manpagez: man pages & more
man pcap_offline_filter(3)
Home | html | info | man
pcap_offline_filter(3)                          pcap_offline_filter(3)


NAME

       pcap_offline_filter - check whether a filter matches a packet


SYNOPSIS

       #include <pcap/pcap.h>

       pcap_offline_filter(3) struct bpf_program *fp,
           const struct pcap_pkthdr *h, const u_char *pkt);


DESCRIPTION

       pcap_offline_filter() checks whether a filter matches a packet.  fp is
       a pointer to a bpf_program structure, usually the result of a call to
       pcap_compile(3).  h points to the pcap_pkthdr structure for the
       packet, and pkt points to the data in the packet.

       In the bpf_program structure the bf_insns member is either a null
       pointer (which means to reject all packets) or points to an array of
       one or more struct bpf_insn elements, in which case the bf_len member
       must be set to the number of elements (this is what pcap_compile()
       produces).

       The filter program must have been compiled for a link-layer header type
       that matches the packet data; also on Linux the filter must not use BPF
       extensions, see pcap_compile() for more information.


RETURN VALUE

       pcap_offline_filter() returns the return value of the filter program.
       This will be zero if the packet doesn't match the filter and non-zero
       if the packet matches the filter.


BACKWARD COMPATIBILITY

       In libpcap releases before 1.10.7 this function ignored the provided
       bf_len value.


SEE ALSO

       pcap(3)

                               6 September 2026     pcap_offline_filter(3)

libpcap 1.11.0 - Generated Tue Sep 15 08:51:43 CDT 2026
© manpagez.com 2000-2026
Individual documents may contain additional copyright information.