3 ms·
I was recently trying to write my own TCP stack to solidify my networking knowledge, similar to Julia Evans's efforts [1]. I got frustrated working with raw so
by jgable 12y ago
I was recently trying to write my own TCP stack to solidify my networking knowledge, similar to Julia Evans's efforts [1]. I got frustrated working with raw sockets on my mac, because they don't provide the same level of control as raw sockets on linux [2]. Is pcap a better level of abstraction that is cross-platform? I don't really care about windows, but it would be nice to work on linux and osx.
[1] http://jvns.ca/blog/2014/08/12/what-happens-if-you-write-a-tcp-stack-in-python/ http://jvns.ca/blog/2014/08/12/what-happens-if-you-write-a-t...
[2] http://stackoverflow.com/questions/6878603/strange-raw-socket-on-mac-os-x http://stackoverflow.com/questions/6878603/strange-raw-socke...
- tptacek 12y agoYes, pcap is the right abstraction to program bare-metal network code to. It's how most non-kernel-resident tools that implement their own TCP actually work.
- tpush 12y agoIf you only care about OS X, bpf(4) provides a very similar but nicer API for intercepting and sending raw packets. You could even go zero-copy without the hell that is Linux's 3 differently broken AF_PACKET mechanisms. I made a small example program[0] which just intercepts all packets and prints out statistics. The pthread stuff is only there to asynchroniusly handle signals without having to check every syscall for EINTR. Makes it possible to get statistics at run time by pressing control+T, however. [0] https://github.com/thasenpusch/bpf-example/blob/master/main.c https://github.com/thasenpusch/bpf-example/blob/master/main....
- tptacek 12y agopcap is an abstraction over bpf; in fact, the two were originally developed in tandem.