Skip to content

pcap 记录头 (Packet Record Header) ​

📦 pcap 文件中每个包前的 16 字节记录头。

结构 ​

每个包前 16 字节记录头,struct.pack('=IIII', ...)(本地端序):

偏移字段类型含义
0ts_secuint32时间戳秒
4ts_usecuint32时间戳微秒
8incl_lenuint32实际写入长度
12orig_lenuint32原始长度

r0capture 的填充 ​

python
ts_sec = int(time.time())
ts_usec = int((time.time() - ts_sec) * 1000000)
incl_len = orig_len = len(IP头 + TCP头 + 载荷)
  • ts_sec/ts_usec:当前时间(Python time.time()),用于 Wireshark 时间列
  • incl_len:实际写了几字节包数据(= IPv4头 + TCP头 + 明文载荷)
  • orig_len:原始长度,r0capture 设等于 incl_len(不截断)

时间戳 ​

时间戳在主机端 on_message 处理时打,反映"r0capture 收到这批明文"的时刻,而非 App 实际收发的精确时刻(有微小延迟)。

与全局头的关系 ​

[全局头 24B][记录头16B][包数据][记录头16B][包数据]...

全局头一次,记录头每包一次。

相关文档 ​

基于 VitePress 构建 · 教学用途