12/21/00

Wesley Eddy spake unto us the following wisdom:
> I checked up some more on this by looking at an actual Redhat box of a friend
> of mine, and I was right, the pcap.h they ship has ts as a bpf_timeval instead
> of a plain old timeval. I'm not sure if you can just do a cast in the tcptrace
> code to fix it, but in any case, getting a different libpcap should fix it.

That's not the only brain damage the RH7 pcap seems to have,
unfortunately... So far as I can tell it also uses a different magic
number. I have no earthly idea why... At any rate, I have had no luck
reading a RH7-captured dump on a Solaris box.

