Red Hat Bugzilla – Bug 219041
Newest packet missing with real time updates
Last modified: 2007-12-21 05:07:09 EST
Description of problem:
When the list of packets is updated in real time, the newest packet does not
Version-Release number of selected component (if applicable):
Happens every time.
Steps to Reproduce:
1. Start wireshark
2. Click capture options
3. Specify filter "port 53"
4. Chose "Update list of packets in real time"
5. Click start
6. Do a DNS query from another program
7. Do another DNS query
The other program reports the result immediately, but wireshark only shows the
query, not the result. When the second query is send wireshark shows the first
response and the second query, but the second respons is sent.
The packet shows up in the wireshark window when it is received.
When I stop the capture, the packet shows up.
Is this bug already reported upstream?
I have not reported it upstream. I haven't even verified which versions are
affected. Though I think I would have noticed if the problem existed in ethereal
Can you please test this bug with the latest rawhide wireshark-0.99.5? I believe
this issue is fixed.
0.99.4-1.fc5 is the newest wireshark for FC5. And for some reason the problem
has gotten worse since I reported this problem. Now I don't see any incomming
packets at all, only outgoing packets are shown. But it is the same wireshark
version as back then, so there has to be another reason for that change, maybe
the kernel has something to say, I'm currently using 2.6.18-1.2257.fc5 and when
I reported the problem I think I was using kernel-2.6.18-1.2239.fc5.
This bug is known by upstream and according to this thread
not easily solvable.
I can reproduce the problem with wireshark-0.99.5-1.fc5 as well.
According to upstream bug this is fixed in the newest release.