On Sun,  4 Oct 2026 05:22:54 +0100
Frank Dressler <[email protected]> wrote:

> By default, AF_PACKET sockets capture both incoming and outgoing
> packets. This leads to unexpected behavior in the AF_PACKET PMD
> since other PMDs only return actually received packets in
> rte_eth_rx_burst() calls.
> 
> This patch adds an option capture_dir=<in|out|inout> that controls
> which packets are received, similar to tcpdump's -Q option.
> 
> The PMD never sees its own TX on RX, but TX from other sources on
> the same netdev is still seen. Use inout for tcpdump-like tools and
> in for applications that send and receive.
> 
> The default is "inout" so that existing software keeps working as
> before.
> 
> The filter checks the packet type in the struct sockaddr_ll that
> comes with each packet. Each TPACKET_V2 packet is laid out as
>   struct tpacket2_hdr | struct sockaddr_ll | packet data.
> The kernel sets sockaddr_ll::sll_pkttype to skb->pkt_type, which is
> PACKET_OUTGOING for outgoing packets (set by dev_queue_xmit_nit())
> and a different value otherwise. Libpcap's linux_check_direction()
> uses the same check.
> 
> A unit test injects OUTGOING traffic from a second port on the same
> TAP and checks in/out/inout filtering.
> 
> Signed-off-by: Frank Dressler <[email protected]>

The AF_PACKET PMD is special case really intended for monitoring
applications, not for general use. You are probably better off using AF_XDP
for general use. 

The kernel does have flags to filter by direction, so you could
avoid having it be done in the PMD.

Reply via email to