/usr/include/wireshark/epan/follow.h is in libwireshark-dev 1.6.7-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 | /* follow.h
*
* $Id: follow.h 31252 2009-12-13 01:10:55Z sake $
*
* Copyright 1998 Mike Hall <mlh@io.com>
*
* Wireshark - Network traffic analyzer
* By Gerald Combs <gerald@wireshark.org>
* Copyright 1998 Gerald Combs
*
* This program is free software; you can redistribute it and/or
* modify it under the terms of the GNU General Public License
* as published by the Free Software Foundation; either version 2
* of the License, or (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
*
*/
#ifndef __FOLLOW_H__
#define __FOLLOW_H__
#include <epan/packet.h>
#define MAX_IPADDR_LEN 16
/* With MSVC and a libwireshark.dll, we need a special declaration. */
WS_VAR_IMPORT gboolean empty_tcp_stream;
WS_VAR_IMPORT gboolean incomplete_tcp_stream;
typedef struct _tcp_stream_chunk {
guint8 src_addr[MAX_IPADDR_LEN];
guint16 src_port;
guint32 dlen;
} tcp_stream_chunk;
char* build_follow_filter( packet_info * );
void reassemble_tcp( guint32, gulong, gulong, gulong, const char*, gulong,
int, address *, address *, guint, guint );
void reset_tcp_reassembly( void );
typedef struct {
guint8 ip_address[2][MAX_IPADDR_LEN];
guint32 port[2];
unsigned int bytes_written[2];
gboolean is_ipv6;
} follow_stats_t;
void follow_stats(follow_stats_t* stats);
#endif
|