]>
git.proxmox.com Git - mirror_iproute2.git/blob - misc/ss.c
2 * ss.c "sockstat", socket statistics
4 * This program is free software; you can redistribute it and/or
5 * modify it under the terms of the GNU General Public License
6 * as published by the Free Software Foundation; either version
7 * 2 of the License, or (at your option) any later version.
9 * Authors: Alexey Kuznetsov, <kuznet@ms2.inr.ac.ru>
17 #include <sys/ioctl.h>
18 #include <sys/socket.h>
20 #include <netinet/in.h>
24 #include <arpa/inet.h>
32 #include "libnetlink.h"
36 #include <linux/tcp.h>
38 int resolve_hosts
= 0;
39 int resolve_services
= 1;
40 int preferred_family
= AF_UNSPEC
;
54 static const char *TCP_PROTO
= "tcp";
55 static const char *UDP_PROTO
= "udp";
56 static const char *RAW_PROTO
= "raw";
57 static const char *dg_proto
= NULL
;
72 #define PACKET_DBM ((1<<PACKET_DG_DB)|(1<<PACKET_R_DB))
73 #define UNIX_DBM ((1<<UNIX_DG_DB)|(1<<UNIX_ST_DB))
74 #define ALL_DB ((1<<MAX_DB)-1)
92 #define SS_ALL ((1<<SS_MAX)-1)
104 struct filter default_filter
= {
106 states
: SS_ALL
& ~((1<<SS_LISTEN
)|(1<<SS_CLOSE
)|(1<<SS_TIME_WAIT
)|(1<<SS_SYN_RECV
)),
107 families
: (1<<AF_INET
)|(1<<AF_INET6
),
110 struct filter current_filter
;
112 int generic_proc_open(char *env
, char *name
)
115 char *p
= getenv(env
);
117 p
= getenv("PROC_ROOT") ? : "/proc";
118 snprintf(store
, sizeof(store
)-1, "%s/%s", p
, name
);
121 return open(store
, O_RDONLY
);
124 int net_tcp_open(void)
126 return generic_proc_open("PROC_NET_TCP", "net/tcp");
129 int net_tcp6_open(void)
131 return generic_proc_open("PROC_NET_TCP6", "net/tcp6");
134 int net_udp_open(void)
136 return generic_proc_open("PROC_NET_UDP", "net/udp");
139 int net_udp6_open(void)
141 return generic_proc_open("PROC_NET_UDP6", "net/udp6");
144 int net_raw_open(void)
146 return generic_proc_open("PROC_NET_RAW", "net/raw");
149 int net_raw6_open(void)
151 return generic_proc_open("PROC_NET_RAW6", "net/raw6");
154 int net_unix_open(void)
156 return generic_proc_open("PROC_NET_UNIX", "net/unix");
159 int net_packet_open(void)
161 return generic_proc_open("PROC_NET_PACKET", "net/packet");
164 int net_netlink_open(void)
166 return generic_proc_open("PROC_NET_NETLINK", "net/netlink");
169 int slabinfo_open(void)
171 return generic_proc_open("PROC_SLABINFO", "slabinfo");
174 int net_sockstat_open(void)
176 return generic_proc_open("PROC_NET_SOCKSTAT", "net/sockstat");
179 int net_sockstat6_open(void)
181 return generic_proc_open("PROC_NET_SOCKSTAT6", "net/sockstat6");
184 int net_snmp_open(void)
186 return generic_proc_open("PROC_NET_SNMP", "net/snmp");
189 int net_netstat_open(void)
191 return generic_proc_open("PROC_NET_NETSTAT", "net/netstat");
194 int ephemeral_ports_open(void)
196 return generic_proc_open("PROC_IP_LOCAL_PORT_RANGE", "sys/net/ipv4/ip_local_port_range");
199 int find_users(int ino
, char *buf
, int buflen
)
213 sprintf(pattern
, "socket:[%d]", ino
);
214 pattern_len
= strlen(pattern
);
216 strncpy(name
, getenv("PROC_ROOT") ? : "/proc/", sizeof(name
)/2);
217 name
[sizeof(name
)/2] = 0;
218 if (strlen(name
) == 0 ||
219 name
[strlen(name
)-1] != '/')
221 nameoff
= strlen(name
);
222 if ((dir
= opendir(name
)) == NULL
)
225 while ((d
= readdir(dir
)) != NULL
) {
233 if (sscanf(d
->d_name
, "%d%c", &pid
, &crap
) != 1)
236 sprintf(name
+nameoff
, "%d/fd/", pid
);
238 if ((dir1
= opendir(name
)) == NULL
)
243 while ((d1
= readdir(dir1
)) != NULL
) {
247 if (sscanf(d1
->d_name
, "%d%c", &fd
, &crap
) != 1)
250 sprintf(name
+pos
, "%d", fd
);
251 n
= readlink(name
, lnk
, sizeof(lnk
)-1);
252 if (n
!= pattern_len
||
253 memcmp(lnk
, pattern
, n
))
256 if (ptr
-buf
>= buflen
-1)
259 if (process
[0] == 0) {
262 snprintf(tmp
, sizeof(tmp
), "%s/%d/stat",
263 getenv("PROC_ROOT") ? : "/proc", pid
);
264 if ((fp
= fopen(tmp
, "r")) != NULL
) {
265 fscanf(fp
, "%*d (%[^)])", process
);
270 snprintf(ptr
, buflen
-(ptr
-buf
), "(\"%s\",%d,%d),", process
, pid
, fd
);
283 /* Get stats from slab */
294 struct slabstat slabstat
;
296 const char *slabstat_ids
[] =
305 int get_slabstat(struct slabstat
*s
)
311 memset(s
, 0, sizeof(*s
));
313 if ((fp
= fdopen(slabinfo_open(), "r")) == NULL
)
316 cnt
= sizeof(*s
)/sizeof(int);
318 fgets(buf
, sizeof(buf
), fp
);
319 while(fgets(buf
, sizeof(buf
), fp
) != NULL
) {
321 for (i
=0; i
<sizeof(slabstat_ids
)/sizeof(slabstat_ids
[0]); i
++) {
322 if (memcmp(buf
, slabstat_ids
[i
], strlen(slabstat_ids
[i
])) == 0) {
323 sscanf(buf
, "%*s%d", ((int *)s
) + i
);
339 char *sstate_name
[] = {
354 char *sstate_namel
[] = {
384 unsigned long long sk
;
385 int rto
, ato
, qack
, cwnd
, ssthresh
;
397 char *print_ms_timer(int timeout
)
400 int secs
, msecs
, minutes
;
406 msecs
= timeout
%1000;
410 snprintf(buf
, sizeof(buf
)-16, "%dmin", minutes
);
417 sprintf(buf
+strlen(buf
), "%d%s", secs
, msecs
? "." : "sec");
420 sprintf(buf
+strlen(buf
), "%03dms", msecs
);
424 char *print_hz_timer(int timeout
)
427 return print_ms_timer(((timeout
*1000) + hz
-1)/hz
);
438 struct scache
*rlist
;
440 void init_service_resolver(void)
443 FILE *fp
= popen("/usr/sbin/rpcinfo -p 2>/dev/null", "r");
445 fgets(buf
, sizeof(buf
), fp
);
446 while (fgets(buf
, sizeof(buf
), fp
) != NULL
) {
447 unsigned int progn
, port
;
448 char proto
[128], prog
[128];
449 if (sscanf(buf
, "%u %*d %s %u %s", &progn
, proto
,
450 &port
, prog
+4) == 4) {
451 struct scache
*c
= malloc(sizeof(*c
));
454 memcpy(prog
, "rpc.", 4);
455 c
->name
= strdup(prog
);
456 if (strcmp(proto
, TCP_PROTO
) == 0)
457 c
->proto
= TCP_PROTO
;
458 else if (strcmp(proto
, UDP_PROTO
) == 0)
459 c
->proto
= UDP_PROTO
;
470 const char *__resolve_service(int port
)
474 for (c
= rlist
; c
; c
= c
->next
) {
475 if (c
->port
== port
&& c
->proto
== dg_proto
)
479 /* Even do not try default linux ephemeral port ranges:
480 * default /etc/services contains so much of useless crap
481 * wouldbe "allocated" to this area that resolution
482 * is really harmful. I shrug each time when seeing
483 * "socks" or "cfinger" in dumps.
485 if (port
< 32768 && (port
< 1024 || port
> 4999)) {
492 se
= getservbyport(htons(port
), dg_proto
);
501 const char *resolve_service(int port
)
503 static char buf
[128];
504 static struct scache cache
[256];
512 if (resolve_services
) {
513 if (dg_proto
== RAW_PROTO
) {
514 return inet_proto_n2a(port
, buf
, sizeof(buf
));
518 int hash
= (port
^(((unsigned long)dg_proto
)>>2))&255;
520 for (c
= &cache
[hash
]; c
; c
= c
->next
) {
521 if (c
->port
== port
&&
522 c
->proto
== dg_proto
) {
529 if ((res
= __resolve_service(port
)) != NULL
) {
530 if ((c
= malloc(sizeof(*c
))) == NULL
)
541 c
->name
= strdup(res
);
542 c
->next
= cache
[hash
].next
;
543 cache
[hash
].next
= c
;
551 sprintf(buf
, "%u", port
);
555 void formatted_print(inet_prefix
*a
, int port
)
558 const char *ap
= buf
;
561 est_len
= addr_width
;
563 if (a
->family
== AF_INET
) {
564 if (a
->data
[0] == 0) {
568 ap
= format_host(AF_INET
, 4, a
->data
, buf
, sizeof(buf
));
571 ap
= format_host(a
->family
, 16, a
->data
, buf
, sizeof(buf
));
572 est_len
= strlen(ap
);
573 if (est_len
<= addr_width
)
574 est_len
= addr_width
;
576 est_len
= addr_width
+ ((est_len
-addr_width
+3)/4)*4;
578 printf("%*s:%-*s ", est_len
, ap
, serv_width
, resolve_service(port
));
585 struct aafilter
*next
;
588 int inet2_addr_match(inet_prefix
*a
, inet_prefix
*p
, int plen
)
590 if (!inet_addr_match(a
, p
, plen
))
592 /* Cursed "v4 mapped" addresses: v4 mapped socket matches
593 * pure IPv4 rule, but v4-mapped rule selects only v4-mapped
595 if (p
->family
== AF_INET
&& a
->family
== AF_INET6
) {
596 if (a
->data
[0] == 0 && a
->data
[1] == 0 &&
597 a
->data
[2] == htonl(0xffff)) {
598 inet_prefix tmp
= *a
;
599 tmp
.data
[0] = a
->data
[3];
600 return inet_addr_match(&tmp
, p
, plen
);
606 int unix_match(inet_prefix
*a
, inet_prefix
*p
)
608 char *addr
, *pattern
;
609 memcpy(&addr
, a
->data
, sizeof(addr
));
610 memcpy(&pattern
, p
->data
, sizeof(pattern
));
615 return !fnmatch(pattern
, addr
, 0);
618 int run_ssfilter(struct ssfilter
*f
, struct tcpstat
*s
)
623 static int low
, high
=65535;
625 if (s
->local
.family
== AF_UNIX
) {
627 memcpy(&p
, s
->local
.data
, sizeof(p
));
628 return p
== NULL
|| (p
[0] == '@' && strlen(p
) == 6 &&
629 strspn(p
+1, "0123456789abcdef") == 5);
631 if (s
->local
.family
== AF_PACKET
)
632 return s
->lport
== 0 && s
->local
.data
== 0;
633 if (s
->local
.family
== AF_NETLINK
)
637 FILE *fp
= fdopen(ephemeral_ports_open(), "r");
639 fscanf(fp
, "%d%d", &low
, &high
);
643 return s
->lport
>= low
&& s
->lport
<= high
;
647 struct aafilter
*a
= (void*)f
->pred
;
648 if (a
->addr
.family
== AF_UNIX
)
649 return unix_match(&s
->remote
, &a
->addr
);
650 if (a
->port
!= -1 && a
->port
!= s
->rport
)
652 if (a
->addr
.bitlen
) {
654 if (!inet2_addr_match(&s
->remote
, &a
->addr
, a
->addr
.bitlen
))
656 } while ((a
= a
->next
) != NULL
);
663 struct aafilter
*a
= (void*)f
->pred
;
664 if (a
->addr
.family
== AF_UNIX
)
665 return unix_match(&s
->local
, &a
->addr
);
666 if (a
->port
!= -1 && a
->port
!= s
->lport
)
668 if (a
->addr
.bitlen
) {
670 if (!inet2_addr_match(&s
->local
, &a
->addr
, a
->addr
.bitlen
))
672 } while ((a
= a
->next
) != NULL
);
679 struct aafilter
*a
= (void*)f
->pred
;
680 return s
->rport
>= a
->port
;
684 struct aafilter
*a
= (void*)f
->pred
;
685 return s
->rport
<= a
->port
;
689 struct aafilter
*a
= (void*)f
->pred
;
690 return s
->lport
>= a
->port
;
694 struct aafilter
*a
= (void*)f
->pred
;
695 return s
->lport
<= a
->port
;
698 /* Yup. It is recursion. Sorry. */
700 return run_ssfilter(f
->pred
, s
) && run_ssfilter(f
->post
, s
);
702 return run_ssfilter(f
->pred
, s
) || run_ssfilter(f
->post
, s
);
704 return !run_ssfilter(f
->pred
, s
);
710 /* Relocate external jumps by reloc. */
711 void ssfilter_patch(char *a
, int len
, int reloc
)
714 struct tcpdiag_bc_op
*op
= (struct tcpdiag_bc_op
*)a
;
724 int ssfilter_bytecompile(struct ssfilter
*f
, char **bytecode
)
729 if (!(*bytecode
=malloc(4))) abort();
730 ((struct tcpdiag_bc_op
*)*bytecode
)[0] = (struct tcpdiag_bc_op
){ TCPDIAG_BC_AUTO
, 4, 8 };
736 struct aafilter
*a
= (void*)f
->pred
;
739 int code
= (f
->type
== SSF_DCOND
? TCPDIAG_BC_D_COND
: TCPDIAG_BC_S_COND
);
742 for (b
=a
; b
; b
=b
->next
) {
743 len
+= 4 + sizeof(struct tcpdiag_hostcond
);
744 if (a
->addr
.family
== AF_INET6
)
751 if (!(ptr
= malloc(len
))) abort();
753 for (b
=a
; b
; b
=b
->next
) {
754 struct tcpdiag_bc_op
*op
= (struct tcpdiag_bc_op
*)ptr
;
755 int alen
= (a
->addr
.family
== AF_INET6
? 16 : 4);
756 int oplen
= alen
+ 4 + sizeof(struct tcpdiag_hostcond
);
757 struct tcpdiag_hostcond
*cond
= (struct tcpdiag_hostcond
*)(ptr
+4);
759 *op
= (struct tcpdiag_bc_op
){ code
, oplen
, oplen
+4 };
760 cond
->family
= a
->addr
.family
;
761 cond
->port
= a
->port
;
762 cond
->prefix_len
= a
->addr
.bitlen
;
763 memcpy(cond
->addr
, a
->addr
.data
, alen
);
766 op
= (struct tcpdiag_bc_op
*)ptr
;
767 *op
= (struct tcpdiag_bc_op
){ TCPDIAG_BC_JMP
, 4, len
- (ptr
-*bytecode
)};
771 return ptr
- *bytecode
;
775 struct aafilter
*x
= (void*)f
->pred
;
776 if (!(*bytecode
=malloc(8))) abort();
777 ((struct tcpdiag_bc_op
*)*bytecode
)[0] = (struct tcpdiag_bc_op
){ TCPDIAG_BC_D_GE
, 8, 12 };
778 ((struct tcpdiag_bc_op
*)*bytecode
)[1] = (struct tcpdiag_bc_op
){ 0, 0, x
->port
};
783 struct aafilter
*x
= (void*)f
->pred
;
784 if (!(*bytecode
=malloc(8))) abort();
785 ((struct tcpdiag_bc_op
*)*bytecode
)[0] = (struct tcpdiag_bc_op
){ TCPDIAG_BC_D_LE
, 8, 12 };
786 ((struct tcpdiag_bc_op
*)*bytecode
)[1] = (struct tcpdiag_bc_op
){ 0, 0, x
->port
};
791 struct aafilter
*x
= (void*)f
->pred
;
792 if (!(*bytecode
=malloc(8))) abort();
793 ((struct tcpdiag_bc_op
*)*bytecode
)[0] = (struct tcpdiag_bc_op
){ TCPDIAG_BC_S_GE
, 8, 12 };
794 ((struct tcpdiag_bc_op
*)*bytecode
)[1] = (struct tcpdiag_bc_op
){ 0, 0, x
->port
};
799 struct aafilter
*x
= (void*)f
->pred
;
800 if (!(*bytecode
=malloc(8))) abort();
801 ((struct tcpdiag_bc_op
*)*bytecode
)[0] = (struct tcpdiag_bc_op
){ TCPDIAG_BC_S_LE
, 8, 12 };
802 ((struct tcpdiag_bc_op
*)*bytecode
)[1] = (struct tcpdiag_bc_op
){ 0, 0, x
->port
};
808 char *a1
, *a2
, *a
, l1
, l2
;
809 l1
= ssfilter_bytecompile(f
->pred
, &a1
);
810 l2
= ssfilter_bytecompile(f
->post
, &a2
);
811 if (!(a
= malloc(l1
+l2
))) abort();
813 memcpy(a
+l1
, a2
, l2
);
815 ssfilter_patch(a
, l1
, l2
);
821 char *a1
, *a2
, *a
, l1
, l2
;
822 l1
= ssfilter_bytecompile(f
->pred
, &a1
);
823 l2
= ssfilter_bytecompile(f
->post
, &a2
);
824 if (!(a
= malloc(l1
+l2
+4))) abort();
826 memcpy(a
+l1
+4, a2
, l2
);
828 *(struct tcpdiag_bc_op
*)(a
+l1
) = (struct tcpdiag_bc_op
){ TCPDIAG_BC_JMP
, 4, l2
+4 };
835 l1
= ssfilter_bytecompile(f
->pred
, &a1
);
836 if (!(a
= malloc(l1
+4))) abort();
839 *(struct tcpdiag_bc_op
*)(a
+l1
) = (struct tcpdiag_bc_op
){ TCPDIAG_BC_JMP
, 4, 8 };
848 int remember_he(struct aafilter
*a
, struct hostent
*he
)
850 char **ptr
= he
->h_addr_list
;
854 if (he
->h_addrtype
== AF_INET
)
856 else if (he
->h_addrtype
== AF_INET6
)
862 struct aafilter
*b
= a
;
863 if (a
->addr
.bitlen
) {
864 if ((b
= malloc(sizeof(*b
))) == NULL
)
870 memcpy(b
->addr
.data
, *ptr
, len
);
871 b
->addr
.bytelen
= len
;
872 b
->addr
.bitlen
= len
*8;
873 b
->addr
.family
= he
->h_addrtype
;
880 int get_dns_host(struct aafilter
*a
, char *addr
, int fam
)
891 he
= gethostbyname2(addr
, fam
== AF_UNSPEC
? AF_INET
: fam
);
893 cnt
= remember_he(a
, he
);
894 if (fam
== AF_UNSPEC
) {
895 he
= gethostbyname2(addr
, AF_INET6
);
897 cnt
+= remember_he(a
, he
);
906 struct rtnl_handle rth
;
913 const char *xll_index_to_name(int index
)
917 return ll_index_to_name(index
);
920 int xll_name_to_index(char *dev
)
924 return ll_name_to_index(dev
);
927 void *parse_hostcond(char *addr
)
931 struct aafilter
*res
;
932 int fam
= preferred_family
;
934 memset(&a
, 0, sizeof(a
));
937 if (fam
== AF_UNIX
|| strncmp(addr
, "unix:", 5) == 0) {
939 a
.addr
.family
= AF_UNIX
;
940 if (strncmp(addr
, "unix:", 5) == 0)
943 a
.addr
.bitlen
= 8*strlen(p
);
944 memcpy(a
.addr
.data
, &p
, sizeof(p
));
948 if (fam
== AF_PACKET
|| strncmp(addr
, "link:", 5) == 0) {
949 a
.addr
.family
= AF_PACKET
;
951 if (strncmp(addr
, "link:", 5) == 0)
953 port
= strchr(addr
, ':');
956 if (port
[1] && strcmp(port
+1, "*")) {
957 if (get_integer(&a
.port
, port
+1, 0)) {
958 if ((a
.port
= xll_name_to_index(port
+1)) <= 0)
963 if (addr
[0] && strcmp(addr
, "*")) {
966 if (ll_proto_a2n(&tmp
, addr
))
968 a
.addr
.data
[0] = ntohs(tmp
);
973 if (fam
== AF_NETLINK
|| strncmp(addr
, "netlink:", 8) == 0) {
974 a
.addr
.family
= AF_NETLINK
;
976 if (strncmp(addr
, "netlink:", 8) == 0)
978 port
= strchr(addr
, ':');
981 if (port
[1] && strcmp(port
+1, "*")) {
982 if (get_integer(&a
.port
, port
+1, 0)) {
983 if (strcmp(port
+1, "kernel") == 0)
990 if (addr
[0] && strcmp(addr
, "*")) {
992 if (get_u32(a
.addr
.data
, addr
, 0)) {
993 if (strcmp(addr
, "rtnl") == 0)
995 else if (strcmp(addr
, "fw") == 0)
997 else if (strcmp(addr
, "tcpdiag") == 0)
1006 if (strncmp(addr
, "inet:", 5) == 0) {
1009 } else if (strncmp(addr
, "inet6:", 6) == 0) {
1014 /* URL-like literal [] */
1015 if (addr
[0] == '[') {
1017 if ((port
= strchr(addr
, ']')) == NULL
)
1020 } else if (addr
[0] == '*') {
1023 port
= strrchr(strchr(addr
, '/') ? : addr
, ':');
1025 if (port
&& *port
) {
1029 if (*port
&& *port
!= '*') {
1030 if (get_integer(&a
.port
, port
, 0)) {
1031 struct servent
*se1
= NULL
;
1032 struct servent
*se2
= NULL
;
1033 if (current_filter
.dbs
&(1<<UDP_DB
))
1034 se1
= getservbyname(port
, UDP_PROTO
);
1035 if (current_filter
.dbs
&(1<<TCP_DB
))
1036 se2
= getservbyname(port
, TCP_PROTO
);
1037 if (se1
&& se2
&& se1
->s_port
!= se2
->s_port
) {
1038 fprintf(stderr
, "Error: ambiguous port \"%s\".\n", port
);
1044 a
.port
= ntohs(se1
->s_port
);
1047 for (s
= rlist
; s
; s
= s
->next
) {
1048 if ((s
->proto
== UDP_PROTO
&&
1049 (current_filter
.dbs
&(1<<UDP_DB
))) ||
1050 (s
->proto
== TCP_PROTO
&&
1051 (current_filter
.dbs
&(1<<TCP_DB
)))) {
1052 if (s
->name
&& strcmp(s
->name
, port
) == 0) {
1053 if (a
.port
> 0 && a
.port
!= s
->port
) {
1054 fprintf(stderr
, "Error: ambiguous port \"%s\".\n", port
);
1062 fprintf(stderr
, "Error: \"%s\" does not look like a port.\n", port
);
1069 if (addr
&& *addr
&& *addr
!= '*') {
1070 if (get_prefix_1(&a
.addr
, addr
, fam
)) {
1071 if (get_dns_host(&a
, addr
, fam
)) {
1072 fprintf(stderr
, "Error: an inet prefix is expected rather than \"%s\".\n", addr
);
1079 res
= malloc(sizeof(*res
));
1081 memcpy(res
, &a
, sizeof(a
));
1085 int tcp_show_line(char *line
, struct filter
*f
, int family
)
1088 char *loc
, *rem
, *data
;
1093 if ((p
= strchr(line
, ':')) == NULL
)
1097 if ((p
= strchr(loc
, ':')) == NULL
)
1102 if ((p
= strchr(rem
, ':')) == NULL
)
1108 int state
= (data
[1] >= 'A') ? (data
[1] - 'A' + 10) : (data
[1] - '0');
1110 if (!(f
->states
& (1<<state
)))
1114 s
.local
.family
= s
.remote
.family
= family
;
1115 if (family
== AF_INET
) {
1116 sscanf(loc
, "%x:%x", s
.local
.data
, (unsigned*)&s
.lport
);
1117 sscanf(rem
, "%x:%x", s
.remote
.data
, (unsigned*)&s
.rport
);
1118 s
.local
.bytelen
= s
.remote
.bytelen
= 4;
1120 sscanf(loc
, "%08x%08x%08x%08x:%x",
1126 sscanf(rem
, "%08x%08x%08x%08x:%x",
1132 s
.local
.bytelen
= s
.remote
.bytelen
= 16;
1135 if (f
->f
&& run_ssfilter(f
->f
, &s
) == 0)
1139 n
= sscanf(data
, "%x %x:%x %x:%x %x %d %d %d %d %llx %d %d %d %d %d %[^\n]\n",
1140 &s
.state
, &s
.wq
, &s
.rq
,
1141 &s
.timer
, &s
.timeout
, &s
.retrs
, &s
.uid
, &s
.probes
, &s
.ino
,
1142 &s
.refcnt
, &s
.sk
, &s
.rto
, &s
.ato
, &s
.qack
,
1143 &s
.cwnd
, &s
.ssthresh
, opt
);
1156 printf("%-*s ", netid_width
, "tcp");
1158 printf("%-*s ", state_width
, sstate_name
[s
.state
]);
1160 printf("%-6d %-6d ", s
.rq
, s
.wq
);
1162 formatted_print(&s
.local
, s
.lport
);
1163 formatted_print(&s
.remote
, s
.rport
);
1169 printf(" timer:(%s,%s,%d)",
1171 print_hz_timer(s
.timeout
),
1172 s
.timer
!= 1 ? s
.probes
: s
.retrs
);
1176 if (s
.rto
&& s
.rto
!= 3*get_hz())
1177 printf(" rto:%g", (double)s
.rto
/get_hz());
1179 printf(" ato:%g", (double)s
.ato
/get_hz());
1181 printf(" cwnd:%d", s
.cwnd
);
1182 if (s
.ssthresh
!= -1)
1183 printf(" ssthresh:%d", s
.ssthresh
);
1185 printf(" qack:%d", s
.qack
/2);
1191 if (find_users(s
.ino
, ubuf
, sizeof(ubuf
)) > 0)
1192 printf(" users:(%s)", ubuf
);
1196 printf(" uid:%u", (unsigned)s
.uid
);
1197 printf(" ino:%u", (unsigned)s
.ino
);
1198 printf(" sk:%llx", s
.sk
);
1200 printf(" opt:\"%s\"", opt
);
1207 int generic_record_read(int fd
, char *buf
, int bufsize
,
1208 int (*worker
)(char*, struct filter
*, int),
1209 struct filter
*f
, int fam
)
1216 /* Load the first chunk and calculate record length from it. */
1217 n
= read(fd
, buf
, bufsize
);
1220 /* I _know_ that this is wrong, do not remind. :-)
1221 * But this works nowadays. */
1224 p
= memchr(buf
, '\n', n
);
1225 if (p
== NULL
|| (p
-buf
) >= n
)
1226 goto outwrongformat
;
1227 recsize
= (p
-buf
)+1;
1231 while ((p
+recsize
) - buf
<= n
) {
1232 if (p
[recsize
-1] != '\n')
1233 goto outwrongformat
;
1235 if (worker(p
, f
, fam
) < 0)
1240 int remains
= (buf
+bufsize
) - p
;
1241 memcpy(buf
, p
, remains
);
1243 n
= read(fd
, p
, (buf
+bufsize
) - p
);
1246 if (n
< (buf
+bufsize
) - p
) {
1250 goto outwrongformat
;
1258 goto outwrongformat
;
1272 int tcp_show_sock(struct nlmsghdr
*nlh
, struct filter
*f
)
1274 struct tcpdiagmsg
*r
= NLMSG_DATA(nlh
);
1277 s
.state
= r
->tcpdiag_state
;
1278 s
.local
.family
= s
.remote
.family
= r
->tcpdiag_family
;
1279 s
.lport
= ntohs(r
->id
.tcpdiag_sport
);
1280 s
.rport
= ntohs(r
->id
.tcpdiag_dport
);
1281 if (s
.local
.family
== AF_INET
) {
1282 s
.local
.bytelen
= s
.remote
.bytelen
= 4;
1284 s
.local
.bytelen
= s
.remote
.bytelen
= 16;
1286 memcpy(s
.local
.data
, r
->id
.tcpdiag_src
, s
.local
.bytelen
);
1287 memcpy(s
.remote
.data
, r
->id
.tcpdiag_dst
, s
.local
.bytelen
);
1289 if (f
&& f
->f
&& run_ssfilter(f
->f
, &s
) == 0)
1293 printf("%-*s ", netid_width
, "tcp");
1295 printf("%-*s ", state_width
, sstate_name
[s
.state
]);
1297 printf("%-6d %-6d ", r
->tcpdiag_rqueue
, r
->tcpdiag_wqueue
);
1299 formatted_print(&s
.local
, s
.lport
);
1300 formatted_print(&s
.remote
, s
.rport
);
1303 if (r
->tcpdiag_timer
) {
1304 if (r
->tcpdiag_timer
> 4)
1305 r
->tcpdiag_timer
= 5;
1306 printf(" timer:(%s,%s,%d)",
1307 tmr_name
[r
->tcpdiag_timer
],
1308 print_ms_timer(r
->tcpdiag_expires
),
1309 r
->tcpdiag_retrans
);
1314 if (find_users(r
->tcpdiag_inode
, ubuf
, sizeof(ubuf
)) > 0)
1315 printf(" users:(%s)", ubuf
);
1319 printf(" uid:%u", (unsigned)r
->tcpdiag_uid
);
1320 printf(" ino:%u", (unsigned)r
->tcpdiag_inode
);
1321 printf(" sk:%08x", r
->id
.tcpdiag_cookie
[0]);
1322 if (r
->id
.tcpdiag_cookie
[1] != 0)
1323 printf("%08x", r
->id
.tcpdiag_cookie
[1]);
1325 if (show_mem
|| show_tcpinfo
) {
1326 struct rtattr
* tb
[TCPDIAG_MAX
+1];
1327 struct tcpdiag_meminfo
*minfo
= NULL
;
1328 struct tcp_info
*info
= NULL
;
1330 memset(tb
, 0, sizeof(tb
));
1331 parse_rtattr(tb
, TCPDIAG_MAX
, (struct rtattr
*)(r
+1),
1332 nlh
->nlmsg_len
- NLMSG_LENGTH(sizeof(*r
)));
1333 if (tb
[TCPDIAG_MEMINFO
])
1334 minfo
= RTA_DATA(tb
[TCPDIAG_MEMINFO
]);
1335 if (tb
[TCPDIAG_INFO
])
1336 info
= RTA_DATA(tb
[TCPDIAG_INFO
]);
1338 printf(" mem:(r%u,w%u,f%u,t%u)",
1339 minfo
->tcpdiag_rmem
,
1340 minfo
->tcpdiag_wmem
,
1341 minfo
->tcpdiag_fmem
,
1342 minfo
->tcpdiag_tmem
);
1346 if (info
->tcpi_rto
&& info
->tcpi_rto
!= 3000000)
1347 printf(" rto:%g", (double)info
->tcpi_rto
/1000);
1349 printf(" rtt:%g/%g", (double)info
->tcpi_rtt
/1000,
1350 (double)info
->tcpi_rttvar
/1000);
1352 printf(" ato:%g", (double)info
->tcpi_ato
/1000);
1353 if (info
->tcpi_snd_cwnd
!= 2)
1354 printf(" cwnd:%d", info
->tcpi_snd_cwnd
);
1355 if (info
->tcpi_snd_ssthresh
< 0xFFFF)
1356 printf(" ssthresh:%d", info
->tcpi_snd_ssthresh
);
1358 #warning No TCP_INFO. Please, do not repeat this experiment, use right kernel.
1359 printf(" MORE_INFO_PROVIDED_YOU_COMPILED_SS_RIGHT");
1369 int tcp_show_netlink(struct filter
*f
, FILE *dump_fp
)
1372 struct sockaddr_nl nladdr
;
1374 struct nlmsghdr nlh
;
1375 struct tcpdiagreq r
;
1382 struct iovec iov
[3];
1384 if ((fd
= socket(AF_NETLINK
, SOCK_RAW
, NETLINK_TCPDIAG
)) < 0)
1387 memset(&nladdr
, 0, sizeof(nladdr
));
1388 nladdr
.nl_family
= AF_NETLINK
;
1390 req
.nlh
.nlmsg_len
= sizeof(req
);
1391 req
.nlh
.nlmsg_type
= TCPDIAG_GETSOCK
;
1392 req
.nlh
.nlmsg_flags
= NLM_F_ROOT
|NLM_F_MATCH
|NLM_F_REQUEST
;
1393 req
.nlh
.nlmsg_pid
= 0;
1394 req
.nlh
.nlmsg_seq
= 123456;
1395 memset(&req
.r
, 0, sizeof(req
.r
));
1396 req
.r
.tcpdiag_family
= AF_INET
;
1397 req
.r
.tcpdiag_states
= f
->states
;
1399 req
.r
.tcpdiag_ext
|= (1<<(TCPDIAG_MEMINFO
-1));
1401 req
.r
.tcpdiag_ext
|= (1<<(TCPDIAG_INFO
-1));
1403 iov
[0] = (struct iovec
){ &req
, sizeof(req
) };
1405 bclen
= ssfilter_bytecompile(f
->f
, &bc
);
1406 rta
.rta_type
= TCPDIAG_REQ_BYTECODE
;
1407 rta
.rta_len
= RTA_LENGTH(bclen
);
1408 iov
[1] = (struct iovec
){ &rta
, sizeof(rta
) };
1409 iov
[2] = (struct iovec
){ bc
, bclen
};
1410 req
.nlh
.nlmsg_len
+= RTA_LENGTH(bclen
);
1413 msg
= (struct msghdr
) {
1414 (void*)&nladdr
, sizeof(nladdr
),
1420 if (sendmsg(fd
, &msg
, 0) < 0)
1424 iov
[0] = (struct iovec
){ buf
, sizeof(buf
) };
1430 msg
= (struct msghdr
) {
1431 (void*)&nladdr
, sizeof(nladdr
),
1437 status
= recvmsg(fd
, &msg
, 0);
1446 fprintf(stderr
, "EOF on netlink\n");
1451 fwrite(buf
, 1, NLMSG_ALIGN(status
), dump_fp
);
1453 h
= (struct nlmsghdr
*)buf
;
1454 while (NLMSG_OK(h
, status
)) {
1457 if (/*h->nlmsg_pid != rth->local.nl_pid ||*/
1458 h
->nlmsg_seq
!= 123456)
1461 if (h
->nlmsg_type
== NLMSG_DONE
)
1463 if (h
->nlmsg_type
== NLMSG_ERROR
) {
1464 struct nlmsgerr
*err
= (struct nlmsgerr
*)NLMSG_DATA(h
);
1465 if (h
->nlmsg_len
< NLMSG_LENGTH(sizeof(struct nlmsgerr
))) {
1466 fprintf(stderr
, "ERROR truncated\n");
1468 errno
= -err
->error
;
1469 perror("TCPDIAG answers");
1474 err
= tcp_show_sock(h
, NULL
);
1480 h
= NLMSG_NEXT(h
, status
);
1482 if (msg
.msg_flags
& MSG_TRUNC
) {
1483 fprintf(stderr
, "Message truncated\n");
1487 fprintf(stderr
, "!!!Remnant of size %d\n", status
);
1494 int tcp_show_netlink_file(struct filter
*f
)
1499 if ((fp
= fopen(getenv("TCPDIAG_FILE"), "r")) == NULL
) {
1500 perror("fopen($TCPDIAG_FILE)");
1506 struct nlmsghdr
*h
= (struct nlmsghdr
*)buf
;
1508 status
= fread(buf
, 1, sizeof(*h
), fp
);
1510 perror("Reading header from $TCPDIAG_FILE");
1513 if (status
!= sizeof(*h
)) {
1514 perror("Unexpected EOF reading $TCPDIAG_FILE");
1518 status
= fread(h
+1, 1, NLMSG_ALIGN(h
->nlmsg_len
-sizeof(*h
)), fp
);
1521 perror("Reading $TCPDIAG_FILE");
1524 if (status
+ sizeof(*h
) < h
->nlmsg_len
) {
1525 perror("Unexpected EOF reading $TCPDIAG_FILE");
1529 /* The only legal exit point */
1530 if (h
->nlmsg_type
== NLMSG_DONE
)
1533 if (h
->nlmsg_type
== NLMSG_ERROR
) {
1534 struct nlmsgerr
*err
= (struct nlmsgerr
*)NLMSG_DATA(h
);
1535 if (h
->nlmsg_len
< NLMSG_LENGTH(sizeof(struct nlmsgerr
))) {
1536 fprintf(stderr
, "ERROR truncated\n");
1538 errno
= -err
->error
;
1539 perror("TCPDIAG answered");
1544 err
= tcp_show_sock(h
, f
);
1550 int tcp_show(struct filter
*f
)
1554 int bufsize
= 64*1024;
1556 dg_proto
= TCP_PROTO
;
1558 if (getenv("TCPDIAG_FILE"))
1559 return tcp_show_netlink_file(f
);
1561 if (!getenv("PROC_NET_TCP") && !getenv("PROC_ROOT")
1562 && tcp_show_netlink(f
, NULL
) == 0)
1565 /* Sigh... We have to parse /proc/net/tcp... */
1567 /* Estimate amount of sockets and try to allocate
1568 * huge buffer to read all the table at one read.
1569 * Limit it by 16MB though. The assumption is: as soon as
1570 * kernel was able to hold information about N connections,
1571 * it is able to give us some memory for snapshot.
1574 int guess
= slabstat
.socks
+slabstat
.tcp_syns
;
1575 if (f
->states
&(1<<SS_TIME_WAIT
))
1576 guess
+= slabstat
.tcp_tws
;
1577 if (guess
> (16*1024*1024)/128)
1578 guess
= (16*1024*1024)/128;
1580 if (guess
> bufsize
)
1583 while (bufsize
>= 64*1024) {
1584 if ((buf
= malloc(bufsize
)) != NULL
)
1593 if (f
->families
& (1<<AF_INET
)) {
1594 if ((fd
= net_tcp_open()) < 0)
1596 if (generic_record_read(fd
, buf
, bufsize
, tcp_show_line
, f
, AF_INET
))
1601 if ((f
->families
& (1<<AF_INET6
)) &&
1602 (fd
= net_tcp6_open()) >= 0) {
1603 if (generic_record_read(fd
, buf
, bufsize
, tcp_show_line
, f
, AF_INET6
))
1613 int saved_errno
= errno
;
1618 errno
= saved_errno
;
1624 int dgram_show_line(char *line
, struct filter
*f
, int family
)
1627 char *loc
, *rem
, *data
;
1632 if ((p
= strchr(line
, ':')) == NULL
)
1636 if ((p
= strchr(loc
, ':')) == NULL
)
1641 if ((p
= strchr(rem
, ':')) == NULL
)
1647 int state
= (data
[1] >= 'A') ? (data
[1] - 'A' + 10) : (data
[1] - '0');
1649 if (!(f
->states
& (1<<state
)))
1653 s
.local
.family
= s
.remote
.family
= family
;
1654 if (family
== AF_INET
) {
1655 sscanf(loc
, "%x:%x", s
.local
.data
, (unsigned*)&s
.lport
);
1656 sscanf(rem
, "%x:%x", s
.remote
.data
, (unsigned*)&s
.rport
);
1657 s
.local
.bytelen
= s
.remote
.bytelen
= 4;
1659 sscanf(loc
, "%08x%08x%08x%08x:%x",
1665 sscanf(rem
, "%08x%08x%08x%08x:%x",
1671 s
.local
.bytelen
= s
.remote
.bytelen
= 16;
1674 if (f
->f
&& run_ssfilter(f
->f
, &s
) == 0)
1678 n
= sscanf(data
, "%x %x:%x %*x:%*x %*x %d %*d %d %d %llx %[^\n]\n",
1679 &s
.state
, &s
.wq
, &s
.rq
,
1681 &s
.refcnt
, &s
.sk
, opt
);
1687 printf("%-*s ", netid_width
, dg_proto
);
1689 printf("%-*s ", state_width
, sstate_name
[s
.state
]);
1691 printf("%-6d %-6d ", s
.rq
, s
.wq
);
1693 formatted_print(&s
.local
, s
.lport
);
1694 formatted_print(&s
.remote
, s
.rport
);
1698 if (find_users(s
.ino
, ubuf
, sizeof(ubuf
)) > 0)
1699 printf(" users:(%s)", ubuf
);
1704 printf(" uid=%u", (unsigned)s
.uid
);
1705 printf(" ino=%u", (unsigned)s
.ino
);
1706 printf(" sk=%llx", s
.sk
);
1708 printf(" opt:\"%s\"", opt
);
1716 int udp_show(struct filter
*f
)
1720 int bufsize
= sizeof(buf
);
1722 dg_proto
= UDP_PROTO
;
1724 if (f
->families
&(1<<AF_INET
)) {
1725 if ((fd
= net_udp_open()) < 0)
1727 if (generic_record_read(fd
, buf
, bufsize
, dgram_show_line
, f
, AF_INET
))
1732 if ((f
->families
&(1<<AF_INET6
)) &&
1733 (fd
= net_udp6_open()) >= 0) {
1734 if (generic_record_read(fd
, buf
, bufsize
, dgram_show_line
, f
, AF_INET6
))
1742 int saved_errno
= errno
;
1745 errno
= saved_errno
;
1750 int raw_show(struct filter
*f
)
1754 int bufsize
= sizeof(buf
);
1756 dg_proto
= RAW_PROTO
;
1758 if (f
->families
&(1<<AF_INET
)) {
1759 if ((fd
= net_raw_open()) < 0)
1761 if (generic_record_read(fd
, buf
, bufsize
, dgram_show_line
, f
, AF_INET
))
1766 if ((f
->families
&(1<<AF_INET6
)) &&
1767 (fd
= net_raw6_open()) >= 0) {
1768 if (generic_record_read(fd
, buf
, bufsize
, dgram_show_line
, f
, AF_INET6
))
1776 int saved_errno
= errno
;
1779 errno
= saved_errno
;
1787 struct unixstat
*next
;
1799 int unix_state_map
[] = { SS_CLOSE
, SS_SYN_SENT
,
1800 SS_ESTABLISHED
, SS_CLOSING
};
1803 #define MAX_UNIX_REMEMBER (1024*1024/sizeof(struct unixstat))
1805 void unix_list_free(struct unixstat
*list
)
1808 struct unixstat
*s
= list
;
1816 void unix_list_print(struct unixstat
*list
, struct filter
*f
)
1821 for (s
= list
; s
; s
= s
->next
) {
1822 if (!(f
->states
& (1<<s
->state
)))
1824 if (s
->type
== SOCK_STREAM
&& !(f
->dbs
&(1<<UNIX_ST_DB
)))
1826 if (s
->type
== SOCK_DGRAM
&& !(f
->dbs
&(1<<UNIX_DG_DB
)))
1832 for (p
= list
; p
; p
= p
->next
) {
1833 if (s
->peer
== p
->ino
)
1839 peer
= p
->name
? : "*";
1845 tst
.local
.family
= AF_UNIX
;
1846 tst
.remote
.family
= AF_UNIX
;
1847 memcpy(tst
.local
.data
, &s
->name
, sizeof(s
->name
));
1848 if (strcmp(peer
, "*") == 0)
1849 memset(tst
.remote
.data
, 0, sizeof(peer
));
1851 memcpy(tst
.remote
.data
, &peer
, sizeof(peer
));
1852 if (run_ssfilter(f
->f
, &tst
) == 0)
1857 printf("%-*s ", netid_width
,
1858 s
->type
== SOCK_STREAM
? "u_str" : "u_dgr");
1860 printf("%-*s ", state_width
, sstate_name
[s
->state
]);
1861 printf("%-6d %-6d ", s
->rq
, s
->wq
);
1862 printf("%*s %-*d %*s %-*d",
1863 addr_width
, s
->name
? : "*", serv_width
, s
->ino
,
1864 addr_width
, peer
, serv_width
, s
->peer
);
1867 if (find_users(s
->ino
, ubuf
, sizeof(ubuf
)) > 0)
1868 printf(" users:(%s)", ubuf
);
1874 int unix_show(struct filter
*f
)
1881 struct unixstat
*list
= NULL
;
1883 if ((fp
= fdopen(net_unix_open(), "r")) == NULL
)
1885 fgets(buf
, sizeof(buf
)-1, fp
);
1887 if (memcmp(buf
, "Peer", 4) == 0)
1891 while (fgets(buf
, sizeof(buf
)-1, fp
)) {
1892 struct unixstat
*u
, **insp
;
1895 if (!(u
= malloc(sizeof(*u
))))
1899 if (sscanf(buf
, "%x: %x %x %x %x %x %d %s",
1900 &u
->peer
, &u
->rq
, &u
->wq
, &flags
, &u
->type
,
1901 &u
->state
, &u
->ino
, name
) < 8)
1904 if (flags
&(1<<16)) {
1905 u
->state
= SS_LISTEN
;
1907 u
->state
= unix_state_map
[u
->state
-1];
1908 if (u
->type
== SOCK_DGRAM
&&
1909 u
->state
== SS_CLOSE
&&
1911 u
->state
= SS_ESTABLISHED
;
1922 if (u
->type
< (*insp
)->type
||
1923 (u
->type
== (*insp
)->type
&&
1924 u
->ino
< (*insp
)->ino
))
1926 insp
= &(*insp
)->next
;
1932 if ((u
->name
= malloc(strlen(name
)+1)) == NULL
)
1934 strcpy(u
->name
, name
);
1936 if (++cnt
> MAX_UNIX_REMEMBER
) {
1937 unix_list_print(list
, f
);
1938 unix_list_free(list
);
1945 unix_list_print(list
, f
);
1946 unix_list_free(list
);
1955 int packet_show(struct filter
*f
)
1966 unsigned long long sk
;
1968 if (!(f
->states
& (1<<SS_CLOSE
)))
1971 if ((fp
= fdopen(net_packet_open(), "r")) == NULL
)
1973 fgets(buf
, sizeof(buf
)-1, fp
);
1975 while (fgets(buf
, sizeof(buf
)-1, fp
)) {
1976 sscanf(buf
, "%llx %*d %d %x %d %d %u %u %u",
1978 &type
, &prot
, &iface
, &state
,
1981 if (type
== SOCK_RAW
&& !(f
->dbs
&(1<<PACKET_R_DB
)))
1983 if (type
== SOCK_DGRAM
&& !(f
->dbs
&(1<<PACKET_DG_DB
)))
1987 tst
.local
.family
= AF_PACKET
;
1988 tst
.remote
.family
= AF_PACKET
;
1991 tst
.local
.data
[0] = prot
;
1992 tst
.remote
.data
[0] = 0;
1993 if (run_ssfilter(f
->f
, &tst
) == 0)
1998 printf("%-*s ", netid_width
,
1999 type
== SOCK_RAW
? "p_raw" : "p_dgr");
2001 printf("%-*s ", state_width
, "UNCONN");
2002 printf("%-6d %-6d ", rq
, 0);
2004 printf("%*s:", addr_width
, "*");
2007 printf("%*s:", addr_width
,
2008 ll_proto_n2a(htons(prot
), tb
, sizeof(tb
)));
2011 printf("%-*s ", serv_width
, "*");
2013 printf("%-*s ", serv_width
, xll_index_to_name(iface
));
2016 addr_width
, "", serv_width
, "");
2020 if (find_users(ino
, ubuf
, sizeof(ubuf
)) > 0)
2021 printf(" users:(%s)", ubuf
);
2024 printf(" ino=%u uid=%u sk=%llx", ino
, uid
, sk
);
2032 int netlink_show(struct filter
*f
)
2039 unsigned long long sk
, cb
;
2041 if (!(f
->states
& (1<<SS_CLOSE
)))
2044 if ((fp
= fdopen(net_netlink_open(), "r")) == NULL
)
2046 fgets(buf
, sizeof(buf
)-1, fp
);
2048 while (fgets(buf
, sizeof(buf
)-1, fp
)) {
2049 sscanf(buf
, "%llx %d %d %x %d %d %llx %d",
2051 &prot
, &pid
, &groups
, &rq
, &wq
, &cb
, &rc
);
2055 tst
.local
.family
= AF_NETLINK
;
2056 tst
.remote
.family
= AF_NETLINK
;
2059 tst
.local
.data
[0] = prot
;
2060 tst
.remote
.data
[0] = 0;
2061 if (run_ssfilter(f
->f
, &tst
) == 0)
2066 printf("%-*s ", netid_width
, "nl");
2068 printf("%-*s ", state_width
, "UNCONN");
2069 printf("%-6d %-6d ", rq
, wq
);
2070 if (resolve_services
&& prot
== 0)
2071 printf("%*s:", addr_width
, "rtnl");
2072 else if (resolve_services
&& prot
== 3)
2073 printf("%*s:", addr_width
, "fw");
2074 else if (resolve_services
&& prot
== 4)
2075 printf("%*s:", addr_width
, "tcpdiag");
2077 printf("%*d:", addr_width
, prot
);
2079 printf("%-*s ", serv_width
, "*");
2080 } else if (resolve_services
) {
2084 printf("%-*s ", serv_width
, "kernel");
2085 } else if (pid
> 0) {
2088 sprintf(procname
, "%s/%d/stat",
2089 getenv("PROC_ROOT") ? : "/proc", pid
);
2090 if ((fp
= fopen(procname
, "r")) != NULL
) {
2091 if (fscanf(fp
, "%*d (%[^)])", procname
) == 1) {
2092 sprintf(procname
+strlen(procname
), "/%d", pid
);
2093 printf("%-*s ", serv_width
, procname
);
2100 printf("%-*d ", serv_width
, pid
);
2102 printf("%-*d ", serv_width
, pid
);
2105 addr_width
, "", serv_width
, "");
2108 printf(" sk=%llx cb=%llx groups=0x%08x", sk
, cb
, groups
);
2121 int get_snmp_int(char *proto
, char *key
, int *result
)
2125 int protolen
= strlen(proto
);
2126 int keylen
= strlen(key
);
2130 if ((fp
= fdopen(net_snmp_open(), "r")) == NULL
)
2133 while (fgets(buf
, sizeof(buf
), fp
) != NULL
) {
2136 if (memcmp(buf
, proto
, protolen
))
2138 while ((p
= strchr(p
, ' ')) != NULL
) {
2141 if (memcmp(p
, key
, keylen
) == 0 &&
2142 (p
[keylen
] == ' ' || p
[keylen
] == '\n'))
2145 if (fgets(buf
, sizeof(buf
), fp
) == NULL
)
2147 if (memcmp(buf
, proto
, protolen
))
2150 while ((p
= strchr(p
, ' ')) != NULL
) {
2153 sscanf(p
, "%d", result
);
2166 /* Get stats from sockstat */
2187 static void get_sockstat_line(char *line
, struct sockstat
*s
)
2189 char id
[256], rem
[256];
2191 if (sscanf(line
, "%[^ ] %[^\n]\n", id
, rem
) != 2)
2194 if (strcmp(id
, "sockets:") == 0)
2195 sscanf(rem
, "%*s%d", &s
->socks
);
2196 else if (strcmp(id
, "UDP:") == 0)
2197 sscanf(rem
, "%*s%d", &s
->udp4
);
2198 else if (strcmp(id
, "UDP6:") == 0)
2199 sscanf(rem
, "%*s%d", &s
->udp6
);
2200 else if (strcmp(id
, "RAW:") == 0)
2201 sscanf(rem
, "%*s%d", &s
->raw4
);
2202 else if (strcmp(id
, "RAW6:") == 0)
2203 sscanf(rem
, "%*s%d", &s
->raw6
);
2204 else if (strcmp(id
, "TCP6:") == 0)
2205 sscanf(rem
, "%*s%d", &s
->tcp6_hashed
);
2206 else if (strcmp(id
, "FRAG:") == 0)
2207 sscanf(rem
, "%*s%d%*s%d", &s
->frag4
, &s
->frag4_mem
);
2208 else if (strcmp(id
, "FRAG6:") == 0)
2209 sscanf(rem
, "%*s%d%*s%d", &s
->frag6
, &s
->frag6_mem
);
2210 else if (strcmp(id
, "TCP:") == 0)
2211 sscanf(rem
, "%*s%d%*s%d%*s%d%*s%d%*s%d",
2213 &s
->tcp_orphans
, &s
->tcp_tws
, &s
->tcp_total
, &s
->tcp_mem
);
2216 int get_sockstat(struct sockstat
*s
)
2221 memset(s
, 0, sizeof(*s
));
2223 if ((fp
= fdopen(net_sockstat_open(), "r")) == NULL
)
2225 while(fgets(buf
, sizeof(buf
), fp
) != NULL
)
2226 get_sockstat_line(buf
, s
);
2229 if ((fp
= fdopen(net_sockstat6_open(), "r")) == NULL
)
2231 while(fgets(buf
, sizeof(buf
), fp
) != NULL
)
2232 get_sockstat_line(buf
, s
);
2238 int print_summary(void)
2243 if (get_sockstat(&s
) < 0)
2244 perror("ss: get_sockstat");
2245 if (get_snmp_int("Tcp:", "CurrEstab", &sn
.tcp_estab
) < 0)
2246 perror("ss: get_snmpstat");
2248 printf("Total: %d (kernel %d)\n", s
.socks
, slabstat
.socks
);
2250 printf("TCP: %d (estab %d, closed %d, orphaned %d, synrecv %d, timewait %d/%d), ports %d\n",
2251 s
.tcp_total
+ slabstat
.tcp_syns
+ s
.tcp_tws
,
2253 s
.tcp_total
- (s
.tcp4_hashed
+s
.tcp6_hashed
-s
.tcp_tws
),
2256 s
.tcp_tws
, slabstat
.tcp_tws
,
2261 printf("Transport Total IP IPv6\n");
2262 printf("* %-9d %-9s %-9s\n", slabstat
.socks
, "-", "-");
2263 printf("RAW %-9d %-9d %-9d\n", s
.raw4
+s
.raw6
, s
.raw4
, s
.raw6
);
2264 printf("UDP %-9d %-9d %-9d\n", s
.udp4
+s
.udp6
, s
.udp4
, s
.udp6
);
2265 printf("TCP %-9d %-9d %-9d\n", s
.tcp4_hashed
+s
.tcp6_hashed
, s
.tcp4_hashed
, s
.tcp6_hashed
);
2266 printf("INET %-9d %-9d %-9d\n",
2267 s
.raw4
+s
.udp4
+s
.tcp4_hashed
+
2268 s
.raw6
+s
.udp6
+s
.tcp6_hashed
,
2269 s
.raw4
+s
.udp4
+s
.tcp4_hashed
,
2270 s
.raw6
+s
.udp6
+s
.tcp6_hashed
);
2271 printf("FRAG %-9d %-9d %-9d\n", s
.frag4
+s
.frag6
, s
.frag4
, s
.frag6
);
2279 static void usage(void) __attribute__((noreturn
));
2281 static void usage(void)
2284 "Usage: ss [ OPTIONS ]\n"
2285 " ss [ OPTIONS ] [ FILTER ]\n"
2286 "where OPTIONS := { -h[elp] | -V[ersion] | -n[umeric] | -r[esolve] |\n"
2287 " -a[ll] -l[istening] -o[ptions] -e[xtended] -p[rocesses]\n"
2288 " -A QUERY } -s[ummary]\n"
2289 " -f[amily] { inet | inet6 | link | unix } }\n"
2290 " QUERY := {all|inet|tcp|udp|raw|unix|packet|netlink}[,QUERY]\n"
2291 " FILTER := [ state TCP-STATE ] [ EXPRESSION ]\n"
2297 int scan_state(char *state
)
2300 if (strcasecmp(state
, "close") == 0 ||
2301 strcasecmp(state
, "closed") == 0)
2302 return (1<<SS_CLOSE
);
2303 if (strcasecmp(state
, "syn-rcv") == 0)
2304 return (1<<SS_SYN_RECV
);
2305 if (matches(state
, "established") == 0)
2306 return (1<<SS_ESTABLISHED
);
2307 if (strcasecmp(state
, "all") == 0)
2309 if (strcasecmp(state
, "connected") == 0)
2310 return SS_ALL
& ~((1<<SS_CLOSE
)|(1<<SS_LISTEN
));
2311 if (matches(state
, "synchronized") == 0)
2312 return SS_ALL
& ~((1<<SS_CLOSE
)|(1<<SS_LISTEN
)|(1<<SS_SYN_SENT
));
2313 if (strcasecmp(state
, "bucket") == 0)
2314 return (1<<SS_SYN_RECV
)|(1<<SS_TIME_WAIT
);
2315 if (strcasecmp(state
, "big") == 0)
2316 return SS_ALL
& ~((1<<SS_SYN_RECV
)|(1<<SS_TIME_WAIT
));
2317 for (i
=0; i
<SS_MAX
; i
++) {
2318 if (matches(state
, sstate_namel
[i
]) == 0)
2325 int main(int argc
, char *argv
[])
2331 char *dump_tcpdiag
= NULL
;
2332 FILE *filter_fp
= NULL
;
2335 memset(¤t_filter
, 0, sizeof(current_filter
));
2337 current_filter
.states
= default_filter
.states
;
2339 while ((ch
= getopt(argc
, argv
, "h?aletuwxnro460spfmiA:D:F:vV")) != EOF
) {
2342 resolve_services
= 0;
2364 current_filter
.dbs
|= (1<<TCP_DB
);
2368 current_filter
.dbs
|= (1<<UDP_DB
);
2372 current_filter
.dbs
|= (1<<RAW_DB
);
2376 current_filter
.dbs
|= UNIX_DBM
;
2380 current_filter
.states
= SS_ALL
;
2383 current_filter
.states
= (1<<SS_LISTEN
);
2386 preferred_family
= AF_INET
;
2389 preferred_family
= AF_INET6
;
2392 preferred_family
= AF_PACKET
;
2395 if (strcmp(optarg
, "inet") == 0)
2396 preferred_family
= AF_INET
;
2397 else if (strcmp(optarg
, "inet6") == 0)
2398 preferred_family
= AF_INET6
;
2399 else if (strcmp(optarg
, "link") == 0)
2400 preferred_family
= AF_PACKET
;
2401 else if (strcmp(optarg
, "unix") == 0)
2402 preferred_family
= AF_UNIX
;
2403 else if (strcmp(optarg
, "netlink") == 0)
2404 preferred_family
= AF_NETLINK
;
2405 else if (strcmp(optarg
, "help") == 0)
2408 fprintf(stderr
, "ss: \"%s\" is invalid family\n", optarg
);
2416 current_filter
.dbs
= 0;
2422 if ((p1
= strchr(p
, ',')) != NULL
)
2424 if (strcmp(p
, "all") == 0) {
2425 current_filter
.dbs
= ALL_DB
;
2426 } else if (strcmp(p
, "inet") == 0) {
2427 current_filter
.dbs
|= (1<<TCP_DB
)|(1<<UDP_DB
)|(1<<RAW_DB
);
2428 } else if (strcmp(p
, "udp") == 0) {
2429 current_filter
.dbs
|= (1<<UDP_DB
);
2430 } else if (strcmp(p
, "tcp") == 0) {
2431 current_filter
.dbs
|= (1<<TCP_DB
);
2432 } else if (strcmp(p
, "raw") == 0) {
2433 current_filter
.dbs
|= (1<<RAW_DB
);
2434 } else if (strcmp(p
, "unix") == 0) {
2435 current_filter
.dbs
|= UNIX_DBM
;
2436 } else if (matches(p
, "unix_stream") == 0 ||
2437 strcmp(p
, "u_str") == 0) {
2438 current_filter
.dbs
|= (1<<UNIX_ST_DB
);
2439 } else if (matches(p
, "unix_dgram") == 0 ||
2440 strcmp(p
, "u_dgr") == 0) {
2441 current_filter
.dbs
|= (1<<UNIX_DG_DB
);
2442 } else if (strcmp(p
, "packet") == 0) {
2443 current_filter
.dbs
|= PACKET_DBM
;
2444 } else if (strcmp(p
, "packet_raw") == 0 ||
2445 strcmp(p
, "p_raw") == 0) {
2446 current_filter
.dbs
|= (1<<PACKET_R_DB
);
2447 } else if (strcmp(p
, "packet_dgram") == 0 ||
2448 strcmp(p
, "p_dgr") == 0) {
2449 current_filter
.dbs
|= (1<<PACKET_DG_DB
);
2450 } else if (strcmp(p
, "netlink") == 0) {
2451 current_filter
.dbs
|= (1<<NETLINK_DB
);
2453 fprintf(stderr
, "ss: \"%s\" is illegal socket table id\n", p
);
2464 dump_tcpdiag
= optarg
;
2468 fprintf(stderr
, "More than one filter file\n");
2471 if (optarg
[0] == '-')
2474 filter_fp
= fopen(optarg
, "r");
2476 perror("fopen filter file");
2482 printf("ss utility, iproute2-ss%s\n", SNAPSHOT
);
2494 get_slabstat(&slabstat
);
2498 if (do_default
&& argc
== 0)
2503 current_filter
.dbs
= default_filter
.dbs
;
2505 if (preferred_family
== AF_UNSPEC
) {
2506 if (!(current_filter
.dbs
&~UNIX_DBM
))
2507 preferred_family
= AF_UNIX
;
2508 else if (!(current_filter
.dbs
&~PACKET_DBM
))
2509 preferred_family
= AF_PACKET
;
2510 else if (!(current_filter
.dbs
&~(1<<NETLINK_DB
)))
2511 preferred_family
= AF_NETLINK
;
2514 if (preferred_family
!= AF_UNSPEC
) {
2516 if (preferred_family
== AF_INET
||
2517 preferred_family
== AF_INET6
) {
2520 mask2
= (1<<UDP_DB
)|(1<<RAW_DB
);
2521 } else if (preferred_family
== AF_PACKET
) {
2523 } else if (preferred_family
== AF_UNIX
) {
2525 } else if (preferred_family
== AF_NETLINK
) {
2526 mask2
= (1<<NETLINK_DB
);
2532 current_filter
.dbs
= mask2
;
2534 current_filter
.dbs
&= mask2
;
2535 current_filter
.families
= (1<<preferred_family
);
2538 current_filter
.families
= ~0;
2540 current_filter
.families
= default_filter
.families
;
2542 if (current_filter
.dbs
== 0) {
2543 fprintf(stderr
, "ss: no socket tables to show with such filter.\n");
2546 if (current_filter
.families
== 0) {
2547 fprintf(stderr
, "ss: no families to show with such filter.\n");
2551 if (resolve_services
&& resolve_hosts
&&
2552 (current_filter
.dbs
&(UNIX_DBM
|(1<<TCP_DB
)|(1<<UDP_DB
))))
2553 init_service_resolver();
2555 /* Now parse filter... */
2556 if (argc
== 0 && filter_fp
) {
2557 if (ssfilter_parse(¤t_filter
.f
, 0, NULL
, filter_fp
))
2562 if (strcmp(*argv
, "state") == 0) {
2565 current_filter
.states
= 0;
2566 current_filter
.states
|= scan_state(*argv
);
2568 } else if (strcmp(*argv
, "exclude") == 0 ||
2569 strcmp(*argv
, "excl") == 0) {
2572 current_filter
.states
= SS_ALL
;
2573 current_filter
.states
&= ~scan_state(*argv
);
2576 if (ssfilter_parse(¤t_filter
.f
, argc
, argv
, filter_fp
))
2583 if (current_filter
.states
== 0) {
2584 fprintf(stderr
, "ss: no socket states to show with such filter.\n");
2589 FILE *dump_fp
= stdout
;
2590 if (!(current_filter
.dbs
& (1<<TCP_DB
))) {
2591 fprintf(stderr
, "ss: tcpdiag dump requested and no tcp in filter.\n");
2594 if (dump_tcpdiag
[0] != '-') {
2595 dump_fp
= fopen(dump_tcpdiag
, "w");
2596 if (!dump_tcpdiag
) {
2597 perror("fopen dump file");
2601 tcp_show_netlink(¤t_filter
, dump_fp
);
2607 if (current_filter
.dbs
&(current_filter
.dbs
-1))
2611 if (current_filter
.states
&(current_filter
.states
-1))
2615 if (isatty(STDOUT_FILENO
)) {
2618 if (ioctl(STDOUT_FILENO
, TIOCGWINSZ
, &w
) != -1) {
2620 screen_width
= w
.ws_col
;
2624 addrp_width
= screen_width
;
2625 addrp_width
-= netid_width
+1;
2626 addrp_width
-= state_width
+1;
2629 if (addrp_width
&1) {
2632 else if (state_width
)
2639 serv_width
= resolve_services
? 7 : 5;
2641 if (addrp_width
< 15+serv_width
+1)
2642 addrp_width
= 15+serv_width
+1;
2644 addr_width
= addrp_width
- serv_width
- 1;
2647 printf("%-*s ", netid_width
, "Netid");
2649 printf("%-*s ", state_width
, "State");
2650 printf("%-6s %-6s ", "Recv-Q", "Send-Q");
2652 printf("%*s:%-*s %*s:%-*s\n",
2653 addr_width
, "Local Address", serv_width
, "Port",
2654 addr_width
, "Peer Address", serv_width
, "Port");
2656 //printf("%08x %08x %08x\n", current_filter.dbs, current_filter.states, current_filter.families);
2659 if (current_filter
.dbs
& (1<<NETLINK_DB
))
2660 netlink_show(¤t_filter
);
2661 if (current_filter
.dbs
& PACKET_DBM
)
2662 packet_show(¤t_filter
);
2663 if (current_filter
.dbs
& UNIX_DBM
)
2664 unix_show(¤t_filter
);
2665 if (current_filter
.dbs
& (1<<RAW_DB
))
2666 raw_show(¤t_filter
);
2667 if (current_filter
.dbs
& (1<<UDP_DB
))
2668 udp_show(¤t_filter
);
2669 if (current_filter
.dbs
& (1<<TCP_DB
))
2670 tcp_show(¤t_filter
);