pcap 记录头 (Packet Record Header)
📦 pcap 文件中每个包前的 16 字节记录头。
结构
每个包前 16 字节记录头,struct.pack('=IIII', ...)(本地端序):
| 偏移 | 字段 | 类型 | 含义 |
|---|---|---|---|
| 0 | ts_sec | uint32 | 时间戳秒 |
| 4 | ts_usec | uint32 | 时间戳微秒 |
| 8 | incl_len | uint32 | 实际写入长度 |
| 12 | orig_len | uint32 | 原始长度 |
r0capture 的填充
python
ts_sec = int(time.time())
ts_usec = int((time.time() - ts_sec) * 1000000)
incl_len = orig_len = len(IP头 + TCP头 + 载荷)ts_sec/ts_usec:当前时间(Pythontime.time()),用于 Wireshark 时间列incl_len:实际写了几字节包数据(= IPv4头 + TCP头 + 明文载荷)orig_len:原始长度,r0capture 设等于 incl_len(不截断)
时间戳
时间戳在主机端 on_message 处理时打,反映"r0capture 收到这批明文"的时刻,而非 App 实际收发的精确时刻(有微小延迟)。
与全局头的关系
[全局头 24B][记录头16B][包数据][记录头16B][包数据]...全局头一次,记录头每包一次。