pcapFileLe(): Coder<PcapFile<PcapGlobalHeader, PcapRecord>>
Creates a coder for a complete pcap capture file fixed to little-endian byte
order. Exactly pcapFile("le"), spelled so it can be called with no
arguments.
Unlike pcapFile(), this coder never sniffs: it reads and writes the
little-endian layout whatever the buffer holds. Prefer pcapFile() for
reading, since it follows the file's own magic. Reach for this one when the
byte order must be pinned and the call site cannot pass an argument.
The building blocks pcapGlobalHeader and pcapRecord have no
such variants on purpose — you compose those in TypeScript, where passing
"le" costs nothing.
Encode a capture in little-endian byte order
Encode a capture in little-endian byte order
import { assertEquals } from "@std/assert"; import { detectPcapMagic, LINKTYPE, PCAP_MAGIC_MICROS, pcapFileLe, } from "@binstruct/pcap"; const coder = pcapFileLe(); const capture = { header: { magic: PCAP_MAGIC_MICROS, versionMajor: 2, versionMinor: 4, thisZone: 0, sigFigs: 0, snapLen: 65535, network: LINKTYPE.ETHERNET, }, records: [{ tsSec: 1_700_000_000, tsUsec: 250_000, inclLen: 4, origLen: 1500, data: new Uint8Array([0xde, 0xad, 0xbe, 0xef]), }], }; const buffer = new Uint8Array(64); const written = coder.encode(capture, buffer); const [decoded, read] = coder.decode(buffer.subarray(0, written)); assertEquals(written, 24 + 16 + 4); assertEquals(read, written); assertEquals(decoded, capture); assertEquals( buffer.subarray(0, 4), new Uint8Array([0xd4, 0xc3, 0xb2, 0xa1]), ); assertEquals(detectPcapMagic(buffer), { endianness: "le", nanos: false });
Coder<PcapFile<PcapGlobalHeader, PcapRecord>>
A coder for a PcapFile of PcapGlobalHeader and PcapRecord, fixed to little-endian.