Part 6 · 1 chapters · ~8 min
The Networking Stack
The receive path (DMA, ring buffers, NAPI, softirq, sk_buff, netfilter, TCP, socket buffers), the transmit path and qdiscs, RSS and multiple queues, socket buffer sizing and BDP, congestion control (CUBIC, BBR), conntrack limits, SO_REUSEPORT, XDP and eBPF, and the counters that show drops.
7
Receive, transmit, and where packets drop
code
ethtool -S eth0 | grep -i -E 'drop|miss' # NIC ring drops ethtool -g eth0 # ring sizes (raise with -G) cat /proc/net/softnet_stat # per-CPU: processed, dropped, time_squeeze nstat -az | grep -E 'TcpExtListenOverflows|TcpExtListenDrops|TcpRetransSegs' ss -tmi # per-socket: cwnd, rtt, retransmits, buffer use sysctl net.ipv4.tcp_congestion_control # cubic (default) or bbr sysctl net.core.somaxconn # cap on listen() backlog cat /proc/sys/net/netfilter/nf_conntrack_count /proc/sys/net/netfilter/nf_conntrack_max # full table = new connections dropped
| symptom | where to look |
|---|---|
| connection timeouts under load | ListenOverflows (backlog full), conntrack table full |
| throughput below link speed on long paths | socket buffers smaller than bandwidth × RTT; try BBR |
| one CPU at 100% in softirq | RSS spreading flows across queues and CPUs |
XDP runs eBPF programs in the driver before an sk_buff is even allocated, which is how high-performance load balancers and DDoS filters (Cloudflare, Meta's Katran) drop or redirect packets at line rate.
A PACKET ARRIVES
from the wire to recv()
swipe the figure sideways, or tap expand for full screen
1/4
DMA and rings
The NIC writes packets into a ring buffer in memory by DMA and raises an interrupt. If the ring fills, packets are dropped (ethtool -S shows rx drops).
DMA into a ringfull ring = drops