today's "I can't believe I wasted half a hour on this" computer issue: whether Wireshark validates the Ethernet checksum in packets depends on the capture format you're using

.snoop: nope, and ignores all settings including "always check FCS"
.pcap: yep

saving a .snoop file as a .pcap file makes it immediately check all FCS

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/whitequark/statuses/114623134955982894 on your instance and quote it. (Note that quoting is not supported in Mastodon.)