‹ BackHN Continuity

Thread

Small programming tricks

681 points · 294 comments · signa11

  1. alexpotato · · focus · HN ↗
    For people asking "do these small tricks/trivia really matter??" I have an example of when they do:

    - having strange networking issues on the blue side of a blue/green deployment

    - networking engineers are involved

    - nobody seems to be able to figure out what's going on despite LOTS of tcpdump/wireshark etc

    - I suggest tcpflow[0] (which I used for protocol analysis of chat services etc)

    - (there is some skepticism as I was SRE and not networking)

    - Turns out that the TCP messages were getting truncated on the problem side

    - Networking guys realize the config issue and fix it

    I have other examples but this is why it's always good to learn new commands/tools etc.

    This, in turn, reminds me of a quote from an army jungle survival expert: "People ask me if it's a good idea to read survival books. I say: 100%. You would be surprised how many people survive an emergency situation because their brain pops out some critical piece of information from a book or article they read 10 years ago."

    0 - <a href="https:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;1&#x2F;tcpflow" rel="nofollow">https:&#x2F;&#x2F;linux.die.net&#x2F;man&#x2F;1&#x2F;tcpflow

    1. xorcist · · focus · HN ↗
      No to belittle your find even the slightest, but it might be good to notice that tcpflow decodes tcp flows, which is exactly what Wireshark does, only the latter in a GUI and with a plethora of other protocol decoders. Just right click any tcp packet and select Follow.

      Both tools even use the same filtering language, coming from tcpdump itself. Wireshark&#x27;s protocol decoder is more advanced than tcpflow. It does understand fragmented packets. So given a choice, Wireshark is often the preferred tool.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.