[prev in list] [next in list] [prev in thread] [next in thread] 

List:       wireshark-dev
Subject:    Re: [Wireshark-dev] Unregistered expert info!
From:       Pascal Quantin <pascal.quantin () gmail ! com>
Date:       2014-12-16 10:40:44
Message-ID: CAGka-80u6ChxgeXUW2o5Abp3CX5iUsrvUUUbRf42OiYibJr_2Q () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


2014-12-16 11:33 GMT+01:00 Vishnu Bhatt <vishnu.bhatt@aricent.com>:
>
>  TFTP is not the protocol which is mentioned after the crash, sometime
> SCTP, sometimes TCP, sometimes LTP etc. I haven't introduce any changes in
> them.
>
>
>
> I've registered expert info in my dissector. Do I need to add something
> else in any other file to register expert info?
>

It means that your dissector is not registering the experts info properly
and is corrupting the expert info tale. Ensure that you provide all the
relevant parameters in the ei_register_info[] array by comparing your code
with another official dissector registering expert info.


>
>
> *From:* wireshark-dev-bounces@wireshark.org [mailto:
> wireshark-dev-bounces@wireshark.org] *On Behalf Of *Pascal Quantin
> *Sent:* Tuesday, December 16, 2014 3:24 PM
>
> *To:* Developer support list for Wireshark
> *Subject:* Re: [Wireshark-dev] Unregistered expert info!
>
>
>
>
>
>
>
> 2014-12-16 10:42 GMT+01:00 Vishnu Bhatt <vishnu.bhatt@aricent.com>:
>
> Version 1.12.2. Actually I took the source code of 1.12.2 and added a few
> dissectors of mine. But the error which I am getting is not in any of those
> files. Even if I disable those dissectors, still I get this error.
>
>
>
> The TFTP dissector contains a single expert info that seems to be
> registered properly. It's quite likely that the crash comes from your own
> modifications. To confirm this, remove them completely (including any
> plugins you might have installed in your personal folder) and verify that
> it runs fine. Then reintroduce your changes one at a time and check the
> behavior.
>
> Pascal.
>
>
>
> *From:* wireshark-dev-bounces@wireshark.org [mailto:
> wireshark-dev-bounces@wireshark.org] *On Behalf Of *Alexis La Goutte
> *Sent:* Tuesday, December 16, 2014 3:08 PM
> *To:* Developer support list for Wireshark
> *Subject:* Re: [Wireshark-dev] Unregistered expert info!
>
>
>
>
>
>
>
> On Tue, Dec 16, 2014 at 10:18 AM, Vishnu Bhatt <vishnu.bhatt@aricent.com>
> wrote:
>
> Hello,
>
>
>
> While loading a capture file, it crashes immediately and I am getting the
> following error:
>
>
>
> Warn Dissector bug, protocol TFTP, in packet 72: expert.c:394: failed
> assertion "(guint)expindex->ei < gpa_expertinfo.len" (Unregistered expert
> info!)
>
> Unhandled exception ("expert.c:414: failed assertion "(guint)expindex->ei
> < gpa_expertinfo.len" (Unregistered expert info!)", group=1, code=5)
>
>
>
> Somebody please help on this one as no file is getting opened and same
> error I am getting every time I open a file.
>
> Hi,
>
>
> What release of Wireshark is used ?
>
> do you have try the last stable ?
>
> If you have always the issue, please create a bug in bugtracker (
> https://bugs.wireshark.org ) and attach your pcap.
>
> Regards,
>
>
>
>
>
>
>
> Thanks
>
> "DISCLAIMER: This message is proprietary to Aricent and is intended solely
> for the use of the individual to whom it is addressed. It may contain
> privileged or confidential information and should not be circulated or used
> for any purpose other than for what it is intended. If you have received
> this message in error, please notify the originator immediately. If you are
> not the intended recipient, you are notified that you are strictly
> prohibited from using, copying, altering, or disclosing the contents of
> this message. Aricent accepts no responsibility for loss or damage arising
> from the use of the information transmitted by this email including damage
> from virus."
>
>
> ___________________________________________________________________________
> Sent via:    Wireshark-dev mailing list <wireshark-dev@wireshark.org>
> Archives:    http://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
>              mailto:wireshark-dev-request@wireshark.org
> ?subject=unsubscribe
>
>      "DISCLAIMER: This message is proprietary to Aricent and is intended
> solely for the use of the individual to whom it is addressed. It may
> contain privileged or confidential information and should not be circulated
> or used for any purpose other than for what it is intended. If you have
> received this message in error, please notify the originator immediately.
> If you are not the intended recipient, you are notified that you are
> strictly prohibited from using, copying, altering, or disclosing the
> contents of this message. Aricent accepts no responsibility for loss or
> damage arising from the use of the information transmitted by this email
> including damage from virus."
>
>
> ___________________________________________________________________________
> Sent via:    Wireshark-dev mailing list <wireshark-dev@wireshark.org>
> Archives:    http://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
>              mailto:wireshark-dev-request@wireshark.org
> ?subject=unsubscribe
>
>   "DISCLAIMER: This message is proprietary to Aricent and is intended
> solely for the use of the individual to whom it is addressed. It may
> contain privileged or confidential information and should not be circulated
> or used for any purpose other than for what it is intended. If you have
> received this message in error, please notify the originator immediately.
> If you are not the intended recipient, you are notified that you are
> strictly prohibited from using, copying, altering, or disclosing the
> contents of this message. Aricent accepts no responsibility for loss or
> damage arising from the use of the information transmitted by this email
> including damage from virus."
>
> ___________________________________________________________________________
> Sent via:    Wireshark-dev mailing list <wireshark-dev@wireshark.org>
> Archives:    http://www.wireshark.org/lists/wireshark-dev
> Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
>              mailto:wireshark-dev-request@wireshark.org
> ?subject=unsubscribe
>

[Attachment #5 (text/html)]

<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">2014-12-16 \
11:33 GMT+01:00 Vishnu Bhatt <span dir="ltr">&lt;<a \
href="mailto:vishnu.bhatt@aricent.com" \
target="_blank">vishnu.bhatt@aricent.com</a>&gt;</span>:<blockquote \
class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid \
rgb(204,204,204);padding-left:1ex">





<div link="blue" vlink="purple" lang="EN-US">
<div>
<p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)">TFTP \
is not the protocol which is mentioned after the crash, sometime SCTP, sometimes TCP, \
sometimes LTP etc. I haven't introduce any changes in them.<u></u><u></u></span></p> \
<p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)"><u></u> \
<u></u></span></p> <p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)">I've \
registered expert info in my dissector. Do I need to add something else in any other \
file to register expert \
info?</span></p></div></div></blockquote><div><br></div><div>It means that your \
dissector is not registering the experts info properly and is corrupting the expert \
info tale. Ensure that you provide all the relevant parameters in the \
ei_register_info[] array by comparing your code with another official dissector \
registering expert info.<br>  <br></div><blockquote class="gmail_quote" \
style="margin:0px 0px 0px 0.8ex;border-left:1px solid \
rgb(204,204,204);padding-left:1ex"><div link="blue" vlink="purple" \
lang="EN-US"><div><p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)"><u></u><u></u></span></p>
 <p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)"><u></u> \
<u></u></span></p> <div style="border-width:1pt medium medium;border-style:solid none \
none;border-color:rgb(181,196,223) -moz-use-text-color \
-moz-use-text-color;padding:3pt 0in 0in"> <p class="MsoNormal"><b><span \
style="font-size:10pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span \
style="font-size:10pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> <a \
href="mailto:wireshark-dev-bounces@wireshark.org" \
target="_blank">wireshark-dev-bounces@wireshark.org</a> [mailto:<a \
href="mailto:wireshark-dev-bounces@wireshark.org" \
target="_blank">wireshark-dev-bounces@wireshark.org</a>] <b>On Behalf Of </b>Pascal \
Quantin<br> <b>Sent:</b> Tuesday, December 16, 2014 3:24 PM</span></p><div><div \
class="h5"><br> <b>To:</b> Developer support list for Wireshark<br>
<b>Subject:</b> Re: [Wireshark-dev] Unregistered expert \
info!<u></u><u></u></div></div><p></p> </div><div><div class="h5">
<p class="MsoNormal"><u></u>  <u></u></p>
<div>
<p class="MsoNormal"><u></u>  <u></u></p>
<div>
<p class="MsoNormal"><u></u>  <u></u></p>
<div>
<p class="MsoNormal">2014-12-16 10:42 GMT+01:00 Vishnu Bhatt &lt;<a \
href="mailto:vishnu.bhatt@aricent.com" \
target="_blank">vishnu.bhatt@aricent.com</a>&gt;:<u></u><u></u></p> <div>
<div>
<p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)">Version \
1.12.2. Actually I took the source code of 1.12.2 and added a few dissectors of mine. \
But  the error which I am getting is not in any of those files. Even if I disable \
those dissectors, still I get this error.</span><u></u><u></u></p> </div>
</div>
<div>
<p class="MsoNormal"><u></u>  <u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12pt">The TFTP dissector contains a single \
expert info that seems to be registered properly. It&#39;s quite likely that the \
crash comes from your own modifications. To confirm this, remove them completely \
(including any  plugins you might have installed in your personal folder) and verify \
that it runs fine. Then reintroduce your changes one at a time and check the \
behavior.<br> <br>
Pascal.<u></u><u></u></p>
</div>
<blockquote style="border-width:medium medium medium 1pt;border-style:none none none \
solid;border-color:-moz-use-text-color -moz-use-text-color -moz-use-text-color \
rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in"> <div>
<div>
<p class="MsoNormal"><span \
style="font-size:11pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:rgb(31,73,125)"> \
</span><u></u><u></u></p> <div style="border-width:1pt medium \
medium;border-style:solid none none;border-color:rgb(181,196,223) -moz-use-text-color \
-moz-use-text-color;padding:3pt 0in 0in"> <p class="MsoNormal"><b><span \
style="font-size:10pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span \
style="font-size:10pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> <a \
href="mailto:wireshark-dev-bounces@wireshark.org" \
target="_blank">wireshark-dev-bounces@wireshark.org</a> [mailto:<a \
href="mailto:wireshark-dev-bounces@wireshark.org" \
target="_blank">wireshark-dev-bounces@wireshark.org</a>] <b>On Behalf Of </b>Alexis \
La Goutte<br> <b>Sent:</b> Tuesday, December 16, 2014 3:08 PM<br>
<b>To:</b> Developer support list for Wireshark<br>
<b>Subject:</b> Re: [Wireshark-dev] Unregistered expert \
info!</span><u></u><u></u></p> </div>
<div>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
<div>
<div>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
<div>
<p class="MsoNormal">On Tue, Dec 16, 2014 at 10:18 AM, Vishnu Bhatt &lt;<a \
href="mailto:vishnu.bhatt@aricent.com" \
target="_blank">vishnu.bhatt@aricent.com</a>&gt; wrote:<u></u><u></u></p> <div>
<div>
<p class="MsoNormal">Hello,<u></u><u></u></p>
<p class="MsoNormal">  <u></u><u></u></p>
<p class="MsoNormal">While loading a capture file, it crashes immediately and I am \
getting the following error:<u></u><u></u></p> <p class="MsoNormal">  \
<u></u><u></u></p> <p class="MsoNormal">Warn Dissector bug, protocol TFTP, in packet \
72: expert.c:394: failed assertion &quot;(guint)expindex-&gt;ei &lt; \
gpa_expertinfo.len&quot; (Unregistered expert info!)<u></u><u></u></p> <p \
class="MsoNormal">Unhandled exception (&quot;expert.c:414: failed assertion \
&quot;(guint)expindex-&gt;ei &lt; gpa_expertinfo.len&quot; (Unregistered expert \
info!)&quot;, group=1, code=5)<u></u><u></u></p> <p class="MsoNormal">  \
<u></u><u></u></p> <p class="MsoNormal">Somebody please help on this one as no file \
is getting opened and same error I am getting every time I open a \
file.<u></u><u></u></p> </div>
</div>
<div>
<p class="MsoNormal">Hi,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><br>
What release of Wireshark is used ?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12pt">do you have try the last stable \
?<u></u><u></u></p> </div>
<div>
<p class="MsoNormal">If you have always the issue, please create a bug in bugtracker \
( <a href="https://bugs.wireshark.org" target="_blank">https://bugs.wireshark.org</a> \
) and attach your pcap.<br> <br>
Regards,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
</div>
<blockquote style="border-width:medium medium medium 1pt;border-style:none none none \
solid;border-color:-moz-use-text-color -moz-use-text-color -moz-use-text-color \
rgb(204,204,204);padding:0in 0in 0in 6pt;margin:5pt 0in 5pt 4.8pt"> <div>
<div>
<p class="MsoNormal">  <u></u><u></u></p>
<p class="MsoNormal">Thanks<u></u><u></u></p>
</div>
<p class="MsoNormal">&quot;DISCLAIMER: This message is proprietary to Aricent and is \
intended solely for the use of the individual to whom it is addressed. It may contain \
privileged or confidential information  and should not be circulated or used for any \
purpose other than for what it is intended. If you have received this message in \
error, please notify the originator immediately. If you are not the intended \
recipient, you are notified that you are strictly prohibited  from using, copying, \
altering, or disclosing the contents of this message. Aricent accepts no \
responsibility for loss or damage arising from the use of the information transmitted \
by this email including damage from virus.&quot; <u></u><u></u></p>
</div>
<p class="MsoNormal"><br>
___________________________________________________________________________<br>
Sent via:      Wireshark-dev mailing list &lt;<a \
href="mailto:wireshark-dev@wireshark.org" \
                target="_blank">wireshark-dev@wireshark.org</a>&gt;<br>
Archives:      <a href="http://www.wireshark.org/lists/wireshark-dev" \
target="_blank"> http://www.wireshark.org/lists/wireshark-dev</a><br>
Unsubscribe: <a href="https://wireshark.org/mailman/options/wireshark-dev" \
target="_blank"> https://wireshark.org/mailman/options/wireshark-dev</a><br>
                    mailto:<a href="mailto:wireshark-dev-request@wireshark.org" \
target="_blank">wireshark-dev-request@wireshark.org</a>?subject=unsubscribe<u></u><u></u></p>
 </blockquote>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal">&quot;DISCLAIMER: This message is proprietary to Aricent and is \
intended solely for the use of the individual to whom it is addressed. It may contain \
privileged or confidential information and should not be circulated or used for any \
purpose  other than for what it is intended. If you have received this message in \
error, please notify the originator immediately. If you are not the intended \
recipient, you are notified that you are strictly prohibited from using, copying, \
altering, or disclosing  the contents of this message. Aricent accepts no \
responsibility for loss or damage arising from the use of the information transmitted \
by this email including damage from virus.&quot; <u></u><u></u></p>
</div>
</div>
</div>
<p class="MsoNormal"><br>
___________________________________________________________________________<br>
Sent via:      Wireshark-dev mailing list &lt;<a \
href="mailto:wireshark-dev@wireshark.org" \
                target="_blank">wireshark-dev@wireshark.org</a>&gt;<br>
Archives:      <a href="http://www.wireshark.org/lists/wireshark-dev" \
target="_blank"> http://www.wireshark.org/lists/wireshark-dev</a><br>
Unsubscribe: <a href="https://wireshark.org/mailman/options/wireshark-dev" \
target="_blank"> https://wireshark.org/mailman/options/wireshark-dev</a><br>
                    mailto:<a href="mailto:wireshark-dev-request@wireshark.org" \
target="_blank">wireshark-dev-request@wireshark.org</a>?subject=unsubscribe<u></u><u></u></p>
 </blockquote>
</div>
</div>
</div>
</div></div></div><div><div class="h5">
&quot;DISCLAIMER: This message is proprietary to Aricent and is intended solely for \
the use of the individual to whom it is addressed. It may contain privileged or \
confidential information and should not be circulated or used for any purpose other \
than for what  it is intended. If you have received this message in error, please \
notify the originator immediately. If you are not the intended recipient, you are \
notified that you are strictly prohibited from using, copying, altering, or \
disclosing the contents of this  message. Aricent accepts no responsibility for loss \
or damage arising from the use of the information transmitted by this email including \
damage from virus.&quot; </div></div></div>

<br>___________________________________________________________________________<br>
Sent via:      Wireshark-dev mailing list &lt;<a \
                href="mailto:wireshark-dev@wireshark.org">wireshark-dev@wireshark.org</a>&gt;<br>
                
Archives:      <a href="http://www.wireshark.org/lists/wireshark-dev" \
                target="_blank">http://www.wireshark.org/lists/wireshark-dev</a><br>
Unsubscribe: <a href="https://wireshark.org/mailman/options/wireshark-dev" \
target="_blank">https://wireshark.org/mailman/options/wireshark-dev</a><br>  \
mailto:<a href="mailto:wireshark-dev-request@wireshark.org">wireshark-dev-request@wireshark.org</a>?subject=unsubscribe<br></blockquote></div></div></div>




___________________________________________________________________________
Sent via:    Wireshark-dev mailing list <wireshark-dev@wireshark.org>
Archives:    http://www.wireshark.org/lists/wireshark-dev
Unsubscribe: https://wireshark.org/mailman/options/wireshark-dev
             mailto:wireshark-dev-request@wireshark.org?subject=unsubscribe

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic