pcapFileBe(): Coder<PcapFile<PcapGlobalHeader, PcapRecord>>
Creates a coder for a complete pcap capture file fixed to big-endian byte
order. Exactly pcapFile("be"), spelled so it can be called with no
arguments.
This is the one thing pcapFile() cannot do. Sniffing already covers reading
a big-endian capture, but encoding has no file to inspect and always writes
PCAP_DEFAULT_ENDIANNESS, so producing a big-endian capture needs a
coder that says so up front.
The building blocks pcapGlobalHeader and pcapRecord have no
such variants on purpose — you compose those in TypeScript, where passing
"be" costs nothing.
Encode a capture in big-endian byte order
Encode a capture in big-endian byte order
import { assertEquals } from "@std/assert"; import { detectPcapMagic, LINKTYPE, PCAP_MAGIC_MICROS, pcapFileBe, } from "@binstruct/pcap"; const coder = pcapFileBe(); const capture = { header: { magic: PCAP_MAGIC_MICROS, versionMajor: 2, versionMinor: 4, thisZone: 0, sigFigs: 0, snapLen: 65535, network: LINKTYPE.ETHERNET, }, records: [{ tsSec: 1_700_000_000, tsUsec: 250_000, inclLen: 4, origLen: 1500, data: new Uint8Array([0xde, 0xad, 0xbe, 0xef]), }], }; const buffer = new Uint8Array(64); const written = coder.encode(capture, buffer); const [decoded, read] = coder.decode(buffer.subarray(0, written)); assertEquals(written, 24 + 16 + 4); assertEquals(read, written); assertEquals(decoded, capture); assertEquals( buffer.subarray(0, 4), new Uint8Array([0xa1, 0xb2, 0xc3, 0xd4]), ); assertEquals(detectPcapMagic(buffer), { endianness: "be", nanos: false });
A big-endian capture reads back through the sniffing coder
A big-endian capture reads back through the sniffing coder
import { assertEquals } from "@std/assert"; import { LINKTYPE, PCAP_MAGIC_NANOS, pcapFile, pcapFileBe, } from "@binstruct/pcap"; const capture = { header: { magic: PCAP_MAGIC_NANOS, versionMajor: 2, versionMinor: 4, thisZone: 0, sigFigs: 0, snapLen: 1500, network: LINKTYPE.RAW, }, records: [], }; const buffer = new Uint8Array(24); const written = pcapFileBe().encode(capture, buffer); const [decoded] = pcapFile().decode(buffer.subarray(0, written)); assertEquals(decoded, capture);
Coder<PcapFile<PcapGlobalHeader, PcapRecord>>
A coder for a PcapFile of PcapGlobalHeader and PcapRecord, fixed to big-endian.