From: Thomas Gleixner <tglx@xxxxxxxxxxxxx> Date: Fri, 18 Oct 2019 00:11:38 +0200 (CEST) > tcpdump and wireshark work perfectly fine on a BPF disabled kernel at least > in the limited way I am using them. Yes it works, but with every packet flowing through the system getting copied into userspace. This takes us back to 1992 :-)