This series adds support for live capture using tcpdump and related
tools that use libpcap. See document doc/guides/tools/rpcapd.rst
for the details.

The dpdkr rpcap daemon runs as a secondary process similar to dpdk-pdump
and dpdk-dumpcap. The difference is instead of writing packets
directly to a file, it provides a standard API for transferring
packet capture over a socket. The command line arguments
are chosen to match the existing libpcap rpcapd, but not
all command flags are implemented.

The capture is only possible if the rpcap daemon is running.
And since it is a secondary process, it needs to be started
after the DPDK primary process. The daemon will also exit when
the primary process exits.

Since it is intended for debugging (and due to limitations in
the pdump API), only a single client can access rpcap at a time.

The dpdk-rpcapd uses existing pdump infrastructure to capture
and filter packets. One small additional API was needed to extract
the timestamp and original capture length from the mbuf
that was processed with pcapng mode. Since rpcap protocol
is limited to pcap legacy format, only microsecond timestamps
(and no metadata info) are visible in the stream.

By default dpdk-rpcapd can only be used over local TCP sockets.
This version also adds TLS and password authentication which
could be useful if dpdk-rpcapd is setup to allow non-local access.
An additional security feature was added based on what libpcap rpcapd has,
with the -l flag a list of allowed hosts can be used.

Changes since previous version:

  - Moved from examples/ to app/
  - Added TLS and password authentication (patch 3).
  - Added the -l host list option (patch 4).

Stephen Hemminger (4):
  pcapng: add API to read back capture mbuf header
  app/rpcapd: remote pcap daemon
  app/rpcapd: add TLS support
  app/rpcapd: add host list option

 MAINTAINERS                            |   2 +
 app/meson.build                        |   1 +
 app/rpcapd/capture.c                   | 541 ++++++++++++++++
 app/rpcapd/filter.c                    | 164 +++++
 app/rpcapd/main.c                      | 840 +++++++++++++++++++++++++
 app/rpcapd/meson.build                 |  40 ++
 app/rpcapd/rpcap-protocol.h            | 146 +++++
 app/rpcapd/rpcapd.h                    | 122 ++++
 app/rpcapd/session.c                   | 292 +++++++++
 app/rpcapd/sock.c                      | 365 +++++++++++
 app/rpcapd/tls.c                       | 273 ++++++++
 app/test/test_pcapng.c                 | 133 ++++
 doc/guides/rel_notes/release_26_11.rst |  13 +
 doc/guides/tools/index.rst             |   1 +
 doc/guides/tools/rpcapd.rst            | 288 +++++++++
 lib/pcapng/rte_pcapng.c                |  40 ++
 lib/pcapng/rte_pcapng.h                |  46 ++
 17 files changed, 3307 insertions(+)
 create mode 100644 app/rpcapd/capture.c
 create mode 100644 app/rpcapd/filter.c
 create mode 100644 app/rpcapd/main.c
 create mode 100644 app/rpcapd/meson.build
 create mode 100644 app/rpcapd/rpcap-protocol.h
 create mode 100644 app/rpcapd/rpcapd.h
 create mode 100644 app/rpcapd/session.c
 create mode 100644 app/rpcapd/sock.c
 create mode 100644 app/rpcapd/tls.c
 create mode 100644 doc/guides/tools/rpcapd.rst

-- 
2.53.0

Reply via email to