Expand description
Records that are not all one size, read from a memory map: length-prefixed records, variants a type field picks, records found by a sync marker, records in compressed blocks or in the payloads of a packet capture, and fixed records with fields that are read one at a time (varints, NUL-terminated text, counted groups, bit fields, deltas, checksums).
A first pass walks the records and keeps where every 1024th one starts (and, for delta columns, the running sums there), so the index stays small and a window anywhere is read by walking from the nearest checkpoint. Fixed records with a known size need no pass at all: where a record starts is arithmetic.
A compressed block is decompressed when it is first read, and a few are kept.
The frame is decoded over a row index (crate::row_index), as
crate::fixed_records’ is, and a window deeper in the file is read through
FramedRecords::window.
Modules§
- capture
- Packet captures (pcap and pcapng): the UDP payload of each packet, with its time.
Structs§
- Framed
Records - Records read through a spec, by walking them.
Constants§
- MAX_
BLOCK - The most bytes one block may decompress to.
Functions§
- decompress
rawdecompressed bycodec, at mostMAX_BLOCKbytes.- needed
- Whether
specneeds records walked rather than the fixed reader.