More Sysdig / system event support.
authorGerald Combs <gerald@zing.org>
Sun, 24 Apr 2016 18:21:50 +0000 (11:21 -0700)
committerAnders Broman <a.broman58@gmail.com>
Wed, 15 Jun 2016 13:39:29 +0000 (13:39 +0000)
commitd25a60c1c1db0d81e332272fe00ec4ef4fb03e65
tree0a90169d7ffa2fcff67c95328328998bb654f580
parentb26e757b310180bd2ab867dd5ad0cc0261993135
More Sysdig / system event support.

Add REC_TYPE_SYSCALL to wiretap and use it for Sysdig events. Call the
Sysdig event dissector from the frame dissector. Create a "syscall"
protocol for system calls, but add "frame" items to it for now.

Add the ability to write Sysdig events. This lets us merge packet
capture and syscall capture files.

Change-Id: I12774ec69c89d8e329b6130c67f29aade4e3d778
Reviewed-on: https://code.wireshark.org/review/15078
Tested-by: Petri Dish Buildbot <buildbot-no-reply@wireshark.org>
Reviewed-by: Anders Broman <a.broman58@gmail.com>
epan/dissectors/packet-frame.c
epan/dissectors/packet-sysdig-event.c
epan/packet.c
wiretap/merge.c
wiretap/pcapng.c
wiretap/wtap.h