function pcapRecord
pcapRecord(endianness?: PcapEndianness): Coder<PcapRecord>

Creates a coder for a single pcap record (16-byte header plus payload).

The payload length is taken from the inclLen field via a forward reference, so records of any captured size round-trip correctly.

A record carries no magic of its own, so its byte order cannot be recovered from the record bytes — it is dictated entirely by the global header that precedes it. When the argument is omitted the coder assumes PCAP_DEFAULT_ENDIANNESS; pass the endianness explicitly whenever the surrounding file might be big-endian.

Examples

Round-trip a single record

import { assertEquals } from "@std/assert";
import { pcapRecord } from "@binstruct/pcap";

const record = pcapRecord("le");
const value = {
  tsSec: 1_700_000_000,
  tsUsec: 123_456,
  inclLen: 4,
  origLen: 4,
  data: new Uint8Array([0xde, 0xad, 0xbe, 0xef]),
};

const buffer = new Uint8Array(64);
const written = record.encode(value, buffer);
const [decoded, read] = record.decode(buffer);

assertEquals(written, 20);
assertEquals(read, 20);
assertEquals(decoded.tsSec, value.tsSec);
assertEquals(decoded.data, value.data);

Truncated capture where inclLen is less than origLen

import { assertEquals } from "@std/assert";
import { pcapRecord } from "@binstruct/pcap";

const record = pcapRecord("be");
const value = {
  tsSec: 1,
  tsUsec: 0,
  inclLen: 2,
  origLen: 1500,
  data: new Uint8Array([0x01, 0x02]),
};

const buffer = new Uint8Array(32);
const written = record.encode(value, buffer);
const [decoded] = record.decode(buffer);

assertEquals(written, 18);
assertEquals(decoded.inclLen, 2);
assertEquals(decoded.origLen, 1500);
assertEquals(decoded.data.length, 2);

Omitting the argument round-trips using the default byte order

import { assertEquals } from "@std/assert";
import { PCAP_DEFAULT_ENDIANNESS, pcapRecord } from "@binstruct/pcap";

const value = {
  tsSec: 1_700_000_000,
  tsUsec: 123_456,
  inclLen: 3,
  origLen: 3,
  data: new Uint8Array([0x01, 0x02, 0x03]),
};

const implicit = new Uint8Array(32);
const explicit = new Uint8Array(32);
const written = pcapRecord().encode(value, implicit);
pcapRecord(PCAP_DEFAULT_ENDIANNESS).encode(value, explicit);

const [decoded, read] = pcapRecord().decode(implicit);

assertEquals(implicit, explicit);
assertEquals(written, 19);
assertEquals(read, 19);
assertEquals(decoded, value);

Parameters

optional
endianness: PcapEndianness = PCAP_DEFAULT_ENDIANNESS

Byte order matching the surrounding pcap file. Defaults to PCAP_DEFAULT_ENDIANNESS.

Return Type

Coder<PcapRecord>

A coder that encodes/decodes a PcapRecord.