Hello friends,
I am right now writing a small sniffer using lsf (linux socket filter).
The question of mine is this that if a bpfcode is attached to the
filter and then detached and reattached. The bettwen these the two
attach operations will the packest which were recvd by the kernel on
this socket will be filtered the new attached expression or not. Here
the packets I am referring to are the one’s which will be buffered on
the socket between the two attach operations.


