function detectPcapMagic
detectPcapMagic(buffer: Uint8Array): PcapMagicInfo | null

Inspects the first four bytes of a buffer to identify the pcap magic.

Returns the decoded PcapMagicInfo, or null if the bytes do not match any of the four known pcap magic values. Useful when the caller receives an arbitrary buffer and needs to pick the correct pcapGlobalHeader factory before decoding.

Examples

Detect a little-endian microsecond capture

import { assertEquals } from "@std/assert";
import { detectPcapMagic } from "@binstruct/pcap";

const buffer = new Uint8Array([0xd4, 0xc3, 0xb2, 0xa1]);
assertEquals(detectPcapMagic(buffer), { endianness: "le", nanos: false });

Detect a big-endian nanosecond capture

import { assertEquals } from "@std/assert";
import { detectPcapMagic } from "@binstruct/pcap";

const buffer = new Uint8Array([0xa1, 0xb2, 0x3c, 0x4d]);
assertEquals(detectPcapMagic(buffer), { endianness: "be", nanos: true });

Unknown bytes return null

import { assertEquals } from "@std/assert";
import { detectPcapMagic } from "@binstruct/pcap";

assertEquals(detectPcapMagic(new Uint8Array([0, 0, 0, 0])), null);

Parameters

buffer: Uint8Array

Buffer whose first four bytes hold the magic number.

Return Type

Endianness and timestamp resolution implied by the magic, or null if no recognised magic is present.