# expression rejects all packets

**URL:** <https://community.zeek.org/t/expression-rejects-all-packets/186>\
**Category:** Zeek\
**Created:** [September 13, 2001, 1:33am UTC](https://community.zeek.org/t/expression-rejects-all-packets/186 "2001-09-13T01:33:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bill\_Fenner](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@Bill\_Fenner](https://community.zeek.org/u/Bill_Fenner)\
**Post date:** [September 13, 2001, 1:33am UTC](https://community.zeek.org/t/expression-rejects-all-packets/186/1 "2001-09-13T01:33:50Z")

</div>

I'm still not 100% clear what the problem is. pcap\_compile()  
resets the off\_linktype and off\_nl fields before compiling the  
expression, so a "vlan" qualifier in an earlier expression can't  
affect future calls to pcap\_compile(). Multiple "vlan" qualifiers  
in the same expression set the offsets to the same constant  
offset.

The only bug I'm aware of is that the "vlan" qualifier is positional  
and so affects all expressions after it, so if you use the expression  
"( vlan and ip ) or ip" (trying to match non-trunked IP packets as well as  
VLAN-trunked) you end up getting just trunked packets; you need to use  
"ip or ( vlan and ip )".

Actually, I take it back -- after composing this email, I decided to  
double-check the compiler, and there's an optimizer bug that affects  
the first construct I described:

mango% ./xprtest vlan and ip or ip  
(000) ldh [12]  
(001) ldh [16]  
(002) jeq #0x800 jt 3 jf 4  
(003) ret #96  
(004) ret #0

Disabling the optimizer results in a correct (but redundant) expression.  
Perhaps you're running into something like this?

&nbsp;&nbsp;Bill

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/expression-rejects-all-packets/186/2 "2022-05-06T15:36:22Z")

</div>


