What are meanings of fields in /proc/net/dev?

Viewed 38026

The Linux file /proc/net/dev reads like this:

[me@host ~]$ cat /proc/net/dev
Inter-|   Receive                                                |  Transmit
 face |bytes    packets errs drop fifo frame compressed multicast|bytes    packets errs drop fifo colls carrier compressed

What do fields drop and errs mean?

Are some errs packets also counted in the drop packets?

Why is a packet considered errs , is it because that it suffers from checksum error?

Why is a packet dropped? Is it because that the system has no enough buffer of because there is some burst on the NIC?

Do the two fields take packets that are destined to another host (e.g. when the NIC is working in promiscuous mode) into consider?

3 Answers

You can have a look at net/core/dev.c in the source tree to see what it means:

seq_printf(seq, "%6s:%8lu %7lu %4lu %4lu %4lu %5lu %10lu %9lu "
       "%8lu %7lu %4lu %4lu %4lu %5lu %7lu %10lu\n",
       dev->name,
       stats->rx_bytes,
       stats->rx_packets,
       stats->rx_errors,
       stats->rx_dropped + stats->rx_missed_errors,
       stats->rx_fifo_errors,
       stats->rx_length_errors + stats->rx_over_errors +
        stats->rx_crc_errors + stats->rx_frame_errors,
       stats->rx_compressed,
       stats->multicast,
       stats->tx_bytes,
       stats->tx_packets,
       stats->tx_errors,
       stats->tx_dropped,
       stats->tx_fifo_errors,
       stats->collisions,
       stats->tx_carrier_errors + stats->tx_aborted_errors +
        stats->tx_window_errors + stats->tx_heartbeat_errors,
       stats->tx_compressed);

So:

  • receive errors means any kind of invalid packet, e.g. invalid length or invalid checksum
  • transmit errors are
    • carrier errors
    • aborted errors
    • window errors
    • heartbeat errors
      (whatever they all mean)

And yes, I think drops means when the device dropped a packet because it ran out of buffer space.

Since noone has answered for almost six months, I feel free to speculate:

I don't think the errs and drops overlap. I also think that errs are checksum or other bad data in a received packet (i.e. not enough data to constitute a whole packet). Further, I believe drops only apply to outgoing packages - how would the system know about dropped packages somewhere else?

Related