Wireshark-dev: Re: [Wireshark-dev] How to modify existing RTP conversation?
From: Jirka Novak <j.novak@xxxxxxxxxxxx>
Date: Mon, 9 Jan 2017 10:50:10 +0100
Hi,

  did I made wrong code analysis and root cause is somewhere else?

>> I would like to know where this is done:
>>
>>  I analysed the code and found that for #1 is created "full"
>> conversation (full = SRC_IP:SRC_PORT <-> DST_IP:DST_PORT) with UDP as
>> protocol.
>>
>> because that sounds questionable. 
> 
> packet_udp.c: dissect() calls find_or_create_conversation(pinfo) for
> every packet. When packet is new (#1 in my example), it creates new full
> conversation just for UDP layer.
> Conversation is created as full/bidirectional, I checked it with enabled
> DEBUG_CONVERSATION.

						Sincerely yours,

							Jirka Novak