-
I'm writing a traffic sniffer and realtime-analyzer. Today I did a test on the performance of the part of writing packets. Results show that it lost packets when the speed of traffic was 200Mbps. I wo…
-
(*TPacket).ZeroCopyReadPacketData is called in a goroutine and it blocking that goroutine. I want to cancel that goroutine by calling (*TPacket).Close in other gorouting, but panic occurred. To align …
-
`afpacket.TPacket.ZeroCopyReadPacketData()` seems to return duplicate packets. When running in a loop, the function returns twice (iterating the loop twice) for each packet.
By modifying the exampl…
-
### What version of rules_go are you using?
`0.19.1`
### What version of gazelle are you using?
`0.18.1`
### What version of Bazel are you using?
`0.26.1`
### Does this issue reproduce…
-
snort3 is running as a daemon on a live network interface in passive mode with daq module "pcap":
```daq = {
module_dirs = {
'/usr/lib/x86_64-linux-gnu/daq3'
},
modules = {
…
-
Hi,
I am using a 2.6 kernel to compile af_packet. I see that the linux/if_packet.h does not have the fields and structs that are introduced by afpacket/header.go.
22:20:28 gopath/src/github.c…
-
**Describe the bug**
We are currently using dnscollector version 1.0.0 with the afpacket sniffer. The issue arises when attempting to stop or restart the dnscollector service. The process does not s…
-
I wrote a small program for the tcpreassembly test and started traffic over FTP (ftp inside a gigabit LAN). On ftp uploaded 1 file (iso image 533 megabytes). As a result, the amount of memory used inc…
-
OMG I shoulda done this months ago! I do not understand why there exists AF_PACKET and PF_RING... they are essentially equivalent but AF_PACKET is merged in the mainline kernel whereas PF_RING has a c…
-
When running Snort inline on an interface in no-carrier state (can be observed by running Snort with interfaces up, then disconnecting 1 or more bridged interfaces OR by simply leaving 1 or more bridg…