Wireshark-dev: Re: [Wireshark-dev] Is "tcp.len < -1" a valid display filter?
From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Thu, 27 Oct 2011 13:12:22 -0600
On Thu, Oct 27, 2011 at 08:28:43AM +0200, Stig Bjørlykke wrote:

> On a 32-bit system the display filter "tcp.len < -1" seems to be 
> valid, and does return all TCP packets.

> The attached patch fixes this, but can we do this check in a simpler 
> manner?

Is there a problem with accepting -1 in that filter?  If so, should the 
filter be checked against possible values of the value, i.e. tcp.len is 
a FT_UINT32 so only accept unsigned 32-bit values and mark the 
background as red / bad filter if not?