Subject: Re: packet capturing
To: Jonathan Stone <jonathan@DSG.Stanford.EDU>
From: Andrew Brown <email@example.com>
Date: 01/21/2004 08:27:47
>I committed changes to libpcap's pcap-bpf.c to probe for, and use,
>much larger in-kernel buffer sizes. Here's a trivial diff (trivial as
>in, no dynamic sizing, no sysctl support) to sys/net/bpf.c. The
>default BPF_BUFSIZE of 8k is arguable; I suggest we make it at least
>9k, to support ATM and Ethernet jumbo frames. (not included below).
>I'm hoping Andrew Brown (or someone else conversant with new-sysctl)
>will add the sysctl hooks, as I can barely even read the new sysctl API.
what are the rules? bpf_maxbufsize must be less or equal than
BPF_MAXBUFSIZE, must be greater than or equal to BPF_MINBUFSIZE, and
must be in increments of 1024?
|-----< "CODE WARRIOR" >-----|
firstname.lastname@example.org * "ah! i see you have the internet
email@example.com (Andrew Brown) that goes *ping*!"
firstname.lastname@example.org * "information is power -- share the wealth."