同一网络Linux虚拟机中hping3 RTT远高于sockperf延迟的原因?
Great question! The gap comes down to fundamental differences in how these two tools operate across the network stack and their core design purposes. Let’s break it down clearly:
They’re testing entirely different TCP stages
Your hping3 command uses-S, which sends individual TCP SYN packets (the first step of a TCP handshake) and waits for SYN-ACK responses. Every single test packet triggers the target server’s kernel to handle a brand new connection request: checking if port 22 is open, creating a half-open connection entry, generating sequence numbers, and crafting a SYN-ACK reply. This adds heavy, per-packet connection setup overhead.
Sockperf’sping-pmode works differently: it first establishes a full, persistent TCP connection (completing the three-way handshake once upfront), then sends application-layer ping/pong messages over this already open pipe. There’s no repeated connection setup work here—just efficient data transfer over an existing, ready-to-use connection.Tool optimization priorities vary wildly
Hping3 is a general-purpose packet manipulation tool, not built for low-latency testing. It relies on raw sockets to construct and send packets, which means more frequent user-kernel mode switches and extra protocol processing overhead for every single packet.
Sockperf is purpose-built for measuring network latency and throughput. It uses optimized socket operations (likesendmsg/recvmsgfor streamlined data transfer), minimizes unnecessary context switches, and often enables TCP optimizations likeTCP_NODELAYby default to avoid Nagle’s algorithm delays—all choices that keep latency as low as possible.Kernel processing paths are night and day
When a SYN packet hits the target server’s kernel, it has to go through TCP’s full connection initialization logic: validating the packet, checking listen queues, generating SYN-ACK details, and managing half-open connections. This is a far heavier process than handling data on an established connection.
For sockperf’s tests, the server’s kernel simply passes incoming application data directly to the sockperf process, which immediately sends a response. The kernel’s workload here is minimal—no connection setup logic, just routing data between the network stack and the waiting application.The definition of "round-trip time" differs
Hping3’s RTT measures the time from when the client kernel sends a SYN packet to when it receives the SYN-ACK. This includes all the server’s kernel connection-handling overhead.
Sockperf’s latency measures the round-trip time from when the client application sends a ping message to when it gets the server application’s pong response. This skips the bulk of TCP connection setup work and focuses on the actual data transfer and lightweight application response.
内容的提问来源于stack exchange,提问作者Vikee

