| PCAP_OFFLINE_FILTER(3PCAP) | Package Capture Library Functions | PCAP_OFFLINE_FILTER(3PCAP) |
pcap_offline_filter - check whether a filter matches a packet
#include <pcap/pcap.h>
int pcap_offline_filter(const struct bpf_program *fp,
const struct pcap_pkthdr *h, const u_char *pkt);
pcap_offline_filter() checks whether a filter matches a packet. fp is a pointer to a bpf_program struct, usually the result of a call to pcap_compile(3PCAP). h points to the pcap_pkthdr structure for the packet, and pkt points to the data in the packet.
In the bpf_program structure the bf_insns member is either NULL (which means to reject all packets) or points to an array of one or more struct bpf_insn elements, in which case the bf_len member must be set to the number of elements (this is what pcap_compile() produces).
The filter program must have been compiled for a link-layer header type that matches the packet data; also on Linux the filter must not use BPF extensions, see pcap_compile() for more information.
pcap_offline_filter() returns the return value of the filter program. This will be zero if the packet doesn't match the filter and non-zero if the packet matches the filter.
In libpcap releases before 1.10.7 this function ignored the provided bf_len value.
| 12 March 2026 | OmniOS |