Feature #3705

wireshark: ip.access PDCH DEACT ACK and NACK missing support to display IE values

Added by pespin 22 days ago. Updated 9 days ago.

Target version:
Start date:
Due date:
% Done:


Spec Reference:


See attached pcap file.

Wireshark can currently parse the ip.access PDCH DEACTIVATION ACK/NACK correctly, and shows IEs type like "Channel Number" or "Cause", but doesn't show its values in the tree.

For "Channel Number", it looks like a TV with len(V) = 1 byte. For Cause, it looks like it's a TLV with L = len(V) = 1.

See matching log message from osmo-bts-trx:

20181123044720700 DRSL <0000> rsl.c:2131 (bts=0,trx=0,ts=6,ss=0) Tx PDCH DEACT NACK (cause = 0x0f)

pdch_deactivation.pcap pdch_deactivation.pcap 1.11 MB pespin, 11/23/2018 03:29 PM


#1 Updated by pespin 22 days ago

Error causes come from include/osmocom/gsm/protocol/gsm_08_58.h, RSL_ERR_*

#2 Updated by pespin 22 days ago

ip.access PDCH DEACTIVATION (the request) is also missing display of value of Channel Number

#3 Updated by pespin 10 days ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 90

Submitted a bunch of patches with stuff I found was wrong or missing:
remote: packet-rsl: Use defines for ip.access value_string
remote: packet-rsl: Fix parsing values of some IE in ip.access specific messages
remote: packet-rsl: Parse missing Cause IE in ip.access specific messages
remote: packet-rsl: Move rsl_class_vals into its correct spec section
remote: packet-rsl: Show cause value string of Cause IE

#4 Updated by pespin 9 days ago

  • Status changed from Feedback to Resolved
  • % Done changed from 90 to 100

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 48.8 MB)