mirror of
https://github.com/opnsense/src.git
synced 2026-02-26 11:20:29 -05:00
Knowing the value of execname during these probes is of some value even if it is commonly the interrupt kernel thread (intr[12]) -- quite often it is not, but that depends on the probe. Sponsored by: Smule, Inc.
76 lines
1.8 KiB
Bash
76 lines
1.8 KiB
Bash
# -*- tab-width: 4 -*- ;; Emacs
|
|
# vi: set filetype=sh tabstop=8 shiftwidth=8 noexpandtab :: Vi/ViM
|
|
############################################################ IDENT(1)
|
|
#
|
|
# $Title: dwatch(8) module for dtrace_ip(4) $
|
|
# $Copyright: 2014-2018 Devin Teske. All rights reserved. $
|
|
# $FreeBSD$
|
|
#
|
|
############################################################ DESCRIPTION
|
|
#
|
|
# Display interface name and bytes sent/received when IP I/O occurs
|
|
#
|
|
############################################################ PROBE
|
|
|
|
case "$PROFILE" in
|
|
ip) : ${PROBE:=ip:::send, ip:::receive} ;;
|
|
*) : ${PROBE:=ip:::${PROFILE#ip-}}
|
|
esac
|
|
|
|
############################################################ ACTIONS
|
|
|
|
exec 9<<EOF
|
|
this string flow;
|
|
this string if_name;
|
|
this string local;
|
|
this string remote;
|
|
this u_char recv;
|
|
this uint32_t length;
|
|
|
|
$PROBE /* probe ID $ID */
|
|
{${TRACE:+
|
|
printf("<$ID>");
|
|
}
|
|
/*
|
|
* dtrace_ip(4)
|
|
*/
|
|
this->recv = probename == "receive" ? 1 : 0;
|
|
this->flow = this->recv ? "<-" : "->";
|
|
|
|
/*
|
|
* ipinfo_t *
|
|
*/
|
|
this->length = (uint32_t)args[2]->ip_plength;
|
|
this->local = this->recv ? args[2]->ip_daddr : args[2]->ip_saddr;
|
|
this->remote = this->recv ? args[2]->ip_saddr : args[2]->ip_daddr;
|
|
|
|
/*
|
|
* ifinfo_t *
|
|
*/
|
|
this->if_name = args[3]->if_name;
|
|
}
|
|
EOF
|
|
ACTIONS=$( cat <&9 )
|
|
ID=$(( $ID + 1 ))
|
|
|
|
############################################################ EVENT DETAILS
|
|
|
|
if [ ! "$CUSTOM_DETAILS" ]; then
|
|
exec 9<<EOF
|
|
/*
|
|
* Print network I/O details
|
|
*/
|
|
printf("%s %s %s %s %u byte%s",
|
|
this->if_name,
|
|
this->local,
|
|
this->flow,
|
|
this->remote,
|
|
this->length,
|
|
this->length == 1 ? "" : "s");
|
|
EOF
|
|
EVENT_DETAILS=$( cat <&9 )
|
|
fi
|
|
|
|
################################################################################
|
|
# END
|
|
################################################################################
|