Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
< Back to tools
L

libpcap

> 编程语言
Open source

the LIBpcap interface to various kernel packet capture mechanism

3.1K stars0 likes0 views
WebsiteGitHub

About

the LIBpcap interface to various kernel packet capture mechanism

LIBPCAP 1.x.y by The Tcpdump Group

To report a security issue please send an e-mail to [email protected].

To report bugs and other problems, contribute patches, request a feature, provide generic feedback etc please see the guidelines for contributing.

The documentation directory has README files about specific operating systems and options.

Anonymous Git is available via:

https://github.com/the-tcpdump-group/libpcap.git

This directory contains source code for libpcap, a system-independent interface for user-level packet capture. libpcap provides a portable framework for low-level network monitoring. Applications include network statistics collection, security monitoring, network debugging, etc. Since almost every system vendor provides a different interface for packet capture, and since we've developed several tools that require this functionality, we've created this system-independent API to ease in porting and to alleviate the need for several system-dependent packet capture modules in each application.

formerly from	Lawrence Berkeley National Laboratory
		Network Research Group <[email protected]>
		ftp://ftp.ee.lbl.gov/old/libpcap-0.4a7.tar.Z

Support for particular platforms and BPF

For some platforms there are README.{system} files that discuss issues with the OS's interface for packet capture on those platforms, such as how to enable support for that interface in the OS, if it's not built in by default.

The libpcap interface supports a filtering mechanism based on the architecture in the BSD packet filter. BPF is described in the 1993 Winter Usenix paper ``The BSD Packet Filter: A New Architecture for User-level Packet Capture'' (compressed PostScript, gzipped PostScript, PDF).

Although most packet capture interfaces support some in-kernel filtering, libpcap utilizes in-kernel filtering only for the use cases that support BPF programs, namely, the BPF packet capture interface, the Linux packet socket and the GNU/Hurd interface.

In all other cases libpcap reads every packet into user-space and evaluates it using the filter program, which incurs added overhead (especially, for selective filters). Ideally, libpcap would translate BPF filters into a filter program that is compatible with the underlying kernel subsystem, but this is not implemented.

BPF is standard in NetBSD, FreeBSD, OpenBSD, DragonFly BSD, macOS, QNX and Solaris 11; an older, modified and undocumented version is standard in AIX.

Linux has a number of BPF based systems, and libpcap does not support any of the eBPF mechanisms as yet, although it supports many of the memory mapped receive mechanisms. See the Linux-specific README for more information.

Note to Linux distributions and *BSD systems that include libpcap:

There's now a rule to make a shared library, which should work on Linux and *BSD, among other platforms.

It sets the soname of the library to libpcap.so.1; this is what it should be, NOT libpcap.so.1.x or libpcap.so.1.x.y or something such as that.

We've been maintaining binary compatibility between libpcap releases for quite a while; there's no reason to tie a binary linked with libpcap to a particular release of libpcap.

GitHub Issues· 180 open

View all on GitHub
  • #1217

    document RDMA and netmap support better

    documentationUpdated Sep 16, 2026
  • #1509

    at the build time verify that atexit() does not crash

    compilingUpdated Sep 14, 2026
  • #1670

    vxlan: "vxlan" filter do not support "vxlan and arp"

    BPF relatedoptimizerUpdated Sep 11, 2026
  • #1733

    netmap module counts received packets before filtering

    Updated Sep 10, 2026
  • #1730

    bpf_filter: Unsigned integer overflow

    Updated Sep 7, 2026
  • #1738

    pcap-rpcap.c:340 [-Walloc-size] from Clang 22

    compilingrpcapUpdated Aug 31, 2026
  • #1673

    dlpi: Truncation warning on Solaris 10 with gcc

    compilingUpdated Aug 27, 2026
  • #1726

    Optimizer dead-store elimination removes a live `st M[1]` for vxlan filters → `vxlan and ip` / `vxlan and arp` silently fail to match (optimize=1)

    BPF relatedoptimizerUpdated Aug 27, 2026

Highlights

  • •C
  • •berkeley-packet-filter
  • •bpf
  • •bsd-packet-filter
  • •libpcap

> Tags

Cberkeley-packet-filterbpfbsd-packet-filterlibpcap

No comments yet. Be the first to share.

> Details

PublishedAug 1, 2026
UpdatedSep 17, 2026
Category编程语言
PricingOpen source

> Related tools

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言