Skip to main content

Module framed_records

Module framed_records 

Source
Expand description

Records that are not all one size, read from a memory map: length-prefixed records, variants a type field picks, records found by a sync marker, records in compressed blocks or in the payloads of a packet capture, and fixed records with fields that are read one at a time (varints, NUL-terminated text, counted groups, bit fields, deltas, checksums).

A first pass walks the records and keeps where every 1024th one starts (and, for delta columns, the running sums there), so the index stays small and a window anywhere is read by walking from the nearest checkpoint. Fixed records with a known size need no pass at all: where a record starts is arithmetic.

A compressed block is decompressed when it is first read, and a few are kept.

The frame is decoded over a row index (crate::row_index), as crate::fixed_records’ is, and a window deeper in the file is read through FramedRecords::window.

Modules§

capture
Packet captures (pcap and pcapng): the UDP payload of each packet, with its time.

Structs§

FramedRecords
Records read through a spec, by walking them.

Constants§

MAX_BLOCK
The most bytes one block may decompress to.

Functions§

decompress
raw decompressed by codec, at most MAX_BLOCK bytes.
needed
Whether spec needs records walked rather than the fixed reader.