Enabling and Verifying BPF Support in Npss: A Practical Build and Runtime Guide
Enable BPF in Npss, build with --enable-bpf, run a filtered capture, and verify kernel offloading. Includes prerequisites, commands, checks, and fallback options.
06 Sept 2026, 23:36 UTC

Why BPF Matters for Npss
Berkeley Packet Filter (BPF) lets the kernel decide which packets to forward to user space. For Npss, enabling BPF cuts CPU usage by up to 70% on high‑traffic links, but it requires a recent kernel, libpcap ≥ 1.9, and proper build flags. This guide walks you through the exact steps to compile Npss with BPF, run it with a filter, and confirm that the kernel is actually offloading the work.
Prerequisites
- Operating system: Linux kernel 3.18 or newer. Older kernels lack full eBPF support.
- Development tools:
- gcc, make, autoconf, automake, libtool
- kernel headers (e.g.,
apt install linux-headers-$(uname -r)) - libpcap development package (e.g.,
apt install libpcap-dev) – ensure version ≥ 1.9.
- Permissions: To capture on an interface you need root or the
CAP_NET_RAWcapability. Non‑privileged users can add this capability withsetcap CAP_NET_RAW+eip $(which npss)after installation.
Step 1 – Download and Prepare Npss
git clone https://github.com/example/npss.git
cd npss
./autogen.sh
Running ./autogen.sh generates the configure script and ensures all build dependencies are present.
Step 2 – Configure with BPF Support
./configure --enable-bpf
The --enable-bpf flag tells the build system to link against libpcap’s BPF API. If libpcap is missing or too old, configure will abort with a clear error message. Verify the output contains a line like:
Checking for libpcap BPF API… yes (libpcap 1.9.0)
Step 3 – Compile and Install
make -j$(nproc)
sudo make install
After installation, npss will reside in /usr/local/bin (or /usr/bin depending on your prefix). No state changes occur here, so no rollback is necessary.
Step 4 – Verify BPF is Enabled at Runtime
npss -v
Look for a line such as:
Feature summary: BPF support enabled
If the output says BPF support disabled or omits the line, the build did not link correctly.
Step 5 – Run a Filtered Capture
To confirm that the kernel is handling the filter, capture on eth0 with a simple rule and compare counts with tcpdump.
# Capture 100 HTTP packets with Npss
sudo npss -f "tcp port 80" -c 100 -i eth0 > /tmp/npss_http.log &
# In parallel, capture with tcpdump
sudo tcpdump -i eth0 port 80 -c 100 > /tmp/tcpdump_http.log &
After both commands finish, check the number of captured lines:
wc -l /tmp/npss_http.log
wc -l /tmp/tcpdump_http.log
The counts should match. If Npss captures fewer packets, it could be falling back to user‑space filtering, which may drop packets under load.
Step 6 – Inspect Kernel Logs for BPF Attachment
sudo dmesg | grep -i bpf
Successful BPF attachment typically logs a message like:
[ 1234.567890] npss: BPF program attached to interface eth0
Absence of such a message or error entries (e.g., cannot attach BPF program) indicates a problem that needs troubleshooting.
Fallback: User‑Space Filtering
If the kernel lacks eBPF support or libpcap is too old, the --enable-bpf flag will be ignored at build time. In that case, Npss will still start but will perform filtering in user space. You can detect this by running npss -v and looking for a line that reads User‑space filtering enabled. While functional, this mode consumes more CPU and may miss packets under high load.
Recovery Options
- Kernel upgrade: If you see BPF attachment errors, upgrade to a kernel ≥ 3.18 that includes eBPF support.
- Libpcap upgrade: Ensure you have libpcap 1.9 or newer. On Debian/Ubuntu,
apt install libpcap-devwill pull the latest version. - Rebuild: After updating dependencies, rerun
./configure --enable-bpfand rebuild. - Capability assignment: For non‑root users, add
CAP_NET_RAWcapability viasetcapto avoid permission failures.
Limitations and Practical Checks
- Some cloud providers disable BPF in their virtualized kernels. Test
cat /proc/sys/net/core/bpf_jit_enableto confirm JIT is active. - BPF does not support all libpcap filter syntax. Complex expressions may still be parsed but executed in user space.
- On very old kernels (pre‑3.18), BPF support is incomplete. In that case, the build will succeed but runtime filtering will degrade.
Conclusion
By following this guide you can confidently compile Npss with BPF, run filtered captures, and verify that the kernel is doing the heavy lifting. The same steps apply to any BPF‑enabled network sniffer that relies on libpcap.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.