From patchwork Mon Mar 11 02:41:03 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Xing X-Patchwork-Id: 13588243 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1C0EA15B3; Mon, 11 Mar 2024 02:41:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1710124876; cv=none; b=tp9NbSEUi7QYU2gheOTZVefmMvR3rkuzMFqUTD3A434vWNHhIyxSS3s8advT6oK6FWXEeXIG6yAzZxXEs/vtkv/OcyaOE6IMd95txayOEBNnhngKwzjtB9DWjBdH3hfg+otM/lqjIMNZ7M99EW8rj4qdh+QkSegeBP4O25AHOpI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1710124876; c=relaxed/simple; bh=SUxenl/BwbSsbDrQBUXDykQNYl1Qk7Yq+NkpuENC15k=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=DzW/eDhK0T5+yLjsP4rQ2Ssb/XTC/lyki/BdwHfMY8IQbrckVgSdwu/zPBp2XLFSRGyIGUqdiANihQ1LIEK9xojKV6YrAC4/TWR43Htp3EGK8WohFejnrzfh2Qe3kpfnjZ4+11hRwUU9ZeUnh1hiLh97XoDx37QKCRa7zbYCvoY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PX5Kdwyx; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PX5Kdwyx" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-1dc29f1956cso14735865ad.0; Sun, 10 Mar 2024 19:41:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1710124874; x=1710729674; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=Do+9SHGs1HG4/leaBYvD8jYQHxGGVY9D4dB/P5w6JJM=; b=PX5KdwyxKjHSD2yIRAsTopvS6FiVQKEd7wQAGbdcUeIzCew6EgeTnJzYSwN+L4emlY aZLd32QhT50Y/UKMrZMqO++bKHApY3XcNYgdtXwrq7G8tUzc7/v/52iX8X0oqMumsTsd g7MjstoZWp1oIsWJ9n8bSce6hUSSaqg7i95SykU2ODBde1O8N07On9++GmrAeo2dBFm1 6Wm3r2seO2QSY0MIWXAOQh8DvueQYlXVsrOKGcPkAU/ykHMAVoXAIZ+zGENstwrPeyI5 wxf1aaPIWVEVTcn4WEKOzcB3RwNweY1iQ8DPO20qAFyQsh8O7jguSUR3uc7tAC5uD6tt KyBg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1710124874; x=1710729674; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Do+9SHGs1HG4/leaBYvD8jYQHxGGVY9D4dB/P5w6JJM=; b=sqvsL23llA5beKkXnIFErvvfnxRkwg1h7QA/580F9hQkXIRNcwsq2gHDwptxiyE7Eo GcYhKvZb16mNIJ4wtyAIZK2ArWO91pn2VwPKc3atrfiDbUX8AelauK97Zq9/TUSCCqJz u2oMJ4ykHg4hR3fmkihR2bxNCW+xmrJgDIldgXGxpVZAMqDgC6pGtbWS2rrepZ0LZKqz CBbg6MZm5ussSsjZa+o+NXyYvN42jzm+QigXs5qB/sRvAm5iDOoI9LWOLumvew90/Gh4 cPzSq4CFklhtNyPOmkUz+KIIsbRH3dByerjNFlz35FYyfeR+X8Mka4VCZjQYYE6ZscNv sVFg== X-Forwarded-Encrypted: i=1; AJvYcCV1XsS4AYewVjO46UZiaJprbaUFq7rOwRBmsf9PySoSZt0U+uv0gftcf+9Nae+0Xj8XRwaRqbofaHlWipjnkUKpPEQuM20XeSxWHQL3wNUwNm3Z X-Gm-Message-State: AOJu0YxhZB/+iKKVqT4UsdlihqOXa/hSUOI+X58DIEQHwao61duEZAjG Wyb9xFUjuew/WodsDMdaUKyY5ZIWnaZSUaGMm4QmNfJP1nj54Hj4 X-Google-Smtp-Source: AGHT+IH+bMjQvC2UBxBiN2xhwYIu10I4giZQpSbMad8VIzAgx0aRb3ZzhAu+g7oFvNy8vufvWJDg9Q== X-Received: by 2002:a17:903:2988:b0:1dc:90a7:660b with SMTP id lm8-20020a170903298800b001dc90a7660bmr5420534plb.9.1710124874367; Sun, 10 Mar 2024 19:41:14 -0700 (PDT) Received: from KERNELXING-MB0.tencent.com ([43.132.141.24]) by smtp.gmail.com with ESMTPSA id y6-20020a17090322c600b001dd98195371sm1135120plg.181.2024.03.10.19.41.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 10 Mar 2024 19:41:13 -0700 (PDT) From: Jason Xing To: edumazet@google.com, mhiramat@kernel.org, mathieu.desnoyers@efficios.com, rostedt@goodmis.org, kuba@kernel.org, pabeni@redhat.com, davem@davemloft.net Cc: netdev@vger.kernel.org, linux-trace-kernel@vger.kernel.org, kerneljasonxing@gmail.com, Jason Xing Subject: [PATCH net-next 1/2] trace: adjust TP_STORE_ADDR_PORTS_SKB() parameters Date: Mon, 11 Mar 2024 10:41:03 +0800 Message-Id: <20240311024104.67522-2-kerneljasonxing@gmail.com> X-Mailer: git-send-email 2.33.0 In-Reply-To: <20240311024104.67522-1-kerneljasonxing@gmail.com> References: <20240311024104.67522-1-kerneljasonxing@gmail.com> Precedence: bulk X-Mailing-List: linux-trace-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 From: Jason Xing Introducing entry_saddr and entry_daddr parameters in this macro for later use can help us record the reverse 4-turple by analyzing the 4-turple of the incoming skb when receiving. Signed-off-by: Jason Xing --- include/trace/events/tcp.h | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/include/trace/events/tcp.h b/include/trace/events/tcp.h index 699dafd204ea..2495a1d579be 100644 --- a/include/trace/events/tcp.h +++ b/include/trace/events/tcp.h @@ -302,15 +302,15 @@ TRACE_EVENT(tcp_probe, __entry->skbaddr, __entry->skaddr) ); -#define TP_STORE_ADDR_PORTS_SKB_V4(__entry, skb) \ +#define TP_STORE_ADDR_PORTS_SKB_V4(skb, entry_saddr, entry_daddr) \ do { \ const struct tcphdr *th = (const struct tcphdr *)skb->data; \ - struct sockaddr_in *v4 = (void *)__entry->saddr; \ + struct sockaddr_in *v4 = (void *)entry_saddr; \ \ v4->sin_family = AF_INET; \ v4->sin_port = th->source; \ v4->sin_addr.s_addr = ip_hdr(skb)->saddr; \ - v4 = (void *)__entry->daddr; \ + v4 = (void *)entry_daddr; \ v4->sin_family = AF_INET; \ v4->sin_port = th->dest; \ v4->sin_addr.s_addr = ip_hdr(skb)->daddr; \ @@ -318,29 +318,30 @@ TRACE_EVENT(tcp_probe, #if IS_ENABLED(CONFIG_IPV6) -#define TP_STORE_ADDR_PORTS_SKB(__entry, skb) \ +#define TP_STORE_ADDR_PORTS_SKB(skb, entry_saddr, entry_daddr) \ do { \ const struct iphdr *iph = ip_hdr(skb); \ \ if (iph->version == 6) { \ const struct tcphdr *th = (const struct tcphdr *)skb->data; \ - struct sockaddr_in6 *v6 = (void *)__entry->saddr; \ + struct sockaddr_in6 *v6 = (void *)entry_saddr; \ \ v6->sin6_family = AF_INET6; \ v6->sin6_port = th->source; \ v6->sin6_addr = ipv6_hdr(skb)->saddr; \ - v6 = (void *)__entry->daddr; \ + v6 = (void *)entry_daddr; \ v6->sin6_family = AF_INET6; \ v6->sin6_port = th->dest; \ v6->sin6_addr = ipv6_hdr(skb)->daddr; \ } else \ - TP_STORE_ADDR_PORTS_SKB_V4(__entry, skb); \ + TP_STORE_ADDR_PORTS_SKB_V4(skb, entry_saddr, \ + entry_daddr); \ } while (0) #else -#define TP_STORE_ADDR_PORTS_SKB(__entry, skb) \ - TP_STORE_ADDR_PORTS_SKB_V4(__entry, skb) +#define TP_STORE_ADDR_PORTS_SKB(skb, entry_saddr, entry_daddr) \ + TP_STORE_ADDR_PORTS_SKB_V4(skb, entry_saddr, entry_daddr) #endif @@ -365,7 +366,7 @@ DECLARE_EVENT_CLASS(tcp_event_skb, memset(__entry->saddr, 0, sizeof(struct sockaddr_in6)); memset(__entry->daddr, 0, sizeof(struct sockaddr_in6)); - TP_STORE_ADDR_PORTS_SKB(__entry, skb); + TP_STORE_ADDR_PORTS_SKB(skb, __entry->saddr, __entry->daddr); ), TP_printk("skbaddr=%p src=%pISpc dest=%pISpc", From patchwork Mon Mar 11 02:41:04 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jason Xing X-Patchwork-Id: 13588244 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 499D723A0; Mon, 11 Mar 2024 02:41:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1710124879; cv=none; b=oLzvIAmEVYjIhpqIZcUDAIvyo//xgib0SQcGn/BoQjfVSPGEeeOj5+0WIjflbXAxowXyuQH//NWBDM14n9ZJWBj0HdhGFr/sQI8bxZcUZuq1kj+wut7uKJ1TQgwAZIEmMb12dvjGTw9WArLGdRtb6SDEjZEEp4MqMxRoIfei/oA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1710124879; c=relaxed/simple; bh=ZBjmOXi0qubXcx6EX51mfp2IYcr9vL77PckhzgCFqE0=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Qpxr/kIDI1RkzIYto8yTyc0mq7byxLS/jrFLU5iHN+vylr5/zqKLc8OKm/8ooEqgn/v4oUOyhmkiUrLXkYBepzxqKY7c7mQDASXKf8rayh2OIINyadaUmXNQEY5V8TJ2ooDzBZeL2LPSEmp03uVC/5YOkAY1Zqv4MZ6WY8x10xI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nJRGaB+6; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nJRGaB+6" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-1dd955753edso4562255ad.1; Sun, 10 Mar 2024 19:41:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1710124877; x=1710729677; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=n8AorYRFqUOOnhfdZfjEkjTqC0gSsRIuuU+61AmJ9Vg=; b=nJRGaB+63RKs951aEGAWpSHP1V0J54Erih2f6M1VfMPvFaDAjawjnw/s6WyuKiGTbo cuuIQyR3qDgIpN5MdiVfSbf09+SDsGGZbZr6uU4s5eRXdp6XBfxI1dBLdkTA6EK+qcOX dvGNdj/kvUXKDF1Y4v6x/D750X4OJzs4tQ3vjXIaq5iLhlBpZWjb24b3L25nHqHgp8eV zci/s8Cc/W1il/83I/3tE/LeQ0zBFuPuahMxPL8vzsH1dcckiwr+5Mr+PhFk3GmxSQdF Yl6w7OBuwMPXRmOhdgAmmxyw2e44fmlBLe+T5g31DKc07xPI0ZjDngmtAtLAWK+mkSF2 Pi+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1710124877; x=1710729677; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=n8AorYRFqUOOnhfdZfjEkjTqC0gSsRIuuU+61AmJ9Vg=; b=tRgGLy1FNi0k309XaTDfv59DpuAHKwBWw6rcJn8YWxTrLmZxplEUhvxGQoXLKpyLVr rG12rxXxRRGoEgmHjV9y8p0n6wURgWgvS7EBb/kvzs1y3GfjX/Y0+N9MnWjgFaZKGlkB qgn8f7YbAF2x8Gjk4JLqqPxoOJt6fakI5N7YYUJqVmhqh+CvDbnFskFuB/xUK2177UN0 A+F5TWQFhNcgrXHCm6hRTEFyjdy/6x+6UidxRZbNL2RItUl1pBA0Pl8fxHnpDcRPlYal UnRnaD1BPjfU++VjQ3yHbWRkhfT+Tg3/nrEICmXv8G6qLSiMX071jRqD9Ut+Q8DsSlSJ hL5Q== X-Forwarded-Encrypted: i=1; AJvYcCWO8kRS3XS6Z3h5rs1HeF8X/hx/QuBLPtKHw/oZ6yE0IpmQjTYY6CYhWQ0UnfjU2TCOtX4/ThJHY+649XVhMsj2g0HxouZXfQWUG6qXCQRTQIE6 X-Gm-Message-State: AOJu0YwqwB+MwEztRd43QdWTj2U9mFmOumaCRuHQsjumLWDorzURIHAH vVVv8d+g59B0caUrWWEFiIJ2g3hNQAWL1rNNvsNl0rCDUGOPK1fS X-Google-Smtp-Source: AGHT+IEe/ECoIJsaQ0OjCtnRyZIiCR0IRN/6C1dNiKgN6pMcL4hdzKML8qBys/iMNg9nyOu7nXvhrQ== X-Received: by 2002:a17:903:2582:b0:1dc:b30c:694c with SMTP id jb2-20020a170903258200b001dcb30c694cmr4032863plb.41.1710124877534; Sun, 10 Mar 2024 19:41:17 -0700 (PDT) Received: from KERNELXING-MB0.tencent.com ([43.132.141.24]) by smtp.gmail.com with ESMTPSA id y6-20020a17090322c600b001dd98195371sm1135120plg.181.2024.03.10.19.41.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 10 Mar 2024 19:41:17 -0700 (PDT) From: Jason Xing To: edumazet@google.com, mhiramat@kernel.org, mathieu.desnoyers@efficios.com, rostedt@goodmis.org, kuba@kernel.org, pabeni@redhat.com, davem@davemloft.net Cc: netdev@vger.kernel.org, linux-trace-kernel@vger.kernel.org, kerneljasonxing@gmail.com, Jason Xing Subject: [PATCH net-next 2/2] trace: tcp: fully support trace_tcp_send_reset Date: Mon, 11 Mar 2024 10:41:04 +0800 Message-Id: <20240311024104.67522-3-kerneljasonxing@gmail.com> X-Mailer: git-send-email 2.33.0 In-Reply-To: <20240311024104.67522-1-kerneljasonxing@gmail.com> References: <20240311024104.67522-1-kerneljasonxing@gmail.com> Precedence: bulk X-Mailing-List: linux-trace-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 From: Jason Xing Prior to this patch, what we can see by enabling trace_tcp_send is only happening under two circumstances: 1) active rst mode 2) non-active rst mode and based on the full socket That means the inconsistency occurs if we use tcpdump and trace simultaneously to see how rst happens. It's necessary that we should take into other cases into considerations, say: 1) time-wait socket 2) no socket ... By parsing the incoming skb and reversing its 4-turple can we know the exact 'flow' which might not exist. Samples after applied this patch: 1. tcp_send_reset: skbaddr=XXX skaddr=XXX src=ip:port dest=ip:port state=TCP_ESTABLISHED 2. tcp_send_reset: skbaddr=000...000 skaddr=XXX src=ip:port dest=ip:port state=UNKNOWN Note: 1) UNKNOWN means we cannot extract the right information from skb. 2) skbaddr/skaddr could be 0 Signed-off-by: Jason Xing --- include/trace/events/tcp.h | 39 ++++++++++++++++++++++++++++++++++++-- net/ipv4/tcp_ipv4.c | 4 ++-- net/ipv6/tcp_ipv6.c | 3 ++- 3 files changed, 41 insertions(+), 5 deletions(-) diff --git a/include/trace/events/tcp.h b/include/trace/events/tcp.h index 2495a1d579be..6c09d7941583 100644 --- a/include/trace/events/tcp.h +++ b/include/trace/events/tcp.h @@ -107,11 +107,46 @@ DEFINE_EVENT(tcp_event_sk_skb, tcp_retransmit_skb, * skb of trace_tcp_send_reset is the skb that caused RST. In case of * active reset, skb should be NULL */ -DEFINE_EVENT(tcp_event_sk_skb, tcp_send_reset, +TRACE_EVENT(tcp_send_reset, TP_PROTO(const struct sock *sk, const struct sk_buff *skb), - TP_ARGS(sk, skb) + TP_ARGS(sk, skb), + + TP_STRUCT__entry( + __field(const void *, skbaddr) + __field(const void *, skaddr) + __field(int, state) + __array(__u8, saddr, sizeof(struct sockaddr_in6)) + __array(__u8, daddr, sizeof(struct sockaddr_in6)) + ), + + TP_fast_assign( + __entry->skbaddr = skb; + __entry->skaddr = sk; + /* Zero means unknown state. */ + __entry->state = sk ? sk->sk_state : 0; + + memset(__entry->saddr, 0, sizeof(struct sockaddr_in6)); + memset(__entry->daddr, 0, sizeof(struct sockaddr_in6)); + + if (sk && sk_fullsock(sk)) { + const struct inet_sock *inet = inet_sk(sk); + + TP_STORE_ADDR_PORTS(__entry, inet, sk); + } else { + /* + * We should reverse the 4-turple of skb, so later + * it can print the right flow direction of rst. + */ + TP_STORE_ADDR_PORTS_SKB(skb, entry->daddr, entry->saddr); + } + ), + + TP_printk("skbaddr=%p skaddr=%p src=%pISpc dest=%pISpc state=%s", + __entry->skbaddr, __entry->skaddr, + __entry->saddr, __entry->daddr, + __entry->state ? show_tcp_state_name(__entry->state) : "UNKNOWN") ); /* diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c index a22ee5838751..d5c4a969c066 100644 --- a/net/ipv4/tcp_ipv4.c +++ b/net/ipv4/tcp_ipv4.c @@ -868,10 +868,10 @@ static void tcp_v4_send_reset(const struct sock *sk, struct sk_buff *skb) */ if (sk) { arg.bound_dev_if = sk->sk_bound_dev_if; - if (sk_fullsock(sk)) - trace_tcp_send_reset(sk, skb); } + trace_tcp_send_reset(sk, skb); + BUILD_BUG_ON(offsetof(struct sock, sk_bound_dev_if) != offsetof(struct inet_timewait_sock, tw_bound_dev_if)); diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c index 3f4cba49e9ee..8e9c59b6c00c 100644 --- a/net/ipv6/tcp_ipv6.c +++ b/net/ipv6/tcp_ipv6.c @@ -1113,7 +1113,6 @@ static void tcp_v6_send_reset(const struct sock *sk, struct sk_buff *skb) if (sk) { oif = sk->sk_bound_dev_if; if (sk_fullsock(sk)) { - trace_tcp_send_reset(sk, skb); if (inet6_test_bit(REPFLOW, sk)) label = ip6_flowlabel(ipv6h); priority = READ_ONCE(sk->sk_priority); @@ -1129,6 +1128,8 @@ static void tcp_v6_send_reset(const struct sock *sk, struct sk_buff *skb) label = ip6_flowlabel(ipv6h); } + trace_tcp_send_reset(sk, skb); + tcp_v6_send_response(sk, skb, seq, ack_seq, 0, 0, 0, oif, 1, ipv6_get_dsfield(ipv6h), label, priority, txhash, &key);