tcpdump work with bonding interface
0.0.1. test case
0.0.1.1. On redhat5, Why tcpdump could not work on bonding work.
OS: redhat 5.
There are two 82599 interfaces eth0 and eth1.
These two interfaces are used as slave of bond0,
eth1 is backup of eth0.
We ping the default gateway on test machine.
ping work OK, and tcpdump on bond0 show the icmp request and icmp require packets.
while on eth0 only icmp request, and eth1 has no any packet.
It is impossible there is no incoming packet on any physical interface.
Why tcpdump could not capture the packets on eth0.
0.0.2. analysis
tcpdump is pf_socket which is based on ptye_all.
0.0.2.1. linux V2.6.32
In linux v2.6.32, there is bond process before ptye_all,
and thus the skb->dev will be change to bond0 from eth0.
so when packet arrive ptye_all, ony match incoming dev bond0.
we has no chance to capture packet on physical interface eth0.
0.0.2.2. upstream linux v3.17-rc4
bond related process is moved to dev->rx_handler,
Just like the bridge or openvswitch.
Packet will first be processed by ptype_all with skb->dev is eth0
and then rx_handler(bond handler for eth0,eth1).
if the rx handler return RX_HANDLER_ANOTHER,
the packet arrive by ptye_all again with differentskb->dev (bond0).
0.0.2.3. related patch
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5b2c4d
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=63d8ea
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5b2c4dd
0.0.2.3.1. TODO:
Test with upstream kernel.
0.0.3. Redhat source
redhat source is based on 2.6.32
1 | |
0.0.3.1. upstream linux V3.16
1 | |