diff --git a/doc/windivert.html b/doc/windivert.html index 19bdd9f..0dc3610 100644 --- a/doc/windivert.html +++ b/doc/windivert.html @@ -46,8 +46,8 @@
-A test also fails if the field is missing.
-E.g. the test tcp.DstPort == 80
will fail if the packet does
-not contain a TCP header.
+A test will also fails if the field is not relevant.
+For example, the test tcp.DstPort == 80
will fail if the
+packet does not contain a TCP header.
-The layer-specific macros make it possible to match specific events +The processId field matches the ID of the process associated +to an event. +Due to technical limitations, this field is not supported by the +WINDIVERT_LAYER_NETWORK* layers. +That said, it is usually possible to associate process IDs to network packets +matching the same network 5-tuple. +
+Note that a fundamental race condition exists between the processId +and the termination of the corresponding process. +By the time an event is received using +WinDivertRecv(), +it is possible that the process has already terminated and +the ID has been reassigned to an unrelated process. +This problem can be partly mitigated by comparing the timestamp +(addr.Timestamp) with the creation time of the process. +If the process is newer, then the ID has been reassigned. +
+The packet*[i], tcp.Payload*[i] and +udp.Payload*[i] fields take an index parameter (i). +The following indexing schemes are supported: +
++These fields can be used to match filters against the contents of +packets/payloads in addition to address/header information. +Words are assumed to be in network-byte ordering. +If the index is out-of-bounds then the corresponding test is +deemed to have failed. +
+The random* fields are not really random but use a +deterministic hash value calculated using the +WinDivertHelperHashPacket() +function. +
+Layer-specific macros make it possible to match events and layers symbolically, e.g.,event == CONNECTor
layer == SOCKET. The possible macros are: @@ -2536,7 +2583,6 @@ The possible macros are: -