/usr/share/systemtap/tapset/linux
NameSizeModeActions
arm/-0755rm
arm64/-0755rm
i386/-0755rm
ia64/-0755rm
mips/-0755rm
powerpc/-0755rm
riscv/-0755rm
s390/-0755rm
x86_64/-0755rm
atomic.stp15630644editdlrm
aux_syscalls.stp1517020644editdlrm
context-caller.stp31480644editdlrm
context-envvar.stp17610644editdlrm
context-symbols.stp122760644editdlrm
context-unwind.stp32830644editdlrm
context.stp190150644editdlrm
context.stpm1250644editdlrm
conversions-guru.stp58760644editdlrm
conversions.stp172730644editdlrm
ctime.stp57500644editdlrm
dentry.stp106670644editdlrm
dev.stp20740644editdlrm
endian.stp6020644editdlrm
errno.stpm570644editdlrm
guru-delay.stp12300644editdlrm
guru-signal.stp10920644editdlrm
inet.stp14560644editdlrm
inet.stpm3830644editdlrm
inet_sock.stp12820644editdlrm
ioblock.stp155970644editdlrm
ioscheduler.stp140980644editdlrm
ip.stp54830644editdlrm
ipmib-filter-default.stp9650644editdlrm
ipmib.stp129810644editdlrm
irq.stp51200644editdlrm
json.stp91940644editdlrm
json.stpm62560644editdlrm
kprocess.stp47500644editdlrm
kretprobe.stp21530644editdlrm
linuxmib-filter-default.stp8760644editdlrm
linuxmib.stp37180644editdlrm
loadavg.stp19950644editdlrm
logging.stp25850644editdlrm
memory.stp192190644editdlrm
netfilter.stp363560644editdlrm
networking.stp96560644editdlrm
nfs.stp389970644editdlrm
nfsd.stp473790644editdlrm
nfsderrno.stp119790644editdlrm
nfs_proc.stp583250644editdlrm
nfs_proc.stpm12880644editdlrm
panic.stp10920644editdlrm
perf.stp52840644editdlrm
proc_mem.stp127020644editdlrm
pstrace.stp7730644editdlrm
rcu.stp9280644editdlrm
rlimit.stp13820644editdlrm
rpc.stp385780644editdlrm
scheduler.stp116610644editdlrm
scsi.stp97210644editdlrm
signal.stp293710644editdlrm
socket.stp350240644editdlrm
syscalls.stpm146430644editdlrm
syscalls_cfg_trunc.stp1110644editdlrm
syscall_any.stp15600644editdlrm
syscall_table.stp14750644editdlrm
sysc_accept.stp78680644editdlrm
sysc_accept4.stp78640644editdlrm
sysc_access.stp29110644editdlrm
sysc_acct.stp25830644editdlrm
sysc_add_key.stp35320644editdlrm
sysc_adjtimex.stp56720644editdlrm
sysc_alarm.stp28330644editdlrm
sysc_bdflush.stp31130644editdlrm
sysc_bind.stp69650644editdlrm
sysc_bpf.stp27380644editdlrm
sysc_brk.stp26290644editdlrm
sysc_capget.stp31010644editdlrm
sysc_capset.stp31020644editdlrm
sysc_chdir.stp26160644editdlrm
sysc_chmod.stp29590644editdlrm
sysc_chown.stp37750644editdlrm
sysc_chown16.stp31150644editdlrm
sysc_chroot.stp26790644editdlrm
sysc_clock_adjtime.stp52430644editdlrm
sysc_clock_getres.stp42480644editdlrm
sysc_clock_gettime.stp40350644editdlrm
sysc_clock_nanosleep.stp80410644editdlrm
sysc_clock_settime.stp55540644editdlrm
sysc_clone.stp67080644editdlrm
sysc_close.stp27710644editdlrm
sysc_connect.stp74520644editdlrm
sysc_copy_file_range.stp37690644editdlrm
sysc_creat.stp27280644editdlrm
sysc_delete_module.stp33660644editdlrm
sysc_dup.stp23830644editdlrm
sysc_dup2.stp29910644editdlrm
sysc_dup3.stp30730644editdlrm
sysc_epoll_create.stp57420644editdlrm
sysc_epoll_ctl.stp39980644editdlrm
sysc_epoll_pwait.stp41570644editdlrm
sysc_epoll_wait.stp48500644editdlrm
sysc_eventfd.stp54110644editdlrm
sysc_execve.stp62570644editdlrm
sysc_execveat.stp69420644editdlrm
sysc_exit.stp19840644editdlrm
sysc_exit_group.stp21460644editdlrm
sysc_faccessat.stp37360644editdlrm
sysc_faccessat2.stp44340644editdlrm
sysc_fadvise64.stp86390644editdlrm
sysc_fallocate.stp39180644editdlrm
sysc_fanotify_init.stp34320644editdlrm
sysc_fanotify_mark.stp75720644editdlrm
sysc_fchdir.stp25250644editdlrm
sysc_fchmod.stp28800644editdlrm
sysc_fchmodat.stp37340644editdlrm
sysc_fchown.stp37220644editdlrm
sysc_fchown16.stp30230644editdlrm
sysc_fchownat.stp39030644editdlrm
sysc_fcntl.stp48060644editdlrm
sysc_fdatasync.stp26920644editdlrm
sysc_fgetxattr.stp37200644editdlrm
sysc_finit_module.stp33820644editdlrm
sysc_flistxattr.stp30000644editdlrm
sysc_flock.stp25790644editdlrm
sysc_fork.stp25860644editdlrm
sysc_fremovexattr.stp32290644editdlrm
sysc_fsetxattr.stp41870644editdlrm
sysc_fstat.stp61630644editdlrm
sysc_fstatat.stp57890644editdlrm
sysc_fstatfs.stp32660644editdlrm
sysc_fstatfs64.stp32400644editdlrm
sysc_fsync.stp24190644editdlrm
sysc_ftruncate.stp62120644editdlrm
sysc_futex.stp58100644editdlrm
sysc_futimesat.stp66390644editdlrm
sysc_getcpu.stp30340644editdlrm
sysc_getcwd.stp27470644editdlrm
sysc_getdents.stp56180644editdlrm
sysc_getegid.stp35420644editdlrm
sysc_geteuid.stp34840644editdlrm
sysc_getgid.stp34020644editdlrm
sysc_getgroups.stp42740644editdlrm
sysc_gethostname.stp12490644editdlrm
sysc_getitimer.stp53550644editdlrm
sysc_getpeername.stp75220644editdlrm
sysc_getpgid.stp28590644editdlrm
sysc_getpgrp.stp20900644editdlrm
sysc_getpid.stp20310644editdlrm
sysc_getppid.stp21120644editdlrm
sysc_getpriority.stp29430644editdlrm
sysc_getrandom.stp31840644editdlrm
sysc_getresgid.stp41720644editdlrm
sysc_getresuid.stp39720644editdlrm
sysc_getrlimit.stp44600644editdlrm
sysc_getrusage.stp38030644editdlrm
sysc_getsid.stp25090644editdlrm
sysc_getsockname.stp75500644editdlrm
sysc_getsockopt.stp85200644editdlrm
sysc_gettid.stp20570644editdlrm
sysc_gettimeofday.stp40780644editdlrm
sysc_getuid.stp34270644editdlrm
sysc_getxattr.stp38120644editdlrm
sysc_get_mempolicy.stp46710644editdlrm
sysc_get_robust_list.stp45720644editdlrm
sysc_init_module.stp32410644editdlrm
sysc_inotify_add_watch.stp38610644editdlrm
sysc_inotify_init.stp55480644editdlrm
sysc_inotify_rm_watch.stp32770644editdlrm
sysc_ioctl.stp35360644editdlrm
sysc_ioperm.stp28190644editdlrm
sysc_ioprio_get.stp30180644editdlrm
sysc_ioprio_set.stp32470644editdlrm
sysc_io_cancel.stp33180644editdlrm
sysc_io_destroy.stp28160644editdlrm
sysc_io_getevents.stp49940644editdlrm
sysc_io_setup.stp38380644editdlrm
sysc_io_submit.stp39830644editdlrm
sysc_kcmp.stp30070644editdlrm
sysc_kexec_file_load.stp40410644editdlrm
sysc_kexec_load.stp45130644editdlrm
sysc_keyctl.stp37220644editdlrm
sysc_kill.stp25910644editdlrm
sysc_lchown.stp38800644editdlrm
sysc_lchown16.stp31940644editdlrm
sysc_lgetxattr.stp39120644editdlrm
sysc_link.stp28850644editdlrm
sysc_linkat.stp40050644editdlrm
sysc_listen.stp66240644editdlrm
sysc_listxattr.stp33180644editdlrm
sysc_llistxattr.stp33790644editdlrm
sysc_llseek.stp33710644editdlrm
sysc_lookup_dcookie.stp40890644editdlrm
sysc_lremovexattr.stp40010644editdlrm
sysc_lseek.stp45000644editdlrm
sysc_lsetxattr.stp40970644editdlrm
sysc_lstat.stp64550644editdlrm
sysc_madvise.stp29760644editdlrm
sysc_mbind.stp43030644editdlrm
sysc_membarrier.stp30170644editdlrm
sysc_memfd_create.stp32470644editdlrm
sysc_memfd_secret.stp28150644editdlrm
sysc_migrate_pages.stp43740644editdlrm
sysc_mincore.stp29000644editdlrm
sysc_mkdir.stp28970644editdlrm
sysc_mkdirat.stp34450644editdlrm
sysc_mknod.stp29580644editdlrm
sysc_mknodat.stp36440644editdlrm
sysc_mlock.stp26180644editdlrm
sysc_mlock2.stp28820644editdlrm
sysc_mlockall.stp27710644editdlrm
sysc_mmap2.stp62290644editdlrm
sysc_modify_ldt.stp31120644editdlrm
sysc_mount.stp44990644editdlrm
sysc_move_pages.stp47250644editdlrm
sysc_mprotect.stp29660644editdlrm
sysc_mq_getsetattr.stp44600644editdlrm
sysc_mq_notify.stp39360644editdlrm
sysc_mq_open.stp53850644editdlrm
sysc_mq_timedreceive.stp61830644editdlrm
sysc_mq_timedsend.stp59280644editdlrm
sysc_mq_unlink.stp30180644editdlrm
sysc_mremap.stp35770644editdlrm
sysc_msgctl.stp82550644editdlrm
sysc_msgget.stp44230644editdlrm
sysc_msgrcv.stp106890644editdlrm
sysc_msgsnd.stp88660644editdlrm
sysc_msync.stp28510644editdlrm
sysc_munlock.stp27440644editdlrm
sysc_munlockall.stp23420644editdlrm
sysc_munmap.stp27090644editdlrm
sysc_name_to_handle_at.stp41500644editdlrm
sysc_nanosleep.stp58240644editdlrm
sysc_nfsservctl.stp22840644editdlrm
sysc_nice.stp24400644editdlrm
sysc_ni_syscall.stp14330644editdlrm
sysc_open.stp43290644editdlrm
sysc_openat.stp39160644editdlrm
sysc_open_by_handle_at.stp42980644editdlrm
sysc_pause.stp25640644editdlrm
sysc_perf_event_open.stp38080644editdlrm
sysc_personality.stp30770644editdlrm
sysc_pipe.stp105960644editdlrm
sysc_pivot_root.stp33140644editdlrm
sysc_pkey_alloc.stp30570644editdlrm
sysc_pkey_free.stp27190644editdlrm
sysc_pkey_mprotect.stp33920644editdlrm
sysc_poll.stp27690644editdlrm
sysc_ppoll.stp64930644editdlrm
sysc_prctl.stp29930644editdlrm
sysc_pread.stp54270644editdlrm
sysc_preadv.stp52830644editdlrm
sysc_preadv2.stp56670644editdlrm
sysc_prlimit64.stp34950644editdlrm
sysc_process_vm_readv.stp47750644editdlrm
sysc_process_vm_writev.stp48970644editdlrm
sysc_pselect6.stp64570644editdlrm
sysc_pselect7.stp36680644editdlrm
sysc_ptrace.stp36610644editdlrm
sysc_pwrite.stp72390644editdlrm
sysc_pwritev.stp54140644editdlrm
sysc_pwritev2.stp57740644editdlrm
sysc_quotactl.stp46910644editdlrm
sysc_read.stp37210644editdlrm
sysc_readahead.stp36010644editdlrm
sysc_readdir.stp40430644editdlrm
sysc_readlink.stp31140644editdlrm
sysc_readlinkat.stp38330644editdlrm
sysc_readv.stp35020644editdlrm
sysc_reboot.stp32530644editdlrm
sysc_recv.stp72600644editdlrm
sysc_recvfrom.stp85540644editdlrm
sysc_recvmmsg.stp64620644editdlrm
sysc_recvmsg.stp109620644editdlrm
sysc_remap_file_pages.stp39350644editdlrm
sysc_removexattr.stp33200644editdlrm
sysc_rename.stp30380644editdlrm
sysc_renameat.stp41910644editdlrm
sysc_renameat2.stp45000644editdlrm
sysc_request_key.stp41380644editdlrm
sysc_restart_syscall.stp25650644editdlrm
sysc_rmdir.stp26570644editdlrm
sysc_rt_sigaction.stp69520644editdlrm
sysc_rt_sigpending.stp47990644editdlrm
sysc_rt_sigprocmask.stp91050644editdlrm
sysc_rt_sigqueueinfo.stp47500644editdlrm
sysc_rt_sigreturn.stp16390644editdlrm
sysc_rt_sigsuspend.stp38790644editdlrm
sysc_rt_sigtimedwait.stp60240644editdlrm
sysc_rt_tgsigqueueinfo.stp44600644editdlrm
sysc_sched_getaffinity.stp41020644editdlrm
sysc_sched_getattr.stp36710644editdlrm
sysc_sched_getparam.stp32360644editdlrm
sysc_sched_getscheduler.stp32960644editdlrm
sysc_sched_get_priority_max.stp36400644editdlrm
sysc_sched_get_priority_min.stp36400644editdlrm
sysc_sched_rr_get_interval.stp48640644editdlrm
sysc_sched_setaffinity.stp39600644editdlrm
sysc_sched_setattr.stp34450644editdlrm
sysc_sched_setparam.stp32210644editdlrm
sysc_sched_setscheduler.stp36660644editdlrm
sysc_sched_yield.stp23150644editdlrm
sysc_seccomp.stp33650644editdlrm
sysc_select.stp63590644editdlrm
sysc_semctl.stp82060644editdlrm
sysc_semget.stp45960644editdlrm
sysc_semop.stp57700644editdlrm
sysc_semtimedop.stp99360644editdlrm
sysc_send.stp73690644editdlrm
sysc_sendfile.stp49120644editdlrm
sysc_sendmmsg.stp93050644editdlrm
sysc_sendmsg.stp121100644editdlrm
sysc_sendto.stp83570644editdlrm
sysc_setdomainname.stp37290644editdlrm
sysc_setfsgid.stp47960644editdlrm
sysc_setfsuid.stp48390644editdlrm
sysc_setgid.stp45730644editdlrm
sysc_setgroups.stp45190644editdlrm
sysc_sethostname.stp32740644editdlrm
sysc_setitimer.stp62860644editdlrm
sysc_setns.stp28040644editdlrm
sysc_setpgid.stp27600644editdlrm
sysc_setpriority.stp32180644editdlrm
sysc_setregid.stp66600644editdlrm
sysc_setresgid.stp70400644editdlrm
sysc_setresuid.stp70550644editdlrm
sysc_setreuid.stp66300644editdlrm
sysc_setrlimit.stp40300644editdlrm
sysc_setsid.stp21010644editdlrm
sysc_setsockopt.stp84440644editdlrm
sysc_settimeofday.stp66460644editdlrm
sysc_setuid.stp45720644editdlrm
sysc_setxattr.stp39930644editdlrm
sysc_set_mempolicy.stp41710644editdlrm
sysc_set_robust_list.stp43580644editdlrm
sysc_set_tid_address.stp31950644editdlrm
sysc_sgetmask.stp21690644editdlrm
sysc_shmat.stp67770644editdlrm
sysc_shmctl.stp81390644editdlrm
sysc_shmdt.stp39820644editdlrm
sysc_shmget.stp45010644editdlrm
sysc_shutdown.stp69090644editdlrm
sysc_sigaction.stp57820644editdlrm
sysc_sigaltstack.stp42670644editdlrm
sysc_signal.stp28670644editdlrm
sysc_signalfd.stp124640644editdlrm
sysc_sigpending.stp37120644editdlrm
sysc_sigprocmask.stp41720644editdlrm
sysc_sigreturn.stp14610644editdlrm
sysc_sigsuspend.stp45750644editdlrm
sysc_socket.stp74380644editdlrm
sysc_socketpair.stp82970644editdlrm
sysc_splice.stp33630644editdlrm
sysc_ssetmask.stp28100644editdlrm
sysc_stat.stp65350644editdlrm
sysc_statfs.stp34910644editdlrm
sysc_statfs64.stp34590644editdlrm
sysc_statx.stp41180644editdlrm
sysc_stime.stp30830644editdlrm
sysc_swapoff.stp28750644editdlrm
sysc_swapon.stp31210644editdlrm
sysc_symlink.stp30280644editdlrm
sysc_symlinkat.stp40600644editdlrm
sysc_sync.stp19250644editdlrm
sysc_syncfs.stp25710644editdlrm
sysc_sync_file_range.stp60110644editdlrm
sysc_sysctl.stp30950644editdlrm
sysc_sysfs.stp36480644editdlrm
sysc_sysinfo.stp32860644editdlrm
sysc_syslog.stp28260644editdlrm
sysc_tee.stp27430644editdlrm
sysc_tgkill.stp28830644editdlrm
sysc_time.stp35050644editdlrm
sysc_timerfd.stp18290644editdlrm
sysc_timerfd_create.stp33940644editdlrm
sysc_timerfd_gettime.stp42190644editdlrm
sysc_timerfd_settime.stp52820644editdlrm
sysc_timer_create.stp49750644editdlrm
sysc_timer_delete.stp29420644editdlrm
sysc_timer_getoverrun.stp32070644editdlrm
sysc_timer_gettime.stp46700644editdlrm
sysc_timer_settime.stp60750644editdlrm
sysc_times.stp31670644editdlrm
sysc_tkill.stp26950644editdlrm
sysc_truncate.stp70310644editdlrm
sysc_tux.stp10680644editdlrm
sysc_umask.stp25220644editdlrm
sysc_umount.stp53600644editdlrm
sysc_uname.stp51450644editdlrm
sysc_unlink.stp28660644editdlrm
sysc_unlinkat.stp33800644editdlrm
sysc_unshare.stp28140644editdlrm
sysc_uselib.stp28710644editdlrm
sysc_userfaultfd.stp30050644editdlrm
sysc_ustat.stp53330644editdlrm
sysc_utime.stp61730644editdlrm
sysc_utimensat.stp70440644editdlrm
sysc_utimes.stp63310644editdlrm
sysc_vfork.stp20290644editdlrm
sysc_vhangup.stp21280644editdlrm
sysc_vmsplice.stp63370644editdlrm
sysc_wait4.stp50970644editdlrm
sysc_waitid.stp42530644editdlrm
sysc_waitpid.stp34600644editdlrm
sysc_write.stp39390644editdlrm
sysc_writev.stp36560644editdlrm
target_set.stp17690644editdlrm
task.stp228800644editdlrm
task.stpm2530644editdlrm
task_ancestry.stp16210644editdlrm
task_time.stp78610644editdlrm
tcp.stp226420644editdlrm
tcpmib-filter-default.stp8850644editdlrm
tcpmib.stp108240644editdlrm
timestamp.stp17610644editdlrm
timestamp_gtod.stp16290644editdlrm
timestamp_monotonic.stp55890644editdlrm
tty.stp73510644editdlrm
tzinfo.stp8030644editdlrm
ucontext-symbols.stp88420644editdlrm
ucontext-unwind.stp76450644editdlrm
ucontext.stp22370644editdlrm
udp.stp60970644editdlrm
utrace.stp13630644editdlrm
vfs.stp338260644editdlrm
Edit: /usr/share/systemtap/tapset/linux/netfilter.stp (36356B)
/* netfilter.stp - netfilter hook tapset * * Copyright (C) 2012, 2017-2018 Red Hat Inc. * * This family of probe points provides a simple way to examine network traffic using the netfilter hooks mechanism. * */ // See the BZ1546179 block comment in tapset/linux/networking.stp for // an explanation of the try/catch statements around sk_buff structure // accesses. /* The below functionality is mostly inspired by tcp.stp and networking.stp. */ %{ #include #include #include #include #include #include #include %} # XXX: IPPROTO_* and NF_* constants should be secure globals -- needs PR10607 # ... currently we use a hideous copypasta hack which defines them as # locals in each probe alias. Blegh @__private30 function __mac_addr_to_string:string(addr:long) { return sprintf("%02x:%02x:%02x:%02x:%02x:%02x", kernel_char(addr)&255, kernel_char(addr+1)&255, kernel_char(addr+2)&255, kernel_char(addr+3)&255, kernel_char(addr+4)&255, kernel_char(addr+5)&255) } @__private30 function __get_mac_addr:string(addr:long) { return __mac_addr_to_string(@cast(addr, "struct net_device", "kernel")->dev_addr) } @__private30 function __get_skb_arphdr:long(addr:long) { // The method is exactly the same as for an IP header: return __get_skb_iphdr(addr) } /* returns the bridge header for kernel >= 2.6.21 */ @__private30 function __get_skb_brhdr_new:long(skb:long) %{ /* pure */ struct sk_buff *skb; skb = (struct sk_buff *)(uintptr_t)STAP_ARG_skb; /* as done by skb_network_header() */ #ifdef NET_SKBUFF_DATA_USES_OFFSET STAP_RETVALUE = (long)(kread(&(skb->head)) + kread(&(skb->network_header)) + sizeof(struct llc_pdu_un)); #else STAP_RETVALUE = (long)(kread(&(skb->network_header)) + sizeof(struct llc_pdu_un)); #endif CATCH_DEREF_FAULT(); %} /* returns the bridge header for a given sk_buff structure */ @__private30 function __get_skb_brhdr:long(skb:long) { %( kernel_v < "2.6.21" %? brhdr = @cast(skb, "sk_buff")->mac->raw + %{ /* pure */ sizeof(struct llc_pdu_un) %} return brhdr %: return __get_skb_brhdr_new(skb) %) } /* returns llc_pdu_un for a given sk_buff structure */ @__private30 function __get_skb_llc:long(skb:long) %{ /* pure */ struct sk_buff *skb; skb = (struct sk_buff *)(uintptr_t)STAP_ARG_skb; /* as done by skb_network_header() */ #ifdef NET_SKBUFF_DATA_USES_OFFSET STAP_RETVALUE = (long)(kread(&(skb->head)) + kread(&(skb->network_header))); #else STAP_RETVALUE = (long)kread(&(skb->network_header)); #endif CATCH_DEREF_FAULT(); %} @__private30 function __ip6_skb_proto:long(addr:long) %{ /* pure */ struct sk_buff *skb = (struct sk_buff *)(uintptr_t)STAP_ARG_addr; struct ipv6hdr *hdr; u8 nexthdr; /* We call deref() here to ensure the memory at the skb location * is valid to read, to avoid potential kernel panic calling ipv6_hdr(). */ (void)kderef_buffer(NULL, skb, sizeof(struct sk_buff)); hdr = ipv6_hdr(skb); nexthdr = kread(&(hdr->nexthdr)); if (ipv6_ext_hdr(nexthdr)) { #if LINUX_VERSION_CODE < KERNEL_VERSION(3,3,0) long result = ipv6_skip_exthdr(skb, sizeof(*hdr), &nexthdr); #else __be16 frag_offp; int extoff = (u8 *)(hdr + 1) - kread(&(skb->data)); long result = ipv6_skip_exthdr(skb, extoff, &nexthdr, &frag_offp); #endif STAP_RETVALUE = result < 0 ? 0 : result; } else { STAP_RETVALUE = 0; } CATCH_DEREF_FAULT(); %} private function __skb_nonlinear:long(addr:long) %{ /* pure */ struct sk_buff *skb = (struct sk_buff *)(uintptr_t)STAP_ARG_addr; STAP_RETVALUE = skb_is_nonlinear(skb); %} private function __skb_shinfo:long(addr:long) %{ /* pure */ struct sk_buff *skb = (struct sk_buff *)(uintptr_t)STAP_ARG_addr; STAP_RETVALUE = (uintptr_t)skb_end_pointer(skb); %} private function __skb_frag_size:long(addr:long, frag:long) %{ /* pure */ struct skb_shared_info *skb_shr = (struct skb_shared_info *)(uintptr_t)STAP_ARG_addr; skb_frag_t *skb_frag = &(skb_shr->frags[STAP_ARG_frag]); STAP_RETVALUE = skb_frag_size(skb_frag); %} private function __skb_frag_data_addr:long(addr:long, frag:long) %{ /* pure */ struct skb_shared_info *skb_shr = (struct skb_shared_info *)(uintptr_t)STAP_ARG_addr; const skb_frag_t *skb_frag = &skb_shr->frags[STAP_ARG_frag]; STAP_RETVALUE = (uintptr_t)skb_frag_address_safe(skb_frag); %} private function __buffer_data:string(skb:long, str:long) { length = @cast(skb, "struct sk_buff", "kernel")->len data_length = @cast(skb, "struct sk_buff", "kernel")->data_len skb_data = @cast(skb, "struct sk_buff", "kernel")->data headlen = length - data_length /* skb_headlen() */ data = "" if (str) { data = kernel_buffer_quoted(skb_data, headlen) } else { data = sprintf("%.*M", headlen, skb_data) } if (__skb_nonlinear(skb)) { shinfo = __skb_shinfo(skb) nr_frags = @cast(shinfo, "struct skb_shared_info", "kernel")->nr_frags for (i = 0; i < nr_frags; i++) { frag_size = __skb_frag_size(shinfo, i) frag_data_addr = __skb_frag_data_addr(shinfo, i) if (str) { data .= kernel_buffer_quoted(frag_data_addr, frag_size) } else { data .= sprintf("%.*M", frag_size, frag_data_addr) } } } return data } @define netfilter_common_setup(pf_name) %( pf = @pf_name /* XXX not relevant for netfilter.arp & netfilter.bridge probes */ ipproto_tcp = @const("IPPROTO_TCP") ipproto_udp = @const("IPPROTO_UDP") /* from include/linux/netfilter.h: */ nf_drop = 0 nf_accept = 1 nf_stolen = 2 nf_queue = 3 nf_repeat = 4 nf_stop = 5 indev = & @cast($in, "struct net_device", "kernel") outdev = & @cast($out, "struct net_device", "kernel") indev_name = kernel_string(indev->name, "") outdev_name = kernel_string(outdev->name, "") if (indev) { indev_mac_len = indev->addr_len in_mac = __get_mac_addr(indev) } if (outdev) { outdev_mac_len = outdev->addr_len out_mac = __get_mac_addr(outdev) } try { length = @cast($skb, "struct sk_buff", "kernel")->len } catch { } try { data_hex = __buffer_data($skb, 0) } catch { } try { data_str = __buffer_data($skb, 1) } catch { } %) @define netfilter_ip4_setup %( family = @const("AF_INET") try { iphdr = __get_skb_iphdr($skb) saddr = format_ipaddr(__ip_skb_saddr(iphdr), @const("AF_INET")) daddr = format_ipaddr(__ip_skb_daddr(iphdr), @const("AF_INET")) protocol = __ip_skb_proto(iphdr) } catch { } try { tcphdr = __get_skb_tcphdr($skb) if (protocol == ipproto_tcp) { dport = __tcp_skb_dport(tcphdr) sport = __tcp_skb_sport(tcphdr) urg = __tcp_skb_urg(tcphdr) ack = __tcp_skb_ack(tcphdr) psh = __tcp_skb_psh(tcphdr) rst = __tcp_skb_rst(tcphdr) syn = __tcp_skb_syn(tcphdr) fin = __tcp_skb_fin(tcphdr) } /* udphdr is in the same place where tcphdr would have been */ udphdr = & @cast(tcphdr, "udphdr", "kernel") if (protocol == ipproto_udp) { dport = ntohs(udphdr->dest) sport = ntohs(udphdr->source) } } catch { } %) @define netfilter_ip6_setup %( family = @const("AF_INET6") try { iphdr = &@cast(__get_skb_iphdr($skb), "ipv6hdr", "kernel") saddr = format_ipaddr(&iphdr->saddr, @const("AF_INET6")) daddr = format_ipaddr(&iphdr->daddr, @const("AF_INET6")) protocol = __ip6_skb_proto($skb) } catch { } try { tcphdr = __get_skb_tcphdr($skb) if (protocol == ipproto_tcp) { dport = __tcp_skb_dport(tcphdr) sport = __tcp_skb_sport(tcphdr) urg = __tcp_skb_urg(tcphdr) ack = __tcp_skb_ack(tcphdr) psh = __tcp_skb_psh(tcphdr) rst = __tcp_skb_rst(tcphdr) syn = __tcp_skb_syn(tcphdr) fin = __tcp_skb_fin(tcphdr) } /* udphdr is in the same place where tcphdr would have been */ udphdr = & @cast(tcphdr, "udphdr", "kernel") if (protocol == ipproto_udp) { dport = ntohs(udphdr->dest) sport = ntohs(udphdr->source) } } catch { } %) /** * probe netfilter.ip.pre_routing - Called before an IP packet is routed * @pf: Protocol family - either 'ipv4' or 'ipv6' * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @iphdr: Address of IP header * @protocol: Packet protocol from driver (ipv4 only) * @ipproto_tcp: Constant used to signify that the packet protocol is TCP * @ipproto_udp: Constant used to signify that the packet protocol is UDP * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP or UDP source port (ipv4 only) * @dport: TCP or UDP destination port (ipv4 only) * @urg: TCP URG flag (if protocol is TCP; ipv4 only) * @ack: TCP ACK flag (if protocol is TCP; ipv4 only) * @psh: TCP PSH flag (if protocol is TCP; ipv4 only) * @rst: TCP RST flag (if protocol is TCP; ipv4 only) * @syn: TCP SYN flag (if protocol is TCP; ipv4 only) * @fin: TCP FIN flag (if protocol is TCP; ipv4 only) */ probe netfilter.ip.pre_routing = netfilter.ipv4.pre_routing, netfilter.ipv6.pre_routing { } probe netfilter.ipv4.pre_routing = netfilter.hook("NF_INET_PRE_ROUTING").pf("NFPROTO_IPV4") { @netfilter_common_setup("ipv4") @netfilter_ip4_setup } probe netfilter.ipv6.pre_routing = netfilter.hook("NF_IP6_PRE_ROUTING").pf("NFPROTO_IPV6") { @netfilter_common_setup("ipv6") @netfilter_ip6_setup } /** * probe netfilter.ip.local_in - Called on an incoming IP packet addressed to the local computer * @pf: Protocol family -- either "ipv4" or "ipv6" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @iphdr: Address of IP header * @protocol: Packet protocol from driver (ipv4 only) * @ipproto_tcp: Constant used to signify that the packet protocol is TCP * @ipproto_udp: Constant used to signify that the packet protocol is UDP * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP or UDP source port (ipv4 only) * @dport: TCP or UDP destination port (ipv4 only) * @urg: TCP URG flag (if protocol is TCP; ipv4 only) * @ack: TCP ACK flag (if protocol is TCP; ipv4 only) * @psh: TCP PSH flag (if protocol is TCP; ipv4 only) * @rst: TCP RST flag (if protocol is TCP; ipv4 only) * @syn: TCP SYN flag (if protocol is TCP; ipv4 only) * @fin: TCP FIN flag (if protocol is TCP; ipv4 only) */ probe netfilter.ip.local_in = netfilter.ipv4.local_in, netfilter.ipv6.local_in { } probe netfilter.ipv4.local_in = netfilter.hook("NF_INET_LOCAL_IN").pf("NFPROTO_IPV4") { @netfilter_common_setup("ipv4") @netfilter_ip4_setup } probe netfilter.ipv6.local_in = netfilter.hook("NF_IP6_LOCAL_IN").pf("NFPROTO_IPV6") { @netfilter_common_setup("ipv6") @netfilter_ip6_setup } /** * probe netfilter.ip.forward - Called on an incoming IP packet addressed to some other computer * @pf: Protocol family -- either "ipv4" or "ipv6" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @iphdr: Address of IP header * @protocol: Packet protocol from driver (ipv4 only) * @ipproto_tcp: Constant used to signify that the packet protocol is TCP * @ipproto_udp: Constant used to signify that the packet protocol is UDP * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP or UDP source port (ipv4 only) * @dport: TCP or UDP destination port (ipv4 only) * @urg: TCP URG flag (if protocol is TCP; ipv4 only) * @ack: TCP ACK flag (if protocol is TCP; ipv4 only) * @psh: TCP PSH flag (if protocol is TCP; ipv4 only) * @rst: TCP RST flag (if protocol is TCP; ipv4 only) * @syn: TCP SYN flag (if protocol is TCP; ipv4 only) * @fin: TCP FIN flag (if protocol is TCP; ipv4 only) */ probe netfilter.ip.forward = netfilter.ipv4.forward, netfilter.ipv6.forward { } probe netfilter.ipv4.forward = netfilter.hook("NF_INET_FORWARD").pf("NFPROTO_IPV4") { @netfilter_common_setup("ipv4") @netfilter_ip4_setup } probe netfilter.ipv6.forward = netfilter.hook("NF_IP6_FORWARD").pf("NFPROTO_IPV6") { @netfilter_common_setup("ipv6") @netfilter_ip6_setup } /** * probe netfilter.ip.local_out - Called on an outgoing IP packet * @pf: Protocol family -- either "ipv4" or "ipv6" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @iphdr: Address of IP header * @protocol: Packet protocol from driver (ipv4 only) * @ipproto_tcp: Constant used to signify that the packet protocol is TCP * @ipproto_udp: Constant used to signify that the packet protocol is UDP * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP or UDP source port (ipv4 only) * @dport: TCP or UDP destination port (ipv4 only) * @urg: TCP URG flag (if protocol is TCP; ipv4 only) * @ack: TCP ACK flag (if protocol is TCP; ipv4 only) * @psh: TCP PSH flag (if protocol is TCP; ipv4 only) * @rst: TCP RST flag (if protocol is TCP; ipv4 only) * @syn: TCP SYN flag (if protocol is TCP; ipv4 only) * @fin: TCP FIN flag (if protocol is TCP; ipv4 only) */ probe netfilter.ip.local_out = netfilter.ipv4.local_out, netfilter.ipv6.local_out { } probe netfilter.ipv4.local_out = netfilter.hook("NF_INET_LOCAL_OUT").pf("NFPROTO_IPV4") { @netfilter_common_setup("ipv4") @netfilter_ip4_setup } probe netfilter.ipv6.local_out = netfilter.hook("NF_IP6_LOCAL_OUT").pf("NFPROTO_IPV6") { @netfilter_common_setup("ipv6") @netfilter_ip6_setup } /** * probe netfilter.ip.post_routing - Called immediately before an outgoing IP packet leaves the computer * @pf: Protocol family -- either "ipv4" or "ipv6" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @iphdr: Address of IP header * @protocol: Packet protocol from driver (ipv4 only) * @ipproto_tcp: Constant used to signify that the packet protocol is TCP * @ipproto_udp: Constant used to signify that the packet protocol is UDP * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP or UDP source port (ipv4 only) * @dport: TCP or UDP destination port (ipv4 only) * @urg: TCP URG flag (if protocol is TCP; ipv4 only) * @ack: TCP ACK flag (if protocol is TCP; ipv4 only) * @psh: TCP PSH flag (if protocol is TCP; ipv4 only) * @rst: TCP RST flag (if protocol is TCP; ipv4 only) * @syn: TCP SYN flag (if protocol is TCP; ipv4 only) * @fin: TCP FIN flag (if protocol is TCP; ipv4 only) */ probe netfilter.ip.post_routing = netfilter.ipv4.post_routing, netfilter.ipv6.local_out { } probe netfilter.ipv4.post_routing = netfilter.hook("NF_INET_POST_ROUTING").pf("NFPROTO_IPV4") { @netfilter_common_setup("ipv4") @netfilter_ip4_setup } probe netfilter.ipv6.post_routing = netfilter.hook("NF_IP6_POST_ROUTING").pf("NFPROTO_IPV6") { @netfilter_common_setup("ipv6") @netfilter_ip6_setup } @define netfilter_arp_setup %( # XXX: include functionality to parse ARP packet contents try { arphdr = & @cast(__get_skb_arphdr($skb), "struct arphdr", "kernel") family = @const("NF_ARP") // from linux/netfilter_arp.h ar_hrd = ntohs(arphdr->ar_hrd) ar_pro = ntohs(arphdr->ar_pro) ar_hln = arphdr->ar_hln ar_pln = arphdr->ar_pln ar_op = ntohs(arphdr->ar_op) } catch { } ar_data = arphdr + 8 if (ar_hrd == 0x001 && ar_pro == 0x800) { /* additional info available for most common (Ethernet+IP) case: */ ar_sha = __mac_addr_to_string(ar_data) ar_sip = format_ipaddr(kernel_int(ar_data + 6), @const("AF_INET")) ar_tha = __mac_addr_to_string(ar_data + 10) ar_tip = format_ipaddr(kernel_int(ar_data + 16), @const("AF_INET")) } /* XXX support for additional cases? */ %) /** * probe netfilter.arp.in -- Called for each incoming ARP packet * @pf: Protocol family -- always "arp" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @arphdr: Address of ARP header * @ar_hrd: Format of hardware address * @ar_pro: Format of protocol address * @ar_hln: Length of hardware address * @ar_pln: Length of protocol address * @ar_op: ARP opcode (command) * @ar_data: Address of ARP packet data region (after the header) * @ar_sha: Ethernet+IP only (ar_pro==0x800): source hardware (MAC) address * @ar_sip: Ethernet+IP only (ar_pro==0x800): source IP address * @ar_tha: Ethernet+IP only (ar_pro==0x800): target hardware (MAC) address * @ar_tip: Ethernet+IP only (ar_pro==0x800): target IP address * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.arp.in = netfilter.hook("NF_ARP_IN").pf("NFPROTO_ARP") { @netfilter_common_setup("arp") @netfilter_arp_setup } /** * probe netfilter.arp.out -- Called for each outgoing ARP packet * @pf: Protocol family -- always "arp" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @arphdr: Address of ARP header * @ar_hrd: Format of hardware address * @ar_pro: Format of protocol address * @ar_hln: Length of hardware address * @ar_pln: Length of protocol address * @ar_op: ARP opcode (command) * @ar_data: Address of ARP packet data region (after the header) * @ar_sha: Ethernet+IP only (ar_pro==0x800): source hardware (MAC) address * @ar_sip: Ethernet+IP only (ar_pro==0x800): source IP address * @ar_tha: Ethernet+IP only (ar_pro==0x800): target hardware (MAC) address * @ar_tip: Ethernet+IP only (ar_pro==0x800): target IP address * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.arp.out = netfilter.hook("NF_ARP_OUT").pf("NFPROTO_ARP") { @netfilter_common_setup("arp") @netfilter_arp_setup } /** * probe netfilter.arp.forward -- Called for each ARP packet to be forwarded * @pf: Protocol family -- always "arp" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @arphdr: Address of ARP header * @ar_hrd: Format of hardware address * @ar_pro: Format of protocol address * @ar_hln: Length of hardware address * @ar_pln: Length of protocol address * @ar_op: ARP opcode (command) * @ar_data: Address of ARP packet data region (after the header) * @ar_sha: Ethernet+IP only (ar_pro==0x800): source hardware (MAC) address * @ar_sip: Ethernet+IP only (ar_pro==0x800): source IP address * @ar_tha: Ethernet+IP only (ar_pro==0x800): target hardware (MAC) address * @ar_tip: Ethernet+IP only (ar_pro==0x800): target IP address * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.arp.forward = netfilter.hook("NF_ARP_FORWARD").pf("NFPROTO_ARP") { @netfilter_common_setup("arp") @netfilter_arp_setup } @define netfilter_bridge_setup %( try { llcpdu = &@cast(__get_skb_llc($skb), "struct llc_pdu_un", "kernel") brhdr = __get_skb_brhdr($skb) } catch { } llcproto_stp = @const("LLC_SAP_BSPAN") // from linux/llc.h if (llcpdu->dsap == llcproto_stp && llcpdu->ssap == llcproto_stp) { protocol = llcproto_stp br_prid = ntohs(kernel_short(brhdr)) br_vid = kernel_char(brhdr + 2) br_type = kernel_char(brhdr + 3) br_flags = kernel_char(brhdr + 4) br_rid = kernel_long(brhdr + 5) br_rmac = __mac_addr_to_string(brhdr + 7) br_cost = ntohl(kernel_int(brhdr + 13)) br_bid = kernel_long(brhdr + 17) br_mac = __mac_addr_to_string(brhdr + 19) br_poid = ntohs(kernel_short(brhdr + 25)) br_msg = ntohs(kernel_short(brhdr + 27)) br_max = ntohs(kernel_short(brhdr + 29)) br_htime = ntohs(kernel_short(brhdr + 31)) br_fd = ntohs(kernel_short(brhdr + 33)) } %) /** * probe netfilter.bridge.pre_routing -- Called before a bridging packet is routed * @pf: Protocol family -- always "bridge" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @llcpdu: Address of LLC Protocol Data Unit * @brhdr: Address of bridge header * @llcproto_stp: Constant used to signify Bridge Spanning Tree Protocol packet * @protocol: Packet protocol * @br_prid: Protocol identifier * @br_vid: Protocol version identifier * @br_type: BPDU type * @br_flags: BPDU flags * @br_rid: Identity of root bridge * @br_rmac: Root bridge MAC address * @br_cost: Total cost from transmitting bridge to root * @br_bid: Identity of bridge * @br_mac: Bridge MAC address * @br_poid: Port identifier * @br_msg: Message age in 1/256 secs * @br_max: Max age in 1/256 secs * @br_htime: Hello time in 1/256 secs * @br_fd: Forward delay in 1/256 secs * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.bridge.pre_routing = netfilter.hook("NF_BR_PRE_ROUTING").pf("NFPROTO_BRIDGE") { @netfilter_common_setup("bridge") @netfilter_bridge_setup } /** * probe netfilter.bridge.local_in - Called on a bridging packet destined for the local computer * @pf: Protocol family -- always "bridge" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @llcpdu: Address of LLC Protocol Data Unit * @brhdr: Address of bridge header * @llcproto_stp: Constant used to signify Bridge Spanning Tree Protocol packet * @protocol: Packet protocol * @br_prid: Protocol identifier * @br_vid: Protocol version identifier * @br_type: BPDU type * @br_flags: BPDU flags * @br_rid: Identity of root bridge * @br_rmac: Root bridge MAC address * @br_cost: Total cost from transmitting bridge to root * @br_bid: Identity of bridge * @br_mac: Bridge MAC address * @br_poid: Port identifier * @br_msg: Message age in 1/256 secs * @br_max: Max age in 1/256 secs * @br_htime: Hello time in 1/256 secs * @br_fd: Forward delay in 1/256 secs * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.bridge.local_in = netfilter.hook("NF_BR_LOCAL_IN").pf("NFPROTO_BRIDGE") { @netfilter_common_setup("bridge") @netfilter_bridge_setup } /** * probe netfilter.bridge.forward - Called on an incoming bridging packet destined for some other computer * @pf: Protocol family -- always "bridge" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @llcpdu: Address of LLC Protocol Data Unit * @brhdr: Address of bridge header * @llcproto_stp: Constant used to signify Bridge Spanning Tree Protocol packet * @protocol: Packet protocol * @br_prid: Protocol identifier * @br_vid: Protocol version identifier * @br_type: BPDU type * @br_flags: BPDU flags * @br_rid: Identity of root bridge * @br_rmac: Root bridge MAC address * @br_cost: Total cost from transmitting bridge to root * @br_bid: Identity of bridge * @br_mac: Bridge MAC address * @br_poid: Port identifier * @br_msg: Message age in 1/256 secs * @br_max: Max age in 1/256 secs * @br_htime: Hello time in 1/256 secs * @br_fd: Forward delay in 1/256 secs * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.bridge.forward = netfilter.hook("NF_BR_FORWARD").pf("NFPROTO_BRIDGE") { @netfilter_common_setup("bridge") @netfilter_bridge_setup } /** * probe netfilter.bridge.local_out - Called on a bridging packet coming from a local process * @pf: Protocol family -- always "bridge" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @llcpdu: Address of LLC Protocol Data Unit * @brhdr: Address of bridge header * @llcproto_stp: Constant used to signify Bridge Spanning Tree Protocol packet * @protocol: Packet protocol * @br_prid: Protocol identifier * @br_vid: Protocol version identifier * @br_type: BPDU type * @br_flags: BPDU flags * @br_rid: Identity of root bridge * @br_rmac: Root bridge MAC address * @br_cost: Total cost from transmitting bridge to root * @br_bid: Identity of bridge * @br_mac: Bridge MAC address * @br_poid: Port identifier * @br_msg: Message age in 1/256 secs * @br_max: Max age in 1/256 secs * @br_htime: Hello time in 1/256 secs * @br_fd: Forward delay in 1/256 secs * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.bridge.local_out = netfilter.hook("NF_BR_LOCAL_OUT").pf("NFPROTO_BRIDGE") { @netfilter_common_setup("bridge") @netfilter_bridge_setup } /** * probe netfilter.bridge.post_routing -- Called before a bridging packet hits the wire * @pf: Protocol family -- always "bridge" * @indev: Address of net_device representing input device, 0 if unknown * @outdev: Address of net_device representing output device, 0 if unknown * @indev_name: Name of network device packet was received on (if known) * @outdev_name: Name of network device packet will be routed to (if known) * @llcpdu: Address of LLC Protocol Data Unit * @brhdr: Address of bridge header * @llcproto_stp: Constant used to signify Bridge Spanning Tree Protocol packet * @protocol: Packet protocol * @br_prid: Protocol identifier * @br_vid: Protocol version identifier * @br_type: BPDU type * @br_flags: BPDU flags * @br_rid: Identity of root bridge * @br_rmac: Root bridge MAC address * @br_cost: Total cost from transmitting bridge to root * @br_bid: Identity of bridge * @br_mac: Bridge MAC address * @br_poid: Port identifier * @br_msg: Message age in 1/256 secs * @br_max: Max age in 1/256 secs * @br_htime: Hello time in 1/256 secs * @br_fd: Forward delay in 1/256 secs * @length: The length of the packet buffer contents, in bytes * @data_str: A string representing the packet buffer contents * @data_hex: A hexadecimal string representing the packet buffer contents * @nf_drop: Constant used to signify a 'drop' verdict * @nf_accept: Constant used to signify an 'accept' verdict * @nf_stolen: Constant used to signify a 'stolen' verdict * @nf_queue: Constant used to signify a 'queue' verdict * @nf_repeat: Constant used to signify a 'repeat' verdict * @nf_stop: Constant used to signify a 'stop' verdict */ probe netfilter.bridge.post_routing = netfilter.hook("NF_BR_POST_ROUTING").pf("NFPROTO_BRIDGE") { @netfilter_common_setup("bridge") @netfilter_bridge_setup }