From: Stephen Hemminger <stephen@networkplumber.org>
To: dev@dpdk.org
Cc: Stephen Hemminger <stephen@networkplumber.org>
Subject: [PATCH v4 0/4] add rpcap remote capture daemon
Date: Wed, 30 Sep 2026 19:35:25 -0700 [thread overview]
Message-ID: <20261001025853.319860-1-stephen@networkplumber.org> (raw)
In-Reply-To: <20260908210832.1556291-1-stephen@networkplumber.org>
This series adds support for live capture using tcpdump and related
tools that use libpcap. See document doc/guides/tools/rpcapd.rst
for the details.
The dpdkr rpcap daemon runs as a secondary process similar to dpdk-pdump
and dpdk-dumpcap. The difference is instead of writing packets
directly to a file, it provides a standard API for transferring
packet capture over a socket. The command line arguments
are chosen to match the existing libpcap rpcapd, but not
all command flags are implemented.
The capture is only possible if the rpcap daemon is running.
And since it is a secondary process, it needs to be started
after the DPDK primary process. The daemon will also exit when
the primary process exits.
Since it is intended for debugging (and due to limitations in
the pdump API), only a single client can access rpcap at a time.
The dpdk-rpcapd uses existing pdump infrastructure to capture
and filter packets. One small additional API was needed to extract
the timestamp and original capture length from the mbuf
that was processed with pcapng mode. Since rpcap protocol
is limited to pcap legacy format, only microsecond timestamps
(and no metadata info) are visible in the stream.
By default dpdk-rpcapd can only be used over local TCP sockets.
This version also adds TLS and password authentication which
could be useful if dpdk-rpcapd is setup to allow non-local access.
An additional security feature was added based on what libpcap rpcapd has,
with the -l flag a list of allowed hosts can be used.
Changes since previous version:
- Moved from examples/ to app/
- Added TLS and password authentication (patch 3).
- Added the -l host list option (patch 4).
Stephen Hemminger (4):
pcapng: add API to read back capture mbuf header
app/rpcapd: remote pcap daemon
app/rpcapd: add TLS support
app/rpcapd: add host list option
MAINTAINERS | 2 +
app/meson.build | 1 +
app/rpcapd/capture.c | 541 ++++++++++++++++
app/rpcapd/filter.c | 164 +++++
app/rpcapd/main.c | 840 +++++++++++++++++++++++++
app/rpcapd/meson.build | 40 ++
app/rpcapd/rpcap-protocol.h | 146 +++++
app/rpcapd/rpcapd.h | 122 ++++
app/rpcapd/session.c | 292 +++++++++
app/rpcapd/sock.c | 365 +++++++++++
app/rpcapd/tls.c | 273 ++++++++
app/test/test_pcapng.c | 133 ++++
doc/guides/rel_notes/release_26_11.rst | 13 +
doc/guides/tools/index.rst | 1 +
doc/guides/tools/rpcapd.rst | 288 +++++++++
lib/pcapng/rte_pcapng.c | 40 ++
lib/pcapng/rte_pcapng.h | 46 ++
17 files changed, 3307 insertions(+)
create mode 100644 app/rpcapd/capture.c
create mode 100644 app/rpcapd/filter.c
create mode 100644 app/rpcapd/main.c
create mode 100644 app/rpcapd/meson.build
create mode 100644 app/rpcapd/rpcap-protocol.h
create mode 100644 app/rpcapd/rpcapd.h
create mode 100644 app/rpcapd/session.c
create mode 100644 app/rpcapd/sock.c
create mode 100644 app/rpcapd/tls.c
create mode 100644 doc/guides/tools/rpcapd.rst
--
2.53.0
next prev parent reply other threads:[~2026-10-01 2:59 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 21:07 [PATCH] examples/rpcapd: demo version of packet capture daemon Stephen Hemminger
2026-09-20 18:59 ` [PATCH v2] " Stephen Hemminger
2026-09-21 9:51 ` Marat Khalili
2026-09-21 15:57 ` Stephen Hemminger
2026-09-21 15:58 ` Stephen Hemminger
2026-09-21 16:43 ` Marat Khalili
2026-09-21 17:31 ` Stephen Hemminger
2026-09-21 17:53 ` Marat Khalili
2026-09-21 16:17 ` Stephen Hemminger
2026-09-22 18:45 ` Stephen Hemminger
2026-09-22 21:31 ` [PATCH v3] " Stephen Hemminger
2026-09-28 16:18 ` Marat Khalili
2026-09-28 17:24 ` Stephen Hemminger
2026-10-01 2:35 ` Stephen Hemminger [this message]
2026-10-01 2:35 ` [PATCH v4 1/4] pcapng: add API to read back capture mbuf header Stephen Hemminger
2026-10-01 2:35 ` [PATCH v4 2/4] app/rpcapd: remote pcap daemon Stephen Hemminger
2026-10-01 18:50 ` Marat Khalili
2026-10-01 2:35 ` [PATCH v4 3/4] app/rpcapd: add TLS support Stephen Hemminger
2026-10-01 2:35 ` [PATCH v4 4/4] app/rpcapd: add host list option Stephen Hemminger
2026-10-01 18:50 ` [PATCH v4 0/4] add rpcap remote capture daemon Marat Khalili
2026-10-01 23:00 ` Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001025853.319860-1-stephen@networkplumber.org \
--to=stephen@networkplumber.org \
--cc=dev@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox