On Sun, 4 Oct 2026 05:22:54 +0100 Frank Dressler <[email protected]> wrote:
> By default, AF_PACKET sockets capture both incoming and outgoing > packets. This leads to unexpected behavior in the AF_PACKET PMD > since other PMDs only return actually received packets in > rte_eth_rx_burst() calls. > > This patch adds an option capture_dir=<in|out|inout> that controls > which packets are received, similar to tcpdump's -Q option. > > The PMD never sees its own TX on RX, but TX from other sources on > the same netdev is still seen. Use inout for tcpdump-like tools and > in for applications that send and receive. > > The default is "inout" so that existing software keeps working as > before. > > The filter checks the packet type in the struct sockaddr_ll that > comes with each packet. Each TPACKET_V2 packet is laid out as > struct tpacket2_hdr | struct sockaddr_ll | packet data. > The kernel sets sockaddr_ll::sll_pkttype to skb->pkt_type, which is > PACKET_OUTGOING for outgoing packets (set by dev_queue_xmit_nit()) > and a different value otherwise. Libpcap's linux_check_direction() > uses the same check. > > A unit test injects OUTGOING traffic from a second port on the same > TAP and checks in/out/inout filtering. > > Signed-off-by: Frank Dressler <[email protected]> The AF_PACKET PMD is special case really intended for monitoring applications, not for general use. You are probably better off using AF_XDP for general use. The kernel does have flags to filter by direction, so you could avoid having it be done in the PMD.

