bpf - Berkeley Packet Filter
function attaches a network interface to . The Fa ifp argument is a pointer to the structure that defines the interface to be attached to an interface. The Fa dlt argument is the data link-layer type: DLT_NULL (no link-layer encapsulation), DLT_EN10MB (Ethernet), DLT_IEEE802_11 (802.11 wireless networks), etc. The rest of the link layer types can be found in In net/bpf.h . The Fa hdrlen argument is the fixed size of the link header; variable length headers are not yet supported. The system will hold a pointer to Fa ifp->if_bpf . This variable will set to a non- NULL value when requires packets from this interface to be tapped using the functions below.
function allows multiple instances to be attached to a single interface, by registering an explicit Fa if_bpf rather than using Fa ifp->if_bpf . It is then possible to run tcpdump(1) on the interface for any data link-layer types attached.
function detaches a instance from an interface, specified by Fa ifp . The bpfdetach ();
function should be called once for each instance attached.
function is used by an interface to pass the packet to . The packet data (including link-header), pointed to by Fa pkt , is of length Fa pktlen , which must be a contiguous buffer. The Fa ifp argument is a pointer to the structure that defines the interface to be tapped. The packet is parsed by each processes filter, and if accepted, it is buffered for the process to read.
function is like bpf_tap ();
except that it is used to tap packets that are in an Vt mbuf chain, Fa m . The Fa ifp argument is a pointer to the structure that defines the interface to be tapped. Like bpf_tap (,);
requires a link-header for whatever data link layer type is specified. Note that only reads from the Vt mbuf chain, it does not free it or keep a pointer to it. This means that an Vt mbuf containing the link-header can be prepended to the chain if necessary. A cleaner interface to achieve this is provided by bpf_mtap2 (.);
function allows the user to pass a link-header Fa data , of length Fa dlen , independent of the Vt mbuf Fa m , containing the packet. This simplifies the passing of some link-headers.
function executes the filter program starting at Fa pc on the packet Fa pkt . The Fa wirelen argument is the length of the original packet and Fa buflen is the amount of data present. The Fa buflen value of 0 is special; it indicates that the Fa pkt is actually a pointer to an mbuf chain (Vt struct mbuf * )
function checks that the filter code Fa fcode , of length Fa flen , is valid.
function returns 0 when the program is not a valid filter program.
Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру