Part 6 · 1 chapters · ~8 min

The Networking Stack

The receive path (DMA, ring buffers, NAPI, softirq, sk_buff, netfilter, TCP, socket buffers), the transmit path and qdiscs, RSS and multiple queues, socket buffer sizing and BDP, congestion control (CUBIC, BBR), conntrack limits, SO_REUSEPORT, XDP and eBPF, and the counters that show drops.

7

Receive, transmit, and where packets drop

code
ethtool -S eth0 | grep -i -E 'drop|miss'      # NIC ring drops
ethtool -g eth0                                # ring sizes (raise with -G)
cat /proc/net/softnet_stat                     # per-CPU: processed, dropped, time_squeeze
nstat -az | grep -E 'TcpExtListenOverflows|TcpExtListenDrops|TcpRetransSegs'
ss -tmi                                        # per-socket: cwnd, rtt, retransmits, buffer use
sysctl net.ipv4.tcp_congestion_control         # cubic (default) or bbr
sysctl net.core.somaxconn                      # cap on listen() backlog
cat /proc/sys/net/netfilter/nf_conntrack_count /proc/sys/net/netfilter/nf_conntrack_max   # full table = new connections dropped
symptomwhere to look
connection timeouts under loadListenOverflows (backlog full), conntrack table full
throughput below link speed on long pathssocket buffers smaller than bandwidth × RTT; try BBR
one CPU at 100% in softirqRSS spreading flows across queues and CPUs

XDP runs eBPF programs in the driver before an sk_buff is even allocated, which is how high-performance load balancers and DDoS filters (Cloudflare, Meta's Katran) drop or redirect packets at line rate.

A PACKET ARRIVES
from the wire to recv()
NICdriver (NAPI poll)IP / netfilterTCPsocket bufferapplicationDMA into ring buffer + interrupt
swipe the figure sideways, or tap expand for full screen
1/4
DMA and rings
The NIC writes packets into a ring buffer in memory by DMA and raises an interrupt. If the ring fills, packets are dropped (ethtool -S shows rx drops).
DMA into a ringfull ring = drops