Re: [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- FCS length description

Guy Harris <> Tue, 22 December 2020 09:23 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id DA2973A0EB2 for <>; Tue, 22 Dec 2020 01:23:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id psR_h_NzQ7Xx for <>; Tue, 22 Dec 2020 01:23:50 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id D88033A0EAF for <>; Tue, 22 Dec 2020 01:23:50 -0800 (PST)
Received: from [] ( []) (authenticated bits=0) by (8.15.1/8.15.1) with ESMTPSA id 0BM9NnTN015636 (version=TLSv1.2 cipher=DHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Tue, 22 Dec 2020 01:23:49 -0800
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.\))
From: Guy Harris <>
In-Reply-To: <>
Date: Tue, 22 Dec 2020 01:23:48 -0800
Cc:, tcpdump-workers <>
Content-Transfer-Encoding: quoted-printable
Message-Id: <>
References: <12531.1608597102@localhost> <>
To: Pcap-ng file format <>
X-Mailer: Apple Mail (2.3608.
X-Sonic-CAuth: UmFuZG9tSVbA0PfaJn4aS8uzt9jiPCEGfpI20f8Fj6DtBWIvKWfDxxMns7TJRFDCNtb1kZ2HhDWwk0uRb+e1KXJQOKVzPMZJ
X-Sonic-ID: C;PitFZjdE6xGd853Pl+vPsg== M;eph9ZjdE6xGd853Pl+vPsg==
X-Sonic-Spam-Details: 0.0/5.0 by cerberusd
Archived-At: <>
Subject: Re: [OPSAWG] [pcap-ng-format] draft-gharris-opsawg-pcap.txt --- FCS length description
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OPSA Working Group Mail List <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 22 Dec 2020 09:23:52 -0000

On Dec 22, 2020, at 1:01 AM, Guy Harris <> wrote:

> They were originally intended for use with some stuff NetBSD was doing (I'd have to look into the history of the NetBSD code), but I think NetBSD stopped doing that.

The commit message for the change that added the macros was:

commit afbb1ce7227dc5edb291f242ed8d95cd3762fc51
Author: Guy Harris <>
Date:   Sat Sep 29 19:33:29 2007 +0000

    Based on work from Florent Drouin, split the 32-bit link-layer type
    field in a capture file into:
            a 16-bit link-layer type field (it's 16 bits in pcap-NG, and
            that'll probably be enough for the foreseeable future);
            a 10-bit "class" field, indicating the group of link-layer type
            values to which the link-layer type belongs - class 0 is for
            regular DLT_ values, and class 0x224 grandfathers in the NetBSD
            "raw address family" link-layer types;
            a 6-bit "extension" field, storing information about the
            capture, such an indication of whether the packets include an
            FCS and, if so, how many bytes of FCS are present.

So what NetBSD had was a convention where a capture file could have a link-layer type that combined an AF_ value with some additional bits to distinguish the value from a regular LINKTYPE_ value; I don't know what AF_ values they supported for that, or where that code was, or whether it's still supported.