On Tue, 6 Oct 2026 07:42:28 +0100 Frank Dressler <[email protected]> wrote:
> By default, AF_PACKET delivers both incoming and outgoing packets. > This might surprise applications that expect rte_eth_rx_burst() to > return only incoming traffic. > > This patch adds the devarg ignore_outgoing=<0|1> to enable > PACKET_IGNORE_OUTGOING. When set, the kernel drops outgoing frames. > The default is 0 to keep the existing behavior. > > Signed-off-by: Frank Dressler <[email protected]> > --- > v3: > - drop #ifdef PACKET_IGNORE_OUTGOING (uapi since 4.20; DPDK requires kernel > >= 5.4) > - fail the test if ignore_outgoing=1 cannot create a port > - drop kernel >= 4.20 notes from docs and release notes > v2: > - use PACKET_IGNORE_OUTGOING / ignore_outgoing= instead of capture_dir > > --- AI spotted issue with multiple qpairs. [PATCH v3] net/af_packet: add option to ignore outgoing packets Builds clean with -Dwerror=true. Test not run. Error 1. ignore_outgoing=1 has no effect when qpairs > 1. rc = setsockopt(qsockfd, SOL_PACKET, PACKET_IGNORE_OUTGOING, &ignore_outgoing, sizeof(ignore_outgoing)); With more than one queue every socket joins a fanout group. fanout_add() removes the socket's own packet_type from ptype_all and registers the group's instead, and dev_queue_xmit_nit() only looks at the group's ignore_outgoing. The per-socket option is accepted and silently does nothing. The group needs PACKET_FANOUT_FLAG_IGNORE_OUTGOING (6.2) or'd into the flags half of fanout_arg. Kernels before 6.2 do not validate fanout flags; the bit is accepted and ignored there. Either keep the sll_pkttype check in eth_af_packet_rx() as a backstop, or document that ignore_outgoing with qpairs > 1 needs 6.2. Distro headers older than 6.2 lack the define, so provide a fallback #define. Warning 2. Test only covers the single queue case and never sends an incoming frame. TEST_ASSERT(rx_on == 0, "Expected no packets with ignore_outgoing=1"); A port that receives nothing at all passes this. Write frames to tap_fd as test_af_packet_loopback() does and check that the ignore_outgoing=1 port still receives them. Run the same check with qpairs=2; that would have caught item 1. Info 3. Commit message: When set, the kernel drops outgoing frames. The frames are still transmitted; the socket just does not get a copy. The doc text has it right, use that wording.

