tcpdump mailing list archives

Re: Libpcap reentrancy and PF_RING patch


From: Guy Harris <guy () alum mit edu>
Date: Mon, 31 Dec 2007 14:05:25 -0800

Luca Deri wrote:

My patch also adds support for PF_RING (http://www.ntop.org/PF_RING.html) that is a Linux packet acceleration technique that uses a shared ring buffer between the kernel and user-space.

I seem to remember an earlier PF_RING paper that said that an interface doing PF_RING capturing wouldn't supply packets to the network stack, but the page you link to lists

Ability to work in transparent mode (i.e. the packets are also forwarded to upperlinks so existing applications will work as usual).

as a feature of PF_RING. I assume that's the mode that your changes to libpcap put the device into, so that, as with other capture mechanisms, networking activity can continue while capturing is in progress.
-
This is the tcpdump-workers list.
Visit https://cod.sandelman.ca/ to unsubscribe.


Current thread: