pcap_offline_filter(3) pcap_offline_filter(3)
NAME
pcap_offline_filter - check whether a filter matches a packet
SYNOPSIS
#include <pcap/pcap.h>
pcap_offline_filter(3) struct bpf_program *fp,
const struct pcap_pkthdr *h, const u_char *pkt);
DESCRIPTION
pcap_offline_filter() checks whether a filter matches a packet. fp is
a pointer to a bpf_program structure, usually the result of a call to
pcap_compile(3). h points to the pcap_pkthdr structure for the
packet, and pkt points to the data in the packet.
In the bpf_program structure the bf_insns member is either a null
pointer (which means to reject all packets) or points to an array of
one or more struct bpf_insn elements, in which case the bf_len member
must be set to the number of elements (this is what pcap_compile()
produces).
The filter program must have been compiled for a link-layer header type
that matches the packet data; also on Linux the filter must not use BPF
extensions, see pcap_compile() for more information.
RETURN VALUE
pcap_offline_filter() returns the return value of the filter program.
This will be zero if the packet doesn't match the filter and non-zero
if the packet matches the filter.
BACKWARD COMPATIBILITY
In libpcap releases before 1.10.7 this function ignored the provided
bf_len value.
SEE ALSO
pcap(3)
6 September 2026 pcap_offline_filter(3)
libpcap 1.11.0 - Generated Tue Sep 15 08:51:43 CDT 2026
