Wireshark-users: Re: [Wireshark-users] Raw socket performance
From: "Bryan Hoyt | Brush Technology" <bryan@xxxxxxxxxxx>
Date: Sun, 4 Jul 2010 20:00:55 +1200
Depends on which process opens the socket first. The kernel copies 
incoming packets to these "taps" one at a time in sequence. Did you
try launching 'P' first before Wireshark?

No, actually. That's a very good point -- I'll try that.

The project's on hold for a bit, so I won't get a chance to look into it further just now, but I'll follow up on this when things move ahead.

- Bryan