.
>
> Thanks,
> Pascal.
> ___
> Sent via:Wireshark-dev mailing list 
> Archives:https://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
>  mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe

[Wireshark-dev] pfcp ctag decode bug

2020-09-11 Thread Ranjeet kumar singh
Hi

I am seeing following error

[Dissector bug, protocol PFCP:
C:\buildbot\builders\wireshark-3.2-64\windows-2019-x64\build\epan\proto.c:11594:
field pfcp.c_tag.dei_flag is not of type FT_CHAR or an FT_{U}INTn
type]

with a pfcp session establishment request.

Can someone please confirm if it is a bug.

Regards
Ranjeet S
___
Sent via:Wireshark-dev mailing list 
Archives:https://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-dev
 mailto:wireshark-dev-requ...@wireshark.org?subject=unsubscribe