Actions
Feature #8225
opendpdk: recognize net_pcap driver and stop after no packets are rx_bursted
Effort:
Difficulty:
Label:
Description
This can be used to read PCAP files, similarly to the PCAP reading mode in Suriacta. The purpose is to test DPDK capture method "offline". This can be done currently as well but Suricata is now stuck in the RX loop after the PCAP reading is finished. The PCAP end of file is characterized by receiving no packets.
The workaround nowadays is to use timeout command, but as a side effect, it slows the evaluation down because "the test" waits until the timeout duration elapses.
This, in turn, stops immediately after PCAP is read and processed.
Within the task, document this option and also evaluate if something like "streaming PCAP files" should be considered.
Updated by OISF Ticketbot about 8 hours ago
- Label deleted (
Needs backport to 8.0)
Actions