/usr/share/systemtap/tapset/linux
NameSizeModeActions
arm/-0755rm
arm64/-0755rm
i386/-0755rm
ia64/-0755rm
mips/-0755rm
powerpc/-0755rm
riscv/-0755rm
s390/-0755rm
x86_64/-0755rm
atomic.stp15630644editdlrm
aux_syscalls.stp1517020644editdlrm
context-caller.stp31480644editdlrm
context-envvar.stp17610644editdlrm
context-symbols.stp122760644editdlrm
context-unwind.stp32830644editdlrm
context.stp190150644editdlrm
context.stpm1250644editdlrm
conversions-guru.stp58760644editdlrm
conversions.stp172730644editdlrm
ctime.stp57500644editdlrm
dentry.stp106670644editdlrm
dev.stp20740644editdlrm
endian.stp6020644editdlrm
errno.stpm570644editdlrm
guru-delay.stp12300644editdlrm
guru-signal.stp10920644editdlrm
inet.stp14560644editdlrm
inet.stpm3830644editdlrm
inet_sock.stp12820644editdlrm
ioblock.stp155970644editdlrm
ioscheduler.stp140980644editdlrm
ip.stp54830644editdlrm
ipmib-filter-default.stp9650644editdlrm
ipmib.stp129810644editdlrm
irq.stp51200644editdlrm
json.stp91940644editdlrm
json.stpm62560644editdlrm
kprocess.stp47500644editdlrm
kretprobe.stp21530644editdlrm
linuxmib-filter-default.stp8760644editdlrm
linuxmib.stp37180644editdlrm
loadavg.stp19950644editdlrm
logging.stp25850644editdlrm
memory.stp192190644editdlrm
netfilter.stp363560644editdlrm
networking.stp96560644editdlrm
nfs.stp389970644editdlrm
nfsd.stp473790644editdlrm
nfsderrno.stp119790644editdlrm
nfs_proc.stp583250644editdlrm
nfs_proc.stpm12880644editdlrm
panic.stp10920644editdlrm
perf.stp52840644editdlrm
proc_mem.stp127020644editdlrm
pstrace.stp7730644editdlrm
rcu.stp9280644editdlrm
rlimit.stp13820644editdlrm
rpc.stp385780644editdlrm
scheduler.stp116610644editdlrm
scsi.stp97210644editdlrm
signal.stp293710644editdlrm
socket.stp350240644editdlrm
syscalls.stpm146430644editdlrm
syscalls_cfg_trunc.stp1110644editdlrm
syscall_any.stp15600644editdlrm
syscall_table.stp14750644editdlrm
sysc_accept.stp78680644editdlrm
sysc_accept4.stp78640644editdlrm
sysc_access.stp29110644editdlrm
sysc_acct.stp25830644editdlrm
sysc_add_key.stp35320644editdlrm
sysc_adjtimex.stp56720644editdlrm
sysc_alarm.stp28330644editdlrm
sysc_bdflush.stp31130644editdlrm
sysc_bind.stp69650644editdlrm
sysc_bpf.stp27380644editdlrm
sysc_brk.stp26290644editdlrm
sysc_capget.stp31010644editdlrm
sysc_capset.stp31020644editdlrm
sysc_chdir.stp26160644editdlrm
sysc_chmod.stp29590644editdlrm
sysc_chown.stp37750644editdlrm
sysc_chown16.stp31150644editdlrm
sysc_chroot.stp26790644editdlrm
sysc_clock_adjtime.stp52430644editdlrm
sysc_clock_getres.stp42480644editdlrm
sysc_clock_gettime.stp40350644editdlrm
sysc_clock_nanosleep.stp80410644editdlrm
sysc_clock_settime.stp55540644editdlrm
sysc_clone.stp67080644editdlrm
sysc_close.stp27710644editdlrm
sysc_connect.stp74520644editdlrm
sysc_copy_file_range.stp37690644editdlrm
sysc_creat.stp27280644editdlrm
sysc_delete_module.stp33660644editdlrm
sysc_dup.stp23830644editdlrm
sysc_dup2.stp29910644editdlrm
sysc_dup3.stp30730644editdlrm
sysc_epoll_create.stp57420644editdlrm
sysc_epoll_ctl.stp39980644editdlrm
sysc_epoll_pwait.stp41570644editdlrm
sysc_epoll_wait.stp48500644editdlrm
sysc_eventfd.stp54110644editdlrm
sysc_execve.stp62570644editdlrm
sysc_execveat.stp69420644editdlrm
sysc_exit.stp19840644editdlrm
sysc_exit_group.stp21460644editdlrm
sysc_faccessat.stp37360644editdlrm
sysc_faccessat2.stp44340644editdlrm
sysc_fadvise64.stp86390644editdlrm
sysc_fallocate.stp39180644editdlrm
sysc_fanotify_init.stp34320644editdlrm
sysc_fanotify_mark.stp75720644editdlrm
sysc_fchdir.stp25250644editdlrm
sysc_fchmod.stp28800644editdlrm
sysc_fchmodat.stp37340644editdlrm
sysc_fchown.stp37220644editdlrm
sysc_fchown16.stp30230644editdlrm
sysc_fchownat.stp39030644editdlrm
sysc_fcntl.stp48060644editdlrm
sysc_fdatasync.stp26920644editdlrm
sysc_fgetxattr.stp37200644editdlrm
sysc_finit_module.stp33820644editdlrm
sysc_flistxattr.stp30000644editdlrm
sysc_flock.stp25790644editdlrm
sysc_fork.stp25860644editdlrm
sysc_fremovexattr.stp32290644editdlrm
sysc_fsetxattr.stp41870644editdlrm
sysc_fstat.stp61630644editdlrm
sysc_fstatat.stp57890644editdlrm
sysc_fstatfs.stp32660644editdlrm
sysc_fstatfs64.stp32400644editdlrm
sysc_fsync.stp24190644editdlrm
sysc_ftruncate.stp62120644editdlrm
sysc_futex.stp58100644editdlrm
sysc_futimesat.stp66390644editdlrm
sysc_getcpu.stp30340644editdlrm
sysc_getcwd.stp27470644editdlrm
sysc_getdents.stp56180644editdlrm
sysc_getegid.stp35420644editdlrm
sysc_geteuid.stp34840644editdlrm
sysc_getgid.stp34020644editdlrm
sysc_getgroups.stp42740644editdlrm
sysc_gethostname.stp12490644editdlrm
sysc_getitimer.stp53550644editdlrm
sysc_getpeername.stp75220644editdlrm
sysc_getpgid.stp28590644editdlrm
sysc_getpgrp.stp20900644editdlrm
sysc_getpid.stp20310644editdlrm
sysc_getppid.stp21120644editdlrm
sysc_getpriority.stp29430644editdlrm
sysc_getrandom.stp31840644editdlrm
sysc_getresgid.stp41720644editdlrm
sysc_getresuid.stp39720644editdlrm
sysc_getrlimit.stp44600644editdlrm
sysc_getrusage.stp38030644editdlrm
sysc_getsid.stp25090644editdlrm
sysc_getsockname.stp75500644editdlrm
sysc_getsockopt.stp85200644editdlrm
sysc_gettid.stp20570644editdlrm
sysc_gettimeofday.stp40780644editdlrm
sysc_getuid.stp34270644editdlrm
sysc_getxattr.stp38120644editdlrm
sysc_get_mempolicy.stp46710644editdlrm
sysc_get_robust_list.stp45720644editdlrm
sysc_init_module.stp32410644editdlrm
sysc_inotify_add_watch.stp38610644editdlrm
sysc_inotify_init.stp55480644editdlrm
sysc_inotify_rm_watch.stp32770644editdlrm
sysc_ioctl.stp35360644editdlrm
sysc_ioperm.stp28190644editdlrm
sysc_ioprio_get.stp30180644editdlrm
sysc_ioprio_set.stp32470644editdlrm
sysc_io_cancel.stp33180644editdlrm
sysc_io_destroy.stp28160644editdlrm
sysc_io_getevents.stp49940644editdlrm
sysc_io_setup.stp38380644editdlrm
sysc_io_submit.stp39830644editdlrm
sysc_kcmp.stp30070644editdlrm
sysc_kexec_file_load.stp40410644editdlrm
sysc_kexec_load.stp45130644editdlrm
sysc_keyctl.stp37220644editdlrm
sysc_kill.stp25910644editdlrm
sysc_lchown.stp38800644editdlrm
sysc_lchown16.stp31940644editdlrm
sysc_lgetxattr.stp39120644editdlrm
sysc_link.stp28850644editdlrm
sysc_linkat.stp40050644editdlrm
sysc_listen.stp66240644editdlrm
sysc_listxattr.stp33180644editdlrm
sysc_llistxattr.stp33790644editdlrm
sysc_llseek.stp33710644editdlrm
sysc_lookup_dcookie.stp40890644editdlrm
sysc_lremovexattr.stp40010644editdlrm
sysc_lseek.stp45000644editdlrm
sysc_lsetxattr.stp40970644editdlrm
sysc_lstat.stp64550644editdlrm
sysc_madvise.stp29760644editdlrm
sysc_mbind.stp43030644editdlrm
sysc_membarrier.stp30170644editdlrm
sysc_memfd_create.stp32470644editdlrm
sysc_memfd_secret.stp28150644editdlrm
sysc_migrate_pages.stp43740644editdlrm
sysc_mincore.stp29000644editdlrm
sysc_mkdir.stp28970644editdlrm
sysc_mkdirat.stp34450644editdlrm
sysc_mknod.stp29580644editdlrm
sysc_mknodat.stp36440644editdlrm
sysc_mlock.stp26180644editdlrm
sysc_mlock2.stp28820644editdlrm
sysc_mlockall.stp27710644editdlrm
sysc_mmap2.stp62290644editdlrm
sysc_modify_ldt.stp31120644editdlrm
sysc_mount.stp44990644editdlrm
sysc_move_pages.stp47250644editdlrm
sysc_mprotect.stp29660644editdlrm
sysc_mq_getsetattr.stp44600644editdlrm
sysc_mq_notify.stp39360644editdlrm
sysc_mq_open.stp53850644editdlrm
sysc_mq_timedreceive.stp61830644editdlrm
sysc_mq_timedsend.stp59280644editdlrm
sysc_mq_unlink.stp30180644editdlrm
sysc_mremap.stp35770644editdlrm
sysc_msgctl.stp82550644editdlrm
sysc_msgget.stp44230644editdlrm
sysc_msgrcv.stp106890644editdlrm
sysc_msgsnd.stp88660644editdlrm
sysc_msync.stp28510644editdlrm
sysc_munlock.stp27440644editdlrm
sysc_munlockall.stp23420644editdlrm
sysc_munmap.stp27090644editdlrm
sysc_name_to_handle_at.stp41500644editdlrm
sysc_nanosleep.stp58240644editdlrm
sysc_nfsservctl.stp22840644editdlrm
sysc_nice.stp24400644editdlrm
sysc_ni_syscall.stp14330644editdlrm
sysc_open.stp43290644editdlrm
sysc_openat.stp39160644editdlrm
sysc_open_by_handle_at.stp42980644editdlrm
sysc_pause.stp25640644editdlrm
sysc_perf_event_open.stp38080644editdlrm
sysc_personality.stp30770644editdlrm
sysc_pipe.stp105960644editdlrm
sysc_pivot_root.stp33140644editdlrm
sysc_pkey_alloc.stp30570644editdlrm
sysc_pkey_free.stp27190644editdlrm
sysc_pkey_mprotect.stp33920644editdlrm
sysc_poll.stp27690644editdlrm
sysc_ppoll.stp64930644editdlrm
sysc_prctl.stp29930644editdlrm
sysc_pread.stp54270644editdlrm
sysc_preadv.stp52830644editdlrm
sysc_preadv2.stp56670644editdlrm
sysc_prlimit64.stp34950644editdlrm
sysc_process_vm_readv.stp47750644editdlrm
sysc_process_vm_writev.stp48970644editdlrm
sysc_pselect6.stp64570644editdlrm
sysc_pselect7.stp36680644editdlrm
sysc_ptrace.stp36610644editdlrm
sysc_pwrite.stp72390644editdlrm
sysc_pwritev.stp54140644editdlrm
sysc_pwritev2.stp57740644editdlrm
sysc_quotactl.stp46910644editdlrm
sysc_read.stp37210644editdlrm
sysc_readahead.stp36010644editdlrm
sysc_readdir.stp40430644editdlrm
sysc_readlink.stp31140644editdlrm
sysc_readlinkat.stp38330644editdlrm
sysc_readv.stp35020644editdlrm
sysc_reboot.stp32530644editdlrm
sysc_recv.stp72600644editdlrm
sysc_recvfrom.stp85540644editdlrm
sysc_recvmmsg.stp64620644editdlrm
sysc_recvmsg.stp109620644editdlrm
sysc_remap_file_pages.stp39350644editdlrm
sysc_removexattr.stp33200644editdlrm
sysc_rename.stp30380644editdlrm
sysc_renameat.stp41910644editdlrm
sysc_renameat2.stp45000644editdlrm
sysc_request_key.stp41380644editdlrm
sysc_restart_syscall.stp25650644editdlrm
sysc_rmdir.stp26570644editdlrm
sysc_rt_sigaction.stp69520644editdlrm
sysc_rt_sigpending.stp47990644editdlrm
sysc_rt_sigprocmask.stp91050644editdlrm
sysc_rt_sigqueueinfo.stp47500644editdlrm
sysc_rt_sigreturn.stp16390644editdlrm
sysc_rt_sigsuspend.stp38790644editdlrm
sysc_rt_sigtimedwait.stp60240644editdlrm
sysc_rt_tgsigqueueinfo.stp44600644editdlrm
sysc_sched_getaffinity.stp41020644editdlrm
sysc_sched_getattr.stp36710644editdlrm
sysc_sched_getparam.stp32360644editdlrm
sysc_sched_getscheduler.stp32960644editdlrm
sysc_sched_get_priority_max.stp36400644editdlrm
sysc_sched_get_priority_min.stp36400644editdlrm
sysc_sched_rr_get_interval.stp48640644editdlrm
sysc_sched_setaffinity.stp39600644editdlrm
sysc_sched_setattr.stp34450644editdlrm
sysc_sched_setparam.stp32210644editdlrm
sysc_sched_setscheduler.stp36660644editdlrm
sysc_sched_yield.stp23150644editdlrm
sysc_seccomp.stp33650644editdlrm
sysc_select.stp63590644editdlrm
sysc_semctl.stp82060644editdlrm
sysc_semget.stp45960644editdlrm
sysc_semop.stp57700644editdlrm
sysc_semtimedop.stp99360644editdlrm
sysc_send.stp73690644editdlrm
sysc_sendfile.stp49120644editdlrm
sysc_sendmmsg.stp93050644editdlrm
sysc_sendmsg.stp121100644editdlrm
sysc_sendto.stp83570644editdlrm
sysc_setdomainname.stp37290644editdlrm
sysc_setfsgid.stp47960644editdlrm
sysc_setfsuid.stp48390644editdlrm
sysc_setgid.stp45730644editdlrm
sysc_setgroups.stp45190644editdlrm
sysc_sethostname.stp32740644editdlrm
sysc_setitimer.stp62860644editdlrm
sysc_setns.stp28040644editdlrm
sysc_setpgid.stp27600644editdlrm
sysc_setpriority.stp32180644editdlrm
sysc_setregid.stp66600644editdlrm
sysc_setresgid.stp70400644editdlrm
sysc_setresuid.stp70550644editdlrm
sysc_setreuid.stp66300644editdlrm
sysc_setrlimit.stp40300644editdlrm
sysc_setsid.stp21010644editdlrm
sysc_setsockopt.stp84440644editdlrm
sysc_settimeofday.stp66460644editdlrm
sysc_setuid.stp45720644editdlrm
sysc_setxattr.stp39930644editdlrm
sysc_set_mempolicy.stp41710644editdlrm
sysc_set_robust_list.stp43580644editdlrm
sysc_set_tid_address.stp31950644editdlrm
sysc_sgetmask.stp21690644editdlrm
sysc_shmat.stp67770644editdlrm
sysc_shmctl.stp81390644editdlrm
sysc_shmdt.stp39820644editdlrm
sysc_shmget.stp45010644editdlrm
sysc_shutdown.stp69090644editdlrm
sysc_sigaction.stp57820644editdlrm
sysc_sigaltstack.stp42670644editdlrm
sysc_signal.stp28670644editdlrm
sysc_signalfd.stp124640644editdlrm
sysc_sigpending.stp37120644editdlrm
sysc_sigprocmask.stp41720644editdlrm
sysc_sigreturn.stp14610644editdlrm
sysc_sigsuspend.stp45750644editdlrm
sysc_socket.stp74380644editdlrm
sysc_socketpair.stp82970644editdlrm
sysc_splice.stp33630644editdlrm
sysc_ssetmask.stp28100644editdlrm
sysc_stat.stp65350644editdlrm
sysc_statfs.stp34910644editdlrm
sysc_statfs64.stp34590644editdlrm
sysc_statx.stp41180644editdlrm
sysc_stime.stp30830644editdlrm
sysc_swapoff.stp28750644editdlrm
sysc_swapon.stp31210644editdlrm
sysc_symlink.stp30280644editdlrm
sysc_symlinkat.stp40600644editdlrm
sysc_sync.stp19250644editdlrm
sysc_syncfs.stp25710644editdlrm
sysc_sync_file_range.stp60110644editdlrm
sysc_sysctl.stp30950644editdlrm
sysc_sysfs.stp36480644editdlrm
sysc_sysinfo.stp32860644editdlrm
sysc_syslog.stp28260644editdlrm
sysc_tee.stp27430644editdlrm
sysc_tgkill.stp28830644editdlrm
sysc_time.stp35050644editdlrm
sysc_timerfd.stp18290644editdlrm
sysc_timerfd_create.stp33940644editdlrm
sysc_timerfd_gettime.stp42190644editdlrm
sysc_timerfd_settime.stp52820644editdlrm
sysc_timer_create.stp49750644editdlrm
sysc_timer_delete.stp29420644editdlrm
sysc_timer_getoverrun.stp32070644editdlrm
sysc_timer_gettime.stp46700644editdlrm
sysc_timer_settime.stp60750644editdlrm
sysc_times.stp31670644editdlrm
sysc_tkill.stp26950644editdlrm
sysc_truncate.stp70310644editdlrm
sysc_tux.stp10680644editdlrm
sysc_umask.stp25220644editdlrm
sysc_umount.stp53600644editdlrm
sysc_uname.stp51450644editdlrm
sysc_unlink.stp28660644editdlrm
sysc_unlinkat.stp33800644editdlrm
sysc_unshare.stp28140644editdlrm
sysc_uselib.stp28710644editdlrm
sysc_userfaultfd.stp30050644editdlrm
sysc_ustat.stp53330644editdlrm
sysc_utime.stp61730644editdlrm
sysc_utimensat.stp70440644editdlrm
sysc_utimes.stp63310644editdlrm
sysc_vfork.stp20290644editdlrm
sysc_vhangup.stp21280644editdlrm
sysc_vmsplice.stp63370644editdlrm
sysc_wait4.stp50970644editdlrm
sysc_waitid.stp42530644editdlrm
sysc_waitpid.stp34600644editdlrm
sysc_write.stp39390644editdlrm
sysc_writev.stp36560644editdlrm
target_set.stp17690644editdlrm
task.stp228800644editdlrm
task.stpm2530644editdlrm
task_ancestry.stp16210644editdlrm
task_time.stp78610644editdlrm
tcp.stp226420644editdlrm
tcpmib-filter-default.stp8850644editdlrm
tcpmib.stp108240644editdlrm
timestamp.stp17610644editdlrm
timestamp_gtod.stp16290644editdlrm
timestamp_monotonic.stp55890644editdlrm
tty.stp73510644editdlrm
tzinfo.stp8030644editdlrm
ucontext-symbols.stp88420644editdlrm
ucontext-unwind.stp76450644editdlrm
ucontext.stp22370644editdlrm
udp.stp60970644editdlrm
utrace.stp13630644editdlrm
vfs.stp338260644editdlrm
Edit: /usr/share/systemtap/tapset/linux/tcp.stp (22642B)
// TCP tapset // Copyright (C) 2006 IBM Corp. // Copyright (C) 2006 Intel Corporation. // Copyright (C) 2007, 2010, 2012-2018 Red Hat, Inc. // // This file is part of systemtap, and is free software. You can // redistribute it and/or modify it under the terms of the GNU General // Public License (GPL); either version 2, or (at your option) any // later version. // // This family of probe points is used to probe events that occur in the TCP layer, // // See the BZ1546179 block comment in tapset/linux/networking.stp for // an explanation of the try/catch statements around sk_buff structure // accesses. %{ #include #include #include #include #include %} // Get retransmission timeout in usecs. RTO is initialized from default // retransmission time, but can be adjusted (increased) each time we // retransmit. It should always be less than the max value of TCP retransmission // timeout (TCP_RTO_MAX) function tcp_get_info_rto:long(sock:long) %{ /* pure */ struct sock *sk = (struct sock *)(uintptr_t) STAP_ARG_sock; #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,10) struct tcp_opt *tp = tcp_sk(sk); STAP_RETVALUE = (int64_t) jiffies_to_usecs(kread(&(tp->rto))); #else const struct inet_connection_sock *icsk = inet_csk(sk); STAP_RETVALUE = (int64_t) jiffies_to_usecs(kread(&(icsk->icsk_rto))); #endif CATCH_DEREF_FAULT(); %} //Get congestion window segment size. Initial value of congestion window size //typically set to one segment (i.e., slow start algorithm, each segment can be 512 bytes). //This congestion window size can be dynamically increased based on whether TCP //is performing slow start or congestion avoidance. function tcp_get_info_snd_cwnd:long(sock:long) %{ /* pure */ struct sock *sk = (struct sock *)(uintptr_t) STAP_ARG_sock; #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,10) struct tcp_opt *tp = tcp_sk(sk); #else struct tcp_sock *tp = tcp_sk(sk); #endif STAP_RETVALUE = (int64_t) kread(&(tp->snd_cwnd)); CATCH_DEREF_FAULT(); %} // //Definitions of the TCP protocol sk_state field listed below. // // TCP_ESTABLISHED = 1, Normal data transfer // TCP_SYN_SENT = 2, App. has started to open a connection // TCP_SYN_RECV = 3, A connection request has arrived; wait for ACK // TCP_FIN_WAIT1 = 4, App. has said it is finished // TCP_FIN_WAIT2 = 5, The other side has agreed to close // TCP_TIME_WAIT = 6, Wait for all packets to die off // TCP_CLOSE = 7, No connection is active or pending // TCP_CLOSE_WAIT = 8, The other side has initiated a release // TCP_LAST_ACK = 9, Last ACK, wait for all packets to die off // TCP_LISTEN = 10, Waiting for incoming call // TCP_CLOSING = 11, Both sides have tried to close simultaneously // TCP_MAX_STATES = 12 Max states number // function tcp_ts_get_info_state:long(sock:long) %{ /* pure */ struct sock *sk = (struct sock *)(uintptr_t) STAP_ARG_sock; STAP_RETVALUE = (int64_t) kread(&(sk->sk_state)); CATCH_DEREF_FAULT(); %} /* return the TCP destination port for a given sock */ function __tcp_sock_dport:long (sock:long) { port = @choose_defined(@inet_sock_cast(sock)->sk->__sk_common->skc_dport, # kernel >= 3.8 @choose_defined(@inet_sock_cast(sock)->inet_dport, # kernel >= 2.6.33 @choose_defined(@inet_sock_cast(sock)->dport, # kernel >= 2.6.11 @inet_sock_cast(sock)->inet->dport))) return ntohs(port) } /* returns the TCP header for recent (<2.6.21) kernel */ @__private30 function __get_skb_tcphdr_new:long(skb:long) %{ /* pure */ struct sk_buff *skb; skb = (struct sk_buff *)(uintptr_t)STAP_ARG_skb; /* as done by skb_transport_header() */ #ifdef NET_SKBUFF_DATA_USES_OFFSET STAP_RETVALUE = (long)(kread(&(skb->head)) + kread(&(skb->transport_header))); #else STAP_RETVALUE = (long)kread(&(skb->transport_header)); #endif CATCH_DEREF_FAULT(); %} /* returns the TCP header for a given sk_buff structure */ function __get_skb_tcphdr:long(skb:long) { %( kernel_v < "2.6.21" %? tcphdr = @cast(skb, "sk_buff")->h->raw return tcphdr %: return __get_skb_tcphdr_new(skb) %) } /* returns TCP URG flag for a given sk_buff structure */ function __tcp_skb_urg:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->urg } /* returns TCP ACK flag for a given sk_buff structure */ function __tcp_skb_ack:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->ack } /* returns TCP PSH flag for a given sk_buff structure */ function __tcp_skb_psh:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->psh } /* returns TCP RST flag for a given sk_buff structure */ function __tcp_skb_rst:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->rst } /* returns TCP SYN flag for a given sk_buff structure */ function __tcp_skb_syn:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->syn } /* returns TCP FIN flag for a given sk_buff structure */ function __tcp_skb_fin:long (tcphdr:long) { return @cast(tcphdr, "tcphdr", "kernel")->fin } /* returns TCP source port for a given sk_buff structure */ function __tcp_skb_sport:long (tcphdr:long) { return ntohs(@cast(tcphdr, "tcphdr", "kernel")->source) } /* returns TCP destination port for a given sk_buff structure */ function __tcp_skb_dport:long (tcphdr:long){ return ntohs(@cast(tcphdr, "tcphdr", "kernel")->dest) } /* return the TCP source port for a given sock */ function __tcp_sock_sport:long (sock:long) { port = @choose_defined(@inet_sock_cast(sock)->inet_sport, # kernel >= 2.6.33 @choose_defined(@inet_sock_cast(sock)->sport, # kernel >= 2.6.11 @inet_sock_cast(sock)->inet->sport)) return ntohs(port) } @__private30 global sockstate[12] probe init { sockstate[1] = "TCP_ESTABLISHED" sockstate[2] = "TCP_SYN_SENT" sockstate[3] = "TCP_SYN_RECV" sockstate[4] = "TCP_FIN_WAIT1" sockstate[5] = "TCP_FIN_WAIT2" sockstate[6] = "TCP_TIME_WAIT" sockstate[7] = "TCP_CLOSE" sockstate[8] = "TCP_CLOSE_WAIT" sockstate[9] = "TCP_LAST_ACK" sockstate[10] = "TCP_LISTEN" sockstate[11] = "TCP_CLOSING" sockstate[12] = "TCP_MAX_STATES" } function tcp_sockstate_str:string (state:long) { return (state in sockstate ? sockstate[state] : "UNDEF") } // Get slow start threshold size. If cwnd size is less than or equal to // threshold size, then TCP is in slow start; otherwise TCP is in congestion // avoidance. function tcp_ts_get_info_snd_ssthresh:long(sock:long) %{ /* pure */ struct sock *sk = (struct sock *)(uintptr_t) STAP_ARG_sock; #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,10) struct tcp_opt *tp = tcp_sk(sk); #else struct tcp_sock *tp = tcp_sk(sk); #endif STAP_RETVALUE = (int64_t) kread(&(tp->snd_ssthresh)); CATCH_DEREF_FAULT(); %} // Get receiver's advertised segment size. TCP typically never sends more // than what receiver can accept. function tcp_ts_get_info_rcv_mss:long(sock:long) %{ /* pure */ struct sock *sk = (struct sock *)(uintptr_t) STAP_ARG_sock; #if LINUX_VERSION_CODE < KERNEL_VERSION(2,6,10) struct tcp_opt *tp = tcp_sk(sk); STAP_RETVALUE = (int64_t) kread(&(tp->ack.rcv_mss)); #else const struct inet_connection_sock *icsk = inet_csk(sk); STAP_RETVALUE = (int64_t) kread(&(icsk->icsk_ack.rcv_mss)); #endif CATCH_DEREF_FAULT(); %} %{ // Define newer IPv4 sockopt constants for older kernels. #ifndef TCP_CONGESTION #define TCP_CONGESTION 0 #endif #ifndef TCP_MD5SIG #define TCP_MD5SIG 0 #endif #ifndef TCP_COOKIE_TRANSACTIONS #define TCP_COOKIE_TRANSACTIONS 0 #endif #ifndef TCP_THIN_LINEAR_TIMEOUTS #define TCP_THIN_LINEAR_TIMEOUTS 0 #endif #ifndef TCP_THIN_DUPACK #define TCP_THIN_DUPACK 0 #endif #ifndef TCP_USER_TIMEOUT #define TCP_USER_TIMEOUT 0 #endif %} @__private30 global __sockopt[18] probe init { __sockopt[@const("TCP_NODELAY")] = "TCP_NODELAY" __sockopt[@const("TCP_MAXSEG")] = "TCP_MAXSEG" __sockopt[@const("TCP_CORK")] = "TCP_CORK" __sockopt[@const("TCP_KEEPIDLE")] = "TCP_KEEPIDLE" __sockopt[@const("TCP_KEEPINTVL")] = "TCP_KEEPINTVL" __sockopt[@const("TCP_KEEPCNT")] = "TCP_KEEPCNT" __sockopt[@const("TCP_SYNCNT")] = "TCP_SYNCNT" __sockopt[@const("TCP_LINGER2")] = "TCP_LINGER2" __sockopt[@const("TCP_DEFER_ACCEPT")] = "TCP_DEFER_ACCEPT" __sockopt[@const("TCP_WINDOW_CLAMP")] = "TCP_WINDOW_CLAMP" __sockopt[@const("TCP_INFO")] = "TCP_INFO" __sockopt[@const("TCP_QUICKACK")] = "TCP_QUICKACK" if (@const("TCP_CONGESTION") > 0) __sockopt[@const("TCP_CONGESTION")] = "TCP_CONGESTION" if (@const("TCP_MD5SIG") > 0) __sockopt[@const("TCP_MD5SIG")] = "TCP_MD5SIG" if (@const("TCP_COOKIE_TRANSACTIONS") > 0) __sockopt[@const("TCP_COOKIE_TRANSACTIONS")] = "TCP_COOKIE_TRANSACTIONS" if (@const("TCP_THIN_LINEAR_TIMEOUTS") > 0) __sockopt[@const("TCP_THIN_LINEAR_TIMEOUTS")] = "TCP_THIN_LINEAR_TIMEOUTS" if (@const("TCP_THIN_DUPACK") > 0) __sockopt[@const("TCP_THIN_DUPACK")] = "TCP_THIN_DUPACK" if (@const("TCP_USER_TIMEOUT") > 0) __sockopt[@const("TCP_USER_TIMEOUT")] = "TCP_USER_TIMEOUT" } function tcp_sockopt_str:string (optname:long) { return (optname in __sockopt ? __sockopt[optname] : sprintf("UNDEF_SOCKOPT(%d)", optname)) } %{ // Define newer IPv6 sockopt constants for older kernels. #include #ifndef IPV6_2292PKTINFO #define IPV6_2292PKTINFO 0 #endif #ifndef IPV6_2292HOPOPTS #define IPV6_2292HOPOPTS 0 #endif #ifndef IPV6_2292DSTOPTS #define IPV6_2292DSTOPTS 0 #endif #ifndef IPV6_2292RTHDR #define IPV6_2292RTHDR 0 #endif #ifndef IPV6_2292PKTOPTIONS #define IPV6_2292PKTOPTIONS 0 #endif #ifndef IPV6_2292HOPLIMIT #define IPV6_2292HOPLIMIT 0 #endif #ifndef IPV6_RECVPKTINFO #define IPV6_RECVPKTINFO 0 #endif #ifndef IPV6_RECVHOPLIMIT #define IPV6_RECVHOPLIMIT 0 #endif #ifndef IPV6_RECVHOPOPTS #define IPV6_RECVHOPOPTS 0 #endif #ifndef IPV6_RTHDRDSTOPTS #define IPV6_RTHDRDSTOPTS 0 #endif #ifndef IPV6_RECVRTHDR #define IPV6_RECVRTHDR 0 #endif #ifndef IPV6_RECVDSTOPTS #define IPV6_RECVDSTOPTS 0 #endif #ifndef IPV6_RECVPATHMTU #define IPV6_RECVPATHMTU 0 #endif #ifndef IPV6_PATHMTU #define IPV6_PATHMTU 0 #endif #ifndef IPV6_DONTFRAG #define IPV6_DONTFRAG 0 #endif #ifndef IPV6_ADDR_PREFERENCES #define IPV6_ADDR_PREFERENCES 0 #endif #ifndef IPV6_MINHOPCOUNT #define IPV6_MINHOPCOUNT 0 #endif #ifndef IPV6_RECVORIGDSTADDR #define IPV6_RECVORIGDSTADDR 0 #endif #ifndef IPV6_TRANSPARENT #define IPV6_TRANSPARENT 0 #endif %} @__private30 global __ipv6_sockopt[55] probe init { __ipv6_sockopt[@const("IPV6_ADDRFORM")] = "IPV6_ADDRFORM" if (@const("IPV6_2292PKTINFO") > 0) __ipv6_sockopt[@const("IPV6_2292PKTINFO")] = "IPV6_2292PKTINFO" if (@const("IPV6_2292HOPOPTS") > 0) __ipv6_sockopt[@const("IPV6_2292HOPOPTS")] = "IPV6_2292HOPOPTS" if (@const("IPV6_2292DSTOPTS") > 0) __ipv6_sockopt[@const("IPV6_2292DSTOPTS")] = "IPV6_2292DSTOPTS" if (@const("IPV6_2292RTHDR") > 0) __ipv6_sockopt[@const("IPV6_2292RTHDR")] = "IPV6_2292RTHDR" if (@const("IPV6_2292PKTOPTIONS") > 0) __ipv6_sockopt[@const("IPV6_2292PKTOPTIONS")] = "IPV6_2292PKTOPTIONS" __ipv6_sockopt[@const("IPV6_CHECKSUM")] = "IPV6_CHECKSUM" if (@const("IPV6_2292HOPLIMIT") > 0) __ipv6_sockopt[@const("IPV6_2292HOPLIMIT")] = "IPV6_2292HOPLIMIT" __ipv6_sockopt[@const("IPV6_NEXTHOP")] = "IPV6_NEXTHOP" __ipv6_sockopt[@const("IPV6_AUTHHDR")] = "IPV6_AUTHHDR" __ipv6_sockopt[@const("IPV6_FLOWINFO")] = "IPV6_FLOWINFO" __ipv6_sockopt[@const("IPV6_UNICAST_HOPS")] = "IPV6_UNICAST_HOPS" __ipv6_sockopt[@const("IPV6_MULTICAST_IF")] = "IPV6_MULTICAST_IF" __ipv6_sockopt[@const("IPV6_MULTICAST_HOPS")] = "IPV6_MULTICAST_HOPS" __ipv6_sockopt[@const("IPV6_MULTICAST_LOOP")] = "IPV6_MULTICAST_LOOP" __ipv6_sockopt[@const("IPV6_ADD_MEMBERSHIP")] = "IPV6_ADD_MEMBERSHIP" __ipv6_sockopt[@const("IPV6_DROP_MEMBERSHIP")] = "IPV6_DROP_MEMBERSHIP" __ipv6_sockopt[@const("IPV6_ROUTER_ALERT")] = "IPV6_ROUTER_ALERT" __ipv6_sockopt[@const("IPV6_MTU_DISCOVER")] = "IPV6_MTU_DISCOVER" __ipv6_sockopt[@const("IPV6_MTU")] = "IPV6_MTU" __ipv6_sockopt[@const("IPV6_RECVERR")] = "IPV6_RECVERR" __ipv6_sockopt[@const("IPV6_V6ONLY")] = "IPV6_V6ONLY" __ipv6_sockopt[@const("IPV6_JOIN_ANYCAST")] = "IPV6_JOIN_ANYCAST" __ipv6_sockopt[@const("IPV6_LEAVE_ANYCAST")] = "IPV6_LEAVE_ANYCAST" __ipv6_sockopt[@const("IPV6_FLOWLABEL_MGR")] = "IPV6_FLOWLABEL_MGR" __ipv6_sockopt[@const("IPV6_FLOWINFO_SEND")] = "IPV6_FLOWINFO_SEND" __ipv6_sockopt[@const("IPV6_IPSEC_POLICY")] = "IPV6_IPSEC_POLICY" __ipv6_sockopt[@const("IPV6_XFRM_POLICY")] = "IPV6_XFRM_POLICY" __ipv6_sockopt[@const("MCAST_JOIN_GROUP")] = "MCAST_JOIN_GROUP" __ipv6_sockopt[@const("MCAST_BLOCK_SOURCE")] = "MCAST_BLOCK_SOURCE" __ipv6_sockopt[@const("MCAST_UNBLOCK_SOURCE")] = "MCAST_UNBLOCK_SOURCE" __ipv6_sockopt[@const("MCAST_LEAVE_GROUP")] = "MCAST_LEAVE_GROUP" __ipv6_sockopt[@const("MCAST_JOIN_SOURCE_GROUP")] = "MCAST_JOIN_SOURCE_GROUP" __ipv6_sockopt[@const("MCAST_LEAVE_SOURCE_GROUP")] = "MCAST_LEAVE_SOURCE_GROUP" __ipv6_sockopt[@const("MCAST_MSFILTER")] = "MCAST_MSFILTER" if (@const("IPV6_RECVPKTINFO") > 0) __ipv6_sockopt[@const("IPV6_RECVPKTINFO")] = "IPV6_RECVPKTINFO" __ipv6_sockopt[@const("IPV6_PKTINFO")] = "IPV6_PKTINFO" if (@const("IPV6_RECVHOPLIMIT") > 0) __ipv6_sockopt[@const("IPV6_RECVHOPLIMIT")] = "IPV6_RECVHOPLIMIT" __ipv6_sockopt[@const("IPV6_HOPLIMIT")] = "IPV6_HOPLIMIT" if (@const("IPV6_RECVHOPOPTS") > 0) __ipv6_sockopt[@const("IPV6_RECVHOPOPTS")] = "IPV6_RECVHOPOPTS" __ipv6_sockopt[@const("IPV6_HOPOPTS")] = "IPV6_HOPOPTS" if (@const("IPV6_RTHDRDSTOPTS") > 0) __ipv6_sockopt[@const("IPV6_RTHDRDSTOPTS")] = "IPV6_RTHDRDSTOPTS" if (@const("IPV6_RECVRTHDR") > 0) __ipv6_sockopt[@const("IPV6_RECVRTHDR")] = "IPV6_RECVRTHDR" __ipv6_sockopt[@const("IPV6_RTHDR")] = "IPV6_RTHDR" if (@const("IPV6_RECVDSTOPTS") > 0) __ipv6_sockopt[@const("IPV6_RECVDSTOPTS")] = "IPV6_RECVDSTOPTS" __ipv6_sockopt[@const("IPV6_DSTOPTS")] = "IPV6_DSTOPTS" if (@const("IPV6_RECVPATHMTU") > 0) __ipv6_sockopt[@const("IPV6_RECVPATHMTU")] = "IPV6_RECVPATHMTU" if (@const("IPV6_PATHMTU") > 0) __ipv6_sockopt[@const("IPV6_PATHMTU")] = "IPV6_PATHMTU" if (@const("IPV6_DONTFRAG") > 0) __ipv6_sockopt[@const("IPV6_DONTFRAG")] = "IPV6_DONTFRAG" __ipv6_sockopt[@const("IPV6_RECVTCLASS")] = "IPV6_RECVTCLASS" __ipv6_sockopt[@const("IPV6_TCLASS")] = "IPV6_TCLASS" if (@const("IPV6_ADDR_PREFERENCES") > 0) __ipv6_sockopt[@const("IPV6_ADDR_PREFERENCES")] = "IPV6_ADDR_PREFERENCES" if (@const("IPV6_MINHOPCOUNT") > 0) __ipv6_sockopt[@const("IPV6_MINHOPCOUNT")] = "IPV6_MINHOPCOUNT" if (@const("IPV6_RECVORIGDSTADDR") > 0) __ipv6_sockopt[@const("IPV6_RECVORIGDSTADDR")] = "IPV6_RECVORIGDSTADDR" if (@const("IPV6_TRANSPARENT") > 0) __ipv6_sockopt[@const("IPV6_TRANSPARENT")] = "IPV6_TRANSPARENT" } function tcp_ipv6_sockopt_str:string (optname:long) { return (optname in __ipv6_sockopt ? __ipv6_sockopt[optname] : sprintf("UNDEF_SOCKOPT(%d)", optname)) } /** * probe tcp.sendmsg - Sending a tcp message * @name: Name of this probe * @sock: Network socket * @family: IP address family * @size: Number of bytes to send * * Context: * The process which sends a tcp message */ probe tcp.sendmsg = kernel.function("tcp_sendmsg") { name = "tcp.sendmsg" sock = (@defined($sock) ? $sock->sk : $sk) family = __ip_sock_family(@defined($sock) ? $sock->sk : $sk) size = $size } /** * probe tcp.sendmsg.return - Sending TCP message is done * @name: Name of this probe * @size: Number of bytes sent or error code if an error occurred. * * Context: * The process which sends a tcp message */ probe tcp.sendmsg.return = kernel.function("tcp_sendmsg").return { name = "tcp.sendmsg" size = $return } /** * probe tcp.recvmsg - Receiving TCP message * @name: Name of this probe * @sock: Network socket * @size: Number of bytes to be received * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP source port * @dport: TCP destination port * Context: * The process which receives a tcp message */ probe tcp.recvmsg = kernel.function("tcp_recvmsg") { name = "tcp.recvmsg" sock = $sk size = $len family = __ip_sock_family($sk) saddr = format_ipaddr(__ip_sock_saddr($sk), __ip_sock_family($sk)) daddr = format_ipaddr(__ip_sock_daddr($sk), __ip_sock_family($sk)) sport = __tcp_sock_sport($sk) dport = __tcp_sock_dport($sk) } /** * probe tcp.recvmsg.return - Receiving TCP message complete * @name: Name of this probe * @size: Number of bytes received or error code if an error occurred. * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP source port * @dport: TCP destination port * * Context: * The process which receives a tcp message */ probe tcp.recvmsg.return = kernel.function("tcp_recvmsg").return { name = "tcp.recvmsg" size = $return family = __ip_sock_family(@entry($sk)) saddr = format_ipaddr(__ip_sock_saddr(@entry($sk)), __ip_sock_family(@entry($sk))) daddr = format_ipaddr(__ip_sock_daddr(@entry($sk)), __ip_sock_family(@entry($sk))) sport = __tcp_sock_sport(@entry($sk)) dport = __tcp_sock_dport(@entry($sk)) } /** * probe tcp.disconnect - TCP socket disconnection * @name: Name of this probe * @sock: Network socket * @family: IP address family * @flags: TCP flags (e.g. FIN, etc) * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP source port * @dport: TCP destination port * * Context: * The process which disconnects tcp */ probe tcp.disconnect = kernel.function("tcp_disconnect") { name = "tcp.disconnect" sock = $sk family = __ip_sock_family($sk) flags = $flags saddr = format_ipaddr(__ip_sock_saddr($sk), __ip_sock_family($sk)) daddr = format_ipaddr(__ip_sock_daddr($sk), __ip_sock_family($sk)) sport = __tcp_sock_sport($sk) dport = __tcp_sock_dport($sk) } /** * probe tcp.disconnect.return - TCP socket disconnection complete * @name: Name of this probe * @ret: Error code (0: no error) * * Context: * The process which disconnects tcp */ probe tcp.disconnect.return = kernel.function("tcp_disconnect").return { name = "tcp.disconnect" ret = $return } /** * probe tcp.setsockopt - Call to setsockopt() * @name: Name of this probe * @sock: Network socket * @family: IP address family * @level: The level at which the socket options will be manipulated * @optname: TCP socket options (e.g. TCP_NODELAY, TCP_MAXSEG, etc) * @optstr: Resolves optname to a human-readable format * @optlen: Used to access values for setsockopt() * * Context: * The process which calls setsockopt */ probe tcp.setsockopt = tcp.ipv4.setsockopt, tcp.ipv6.setsockopt { } probe tcp.ipv4.setsockopt = kernel.function("tcp_setsockopt") { name = "tcp.ipv4.setsockopt" sock = $sk family = __ip_sock_family($sk) level = $level optname = $optname optstr = tcp_sockopt_str($optname) optlen = $optlen } probe tcp.ipv6.setsockopt = kernel.function("ipv6_setsockopt")!, module("ipv6").function("ipv6_setsockopt") { name = "tcp.ipv6.setsockopt" sock = $sk family = __ip_sock_family($sk) level = $level optname = $optname optstr = tcp_ipv6_sockopt_str($optname) optlen = $optlen } /** * probe tcp.setsockopt.return - Return from setsockopt() * @name: Name of this probe * @ret: Error code (0: no error) * * Context: * The process which calls setsockopt */ probe tcp.setsockopt.return = tcp.ipv4.setsockopt.return, tcp.ipv6.setsockopt.return { } probe tcp.ipv4.setsockopt.return = kernel.function("tcp_setsockopt").return { name = "tcp.ipv4.setsockopt" ret = $return } probe tcp.ipv6.setsockopt.return = kernel.function("ipv6_setsockopt").return!, module("ipv6").function("ipv6_setsockopt").return { name = "tcp.ipv6.setsockopt" ret = $return } /** * probe tcp.receive - Called when a TCP packet is received * @name: Name of the probe point * @iphdr: IP header address * @protocol: Packet protocol from driver * @family: IP address family * @saddr: A string representing the source IP address * @daddr: A string representing the destination IP address * @sport: TCP source port * @dport: TCP destination port * @urg: TCP URG flag * @ack: TCP ACK flag * @psh: TCP PSH flag * @rst: TCP RST flag * @syn: TCP SYN flag * @fin: TCP FIN flag */ probe tcp.receive = tcp.ipv4.receive, tcp.ipv6.receive { } probe tcp.ipv4.receive = kernel.function("tcp_v4_rcv") { name = "tcp.ipv4.receive" # If we're here, by definition we're doing AF_INET, not AF_INET6. family = @const("AF_INET") try { iphdr = __get_skb_iphdr($skb) saddr = format_ipaddr(__ip_skb_saddr(iphdr), @const("AF_INET")) daddr = format_ipaddr(__ip_skb_daddr(iphdr), @const("AF_INET")) protocol = __ip_skb_proto(iphdr) } catch { } try { tcphdr = __get_skb_tcphdr($skb) dport = __tcp_skb_dport(tcphdr) sport = __tcp_skb_sport(tcphdr) urg = __tcp_skb_urg(tcphdr) ack = __tcp_skb_ack(tcphdr) psh = __tcp_skb_psh(tcphdr) rst = __tcp_skb_rst(tcphdr) syn = __tcp_skb_syn(tcphdr) fin = __tcp_skb_fin(tcphdr) } catch { } } probe tcp.ipv6.receive = kernel.function("tcp_v6_rcv")!, module("ipv6").function("tcp_v6_rcv") { name = "tcp.ipv6.receive" # If we're here, by definition we're doing AF_INET6, not AF_INET. family = @const("AF_INET6") try { iphdr = __get_skb_iphdr(@choose_defined($skb, kernel_pointer($pskb))) saddr = format_ipaddr(&@cast(iphdr, "ipv6hdr", "kernel")->saddr, @const("AF_INET6")) daddr = format_ipaddr(&@cast(iphdr, "ipv6hdr", "kernel")->daddr, @const("AF_INET6")) } catch { } # If we're here, by definition we're doing IPPROTO_TCP. There # isn't a protocol field in 'struct ipv6hdr'. There is one in # 'struct sk_buff', but that protocol field is an Ethernet # Procol ID (ETH_P_*), not an IP protocol ID (IPPROTO_*). protocol = @const("IPPROTO_TCP") try { tcphdr = __get_skb_tcphdr(@choose_defined($skb, kernel_pointer($pskb))) dport = __tcp_skb_dport(tcphdr) sport = __tcp_skb_sport(tcphdr) urg = __tcp_skb_urg(tcphdr) ack = __tcp_skb_ack(tcphdr) psh = __tcp_skb_psh(tcphdr) rst = __tcp_skb_rst(tcphdr) syn = __tcp_skb_syn(tcphdr) fin = __tcp_skb_fin(tcphdr) } catch { } }