ebpf_socket.c 115 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793
  1. // SPDX-License-Identifier: GPL-3.0-or-later
  2. #include <sys/resource.h>
  3. #include "ebpf.h"
  4. #include "ebpf_socket.h"
  5. /*****************************************************************
  6. *
  7. * GLOBAL VARIABLES
  8. *
  9. *****************************************************************/
  10. static char *socket_dimension_names[NETDATA_MAX_SOCKET_VECTOR] = { "received", "sent", "close",
  11. "received", "sent", "retransmitted",
  12. "connected_V4", "connected_V6", "connected_tcp",
  13. "connected_udp"};
  14. static char *socket_id_names[NETDATA_MAX_SOCKET_VECTOR] = { "tcp_cleanup_rbuf", "tcp_sendmsg", "tcp_close",
  15. "udp_recvmsg", "udp_sendmsg", "tcp_retransmit_skb",
  16. "tcp_connect_v4", "tcp_connect_v6", "inet_csk_accept_tcp",
  17. "inet_csk_accept_udp" };
  18. static ebpf_local_maps_t socket_maps[] = {{.name = "tbl_global_sock",
  19. .internal_input = NETDATA_SOCKET_COUNTER,
  20. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  21. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  22. #ifdef LIBBPF_MAJOR_VERSION
  23. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  24. #endif
  25. },
  26. {.name = "tbl_lports",
  27. .internal_input = NETDATA_SOCKET_COUNTER,
  28. .user_input = 0, .type = NETDATA_EBPF_MAP_STATIC,
  29. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  30. #ifdef LIBBPF_MAJOR_VERSION
  31. .map_type = BPF_MAP_TYPE_PERCPU_HASH
  32. #endif
  33. },
  34. {.name = "tbl_nd_socket",
  35. .internal_input = NETDATA_COMPILED_CONNECTIONS_ALLOWED,
  36. .user_input = NETDATA_MAXIMUM_CONNECTIONS_ALLOWED,
  37. .type = NETDATA_EBPF_MAP_STATIC,
  38. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  39. #ifdef LIBBPF_MAJOR_VERSION
  40. .map_type = BPF_MAP_TYPE_PERCPU_HASH
  41. #endif
  42. },
  43. {.name = "tbl_nv_udp",
  44. .internal_input = NETDATA_COMPILED_UDP_CONNECTIONS_ALLOWED,
  45. .user_input = NETDATA_MAXIMUM_UDP_CONNECTIONS_ALLOWED,
  46. .type = NETDATA_EBPF_MAP_STATIC,
  47. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  48. #ifdef LIBBPF_MAJOR_VERSION
  49. .map_type = BPF_MAP_TYPE_PERCPU_HASH
  50. #endif
  51. },
  52. {.name = "socket_ctrl", .internal_input = NETDATA_CONTROLLER_END,
  53. .user_input = 0,
  54. .type = NETDATA_EBPF_MAP_CONTROLLER,
  55. .map_fd = ND_EBPF_MAP_FD_NOT_INITIALIZED,
  56. #ifdef LIBBPF_MAJOR_VERSION
  57. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  58. #endif
  59. },
  60. {.name = NULL, .internal_input = 0, .user_input = 0,
  61. #ifdef LIBBPF_MAJOR_VERSION
  62. .map_type = BPF_MAP_TYPE_PERCPU_ARRAY
  63. #endif
  64. }};
  65. static netdata_idx_t *socket_hash_values = NULL;
  66. static netdata_syscall_stat_t socket_aggregated_data[NETDATA_MAX_SOCKET_VECTOR];
  67. static netdata_publish_syscall_t socket_publish_aggregated[NETDATA_MAX_SOCKET_VECTOR];
  68. netdata_socket_t *socket_values;
  69. ebpf_network_viewer_port_list_t *listen_ports = NULL;
  70. struct config socket_config = { .first_section = NULL,
  71. .last_section = NULL,
  72. .mutex = NETDATA_MUTEX_INITIALIZER,
  73. .index = { .avl_tree = { .root = NULL, .compar = appconfig_section_compare },
  74. .rwlock = AVL_LOCK_INITIALIZER } };
  75. netdata_ebpf_targets_t socket_targets[] = { {.name = "inet_csk_accept", .mode = EBPF_LOAD_PROBE},
  76. {.name = "tcp_retransmit_skb", .mode = EBPF_LOAD_PROBE},
  77. {.name = "tcp_cleanup_rbuf", .mode = EBPF_LOAD_PROBE},
  78. {.name = "tcp_close", .mode = EBPF_LOAD_PROBE},
  79. {.name = "udp_recvmsg", .mode = EBPF_LOAD_PROBE},
  80. {.name = "tcp_sendmsg", .mode = EBPF_LOAD_PROBE},
  81. {.name = "udp_sendmsg", .mode = EBPF_LOAD_PROBE},
  82. {.name = "tcp_v4_connect", .mode = EBPF_LOAD_PROBE},
  83. {.name = "tcp_v6_connect", .mode = EBPF_LOAD_PROBE},
  84. {.name = NULL, .mode = EBPF_LOAD_TRAMPOLINE}};
  85. struct netdata_static_thread ebpf_read_socket = {
  86. .name = "EBPF_READ_SOCKET",
  87. .config_section = NULL,
  88. .config_name = NULL,
  89. .env_name = NULL,
  90. .enabled = 1,
  91. .thread = NULL,
  92. .init_routine = NULL,
  93. .start_routine = NULL
  94. };
  95. ARAL *aral_socket_table = NULL;
  96. #ifdef NETDATA_DEV_MODE
  97. int socket_disable_priority;
  98. #endif
  99. #ifdef LIBBPF_MAJOR_VERSION
  100. /**
  101. * Disable Probe
  102. *
  103. * Disable probes to use trampoline.
  104. *
  105. * @param obj is the main structure for bpf objects.
  106. */
  107. static void ebpf_socket_disable_probes(struct socket_bpf *obj)
  108. {
  109. bpf_program__set_autoload(obj->progs.netdata_inet_csk_accept_kretprobe, false);
  110. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_kprobe, false);
  111. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_kretprobe, false);
  112. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_kprobe, false);
  113. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_kretprobe, false);
  114. bpf_program__set_autoload(obj->progs.netdata_tcp_retransmit_skb_kprobe, false);
  115. bpf_program__set_autoload(obj->progs.netdata_tcp_cleanup_rbuf_kprobe, false);
  116. bpf_program__set_autoload(obj->progs.netdata_tcp_close_kprobe, false);
  117. bpf_program__set_autoload(obj->progs.netdata_udp_recvmsg_kprobe, false);
  118. bpf_program__set_autoload(obj->progs.netdata_udp_recvmsg_kretprobe, false);
  119. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_kretprobe, false);
  120. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_kprobe, false);
  121. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_kretprobe, false);
  122. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_kprobe, false);
  123. }
  124. /**
  125. * Disable Trampoline
  126. *
  127. * Disable trampoline to use probes.
  128. *
  129. * @param obj is the main structure for bpf objects.
  130. */
  131. static void ebpf_socket_disable_trampoline(struct socket_bpf *obj)
  132. {
  133. bpf_program__set_autoload(obj->progs.netdata_inet_csk_accept_fexit, false);
  134. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_fentry, false);
  135. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_fexit, false);
  136. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_fentry, false);
  137. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_fexit, false);
  138. bpf_program__set_autoload(obj->progs.netdata_tcp_retransmit_skb_fentry, false);
  139. bpf_program__set_autoload(obj->progs.netdata_tcp_cleanup_rbuf_fentry, false);
  140. bpf_program__set_autoload(obj->progs.netdata_tcp_close_fentry, false);
  141. bpf_program__set_autoload(obj->progs.netdata_udp_recvmsg_fentry, false);
  142. bpf_program__set_autoload(obj->progs.netdata_udp_recvmsg_fexit, false);
  143. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_fentry, false);
  144. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_fexit, false);
  145. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_fentry, false);
  146. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_fexit, false);
  147. }
  148. /**
  149. * Set trampoline target.
  150. *
  151. * @param obj is the main structure for bpf objects.
  152. */
  153. static void ebpf_set_trampoline_target(struct socket_bpf *obj)
  154. {
  155. bpf_program__set_attach_target(obj->progs.netdata_inet_csk_accept_fexit, 0,
  156. socket_targets[NETDATA_FCNT_INET_CSK_ACCEPT].name);
  157. bpf_program__set_attach_target(obj->progs.netdata_tcp_v4_connect_fentry, 0,
  158. socket_targets[NETDATA_FCNT_TCP_V4_CONNECT].name);
  159. bpf_program__set_attach_target(obj->progs.netdata_tcp_v4_connect_fexit, 0,
  160. socket_targets[NETDATA_FCNT_TCP_V4_CONNECT].name);
  161. bpf_program__set_attach_target(obj->progs.netdata_tcp_v6_connect_fentry, 0,
  162. socket_targets[NETDATA_FCNT_TCP_V6_CONNECT].name);
  163. bpf_program__set_attach_target(obj->progs.netdata_tcp_v6_connect_fexit, 0,
  164. socket_targets[NETDATA_FCNT_TCP_V6_CONNECT].name);
  165. bpf_program__set_attach_target(obj->progs.netdata_tcp_retransmit_skb_fentry, 0,
  166. socket_targets[NETDATA_FCNT_TCP_RETRANSMIT].name);
  167. bpf_program__set_attach_target(obj->progs.netdata_tcp_cleanup_rbuf_fentry, 0,
  168. socket_targets[NETDATA_FCNT_CLEANUP_RBUF].name);
  169. bpf_program__set_attach_target(obj->progs.netdata_tcp_close_fentry, 0,
  170. socket_targets[NETDATA_FCNT_TCP_CLOSE].name);
  171. bpf_program__set_attach_target(obj->progs.netdata_udp_recvmsg_fentry, 0,
  172. socket_targets[NETDATA_FCNT_UDP_RECEVMSG].name);
  173. bpf_program__set_attach_target(obj->progs.netdata_udp_recvmsg_fexit, 0,
  174. socket_targets[NETDATA_FCNT_UDP_RECEVMSG].name);
  175. bpf_program__set_attach_target(obj->progs.netdata_tcp_sendmsg_fentry, 0,
  176. socket_targets[NETDATA_FCNT_TCP_SENDMSG].name);
  177. bpf_program__set_attach_target(obj->progs.netdata_tcp_sendmsg_fexit, 0,
  178. socket_targets[NETDATA_FCNT_TCP_SENDMSG].name);
  179. bpf_program__set_attach_target(obj->progs.netdata_udp_sendmsg_fentry, 0,
  180. socket_targets[NETDATA_FCNT_UDP_SENDMSG].name);
  181. bpf_program__set_attach_target(obj->progs.netdata_udp_sendmsg_fexit, 0,
  182. socket_targets[NETDATA_FCNT_UDP_SENDMSG].name);
  183. }
  184. /**
  185. * Disable specific trampoline
  186. *
  187. * Disable specific trampoline to match user selection.
  188. *
  189. * @param obj is the main structure for bpf objects.
  190. * @param sel option selected by user.
  191. */
  192. static inline void ebpf_socket_disable_specific_trampoline(struct socket_bpf *obj, netdata_run_mode_t sel)
  193. {
  194. if (sel == MODE_RETURN) {
  195. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_fentry, false);
  196. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_fentry, false);
  197. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_fentry, false);
  198. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_fentry, false);
  199. } else {
  200. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_fexit, false);
  201. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_fexit, false);
  202. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_fexit, false);
  203. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_fexit, false);
  204. }
  205. }
  206. /**
  207. * Disable specific probe
  208. *
  209. * Disable specific probe to match user selection.
  210. *
  211. * @param obj is the main structure for bpf objects.
  212. * @param sel option selected by user.
  213. */
  214. static inline void ebpf_socket_disable_specific_probe(struct socket_bpf *obj, netdata_run_mode_t sel)
  215. {
  216. if (sel == MODE_RETURN) {
  217. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_kprobe, false);
  218. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_kprobe, false);
  219. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_kprobe, false);
  220. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_kprobe, false);
  221. } else {
  222. bpf_program__set_autoload(obj->progs.netdata_tcp_sendmsg_kretprobe, false);
  223. bpf_program__set_autoload(obj->progs.netdata_tcp_v4_connect_kretprobe, false);
  224. bpf_program__set_autoload(obj->progs.netdata_tcp_v6_connect_kretprobe, false);
  225. bpf_program__set_autoload(obj->progs.netdata_udp_sendmsg_kretprobe, false);
  226. }
  227. }
  228. /**
  229. * Attach probes
  230. *
  231. * Attach probes to targets.
  232. *
  233. * @param obj is the main structure for bpf objects.
  234. * @param sel option selected by user.
  235. */
  236. static long ebpf_socket_attach_probes(struct socket_bpf *obj, netdata_run_mode_t sel)
  237. {
  238. obj->links.netdata_inet_csk_accept_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_inet_csk_accept_kretprobe,
  239. true,
  240. socket_targets[NETDATA_FCNT_INET_CSK_ACCEPT].name);
  241. long ret = libbpf_get_error(obj->links.netdata_inet_csk_accept_kretprobe);
  242. if (ret)
  243. return -1;
  244. obj->links.netdata_tcp_retransmit_skb_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_retransmit_skb_kprobe,
  245. false,
  246. socket_targets[NETDATA_FCNT_TCP_RETRANSMIT].name);
  247. ret = libbpf_get_error(obj->links.netdata_tcp_retransmit_skb_kprobe);
  248. if (ret)
  249. return -1;
  250. obj->links.netdata_tcp_cleanup_rbuf_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_cleanup_rbuf_kprobe,
  251. false,
  252. socket_targets[NETDATA_FCNT_CLEANUP_RBUF].name);
  253. ret = libbpf_get_error(obj->links.netdata_tcp_cleanup_rbuf_kprobe);
  254. if (ret)
  255. return -1;
  256. obj->links.netdata_tcp_close_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_close_kprobe,
  257. false,
  258. socket_targets[NETDATA_FCNT_TCP_CLOSE].name);
  259. ret = libbpf_get_error(obj->links.netdata_tcp_close_kprobe);
  260. if (ret)
  261. return -1;
  262. obj->links.netdata_udp_recvmsg_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_udp_recvmsg_kprobe,
  263. false,
  264. socket_targets[NETDATA_FCNT_UDP_RECEVMSG].name);
  265. ret = libbpf_get_error(obj->links.netdata_udp_recvmsg_kprobe);
  266. if (ret)
  267. return -1;
  268. obj->links.netdata_udp_recvmsg_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_udp_recvmsg_kretprobe,
  269. true,
  270. socket_targets[NETDATA_FCNT_UDP_RECEVMSG].name);
  271. ret = libbpf_get_error(obj->links.netdata_udp_recvmsg_kretprobe);
  272. if (ret)
  273. return -1;
  274. if (sel == MODE_RETURN) {
  275. obj->links.netdata_tcp_sendmsg_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_sendmsg_kretprobe,
  276. true,
  277. socket_targets[NETDATA_FCNT_TCP_SENDMSG].name);
  278. ret = libbpf_get_error(obj->links.netdata_tcp_sendmsg_kretprobe);
  279. if (ret)
  280. return -1;
  281. obj->links.netdata_udp_sendmsg_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_udp_sendmsg_kretprobe,
  282. true,
  283. socket_targets[NETDATA_FCNT_UDP_SENDMSG].name);
  284. ret = libbpf_get_error(obj->links.netdata_udp_sendmsg_kretprobe);
  285. if (ret)
  286. return -1;
  287. obj->links.netdata_tcp_v4_connect_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_v4_connect_kretprobe,
  288. true,
  289. socket_targets[NETDATA_FCNT_TCP_V4_CONNECT].name);
  290. ret = libbpf_get_error(obj->links.netdata_tcp_v4_connect_kretprobe);
  291. if (ret)
  292. return -1;
  293. obj->links.netdata_tcp_v6_connect_kretprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_v6_connect_kretprobe,
  294. true,
  295. socket_targets[NETDATA_FCNT_TCP_V6_CONNECT].name);
  296. ret = libbpf_get_error(obj->links.netdata_tcp_v6_connect_kretprobe);
  297. if (ret)
  298. return -1;
  299. } else {
  300. obj->links.netdata_tcp_sendmsg_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_sendmsg_kprobe,
  301. false,
  302. socket_targets[NETDATA_FCNT_TCP_SENDMSG].name);
  303. ret = libbpf_get_error(obj->links.netdata_tcp_sendmsg_kprobe);
  304. if (ret)
  305. return -1;
  306. obj->links.netdata_udp_sendmsg_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_udp_sendmsg_kprobe,
  307. false,
  308. socket_targets[NETDATA_FCNT_UDP_SENDMSG].name);
  309. ret = libbpf_get_error(obj->links.netdata_udp_sendmsg_kprobe);
  310. if (ret)
  311. return -1;
  312. obj->links.netdata_tcp_v4_connect_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_v4_connect_kprobe,
  313. false,
  314. socket_targets[NETDATA_FCNT_TCP_V4_CONNECT].name);
  315. ret = libbpf_get_error(obj->links.netdata_tcp_v4_connect_kprobe);
  316. if (ret)
  317. return -1;
  318. obj->links.netdata_tcp_v6_connect_kprobe = bpf_program__attach_kprobe(obj->progs.netdata_tcp_v6_connect_kprobe,
  319. false,
  320. socket_targets[NETDATA_FCNT_TCP_V6_CONNECT].name);
  321. ret = libbpf_get_error(obj->links.netdata_tcp_v6_connect_kprobe);
  322. if (ret)
  323. return -1;
  324. }
  325. return 0;
  326. }
  327. /**
  328. * Set hash tables
  329. *
  330. * Set the values for maps according the value given by kernel.
  331. *
  332. * @param obj is the main structure for bpf objects.
  333. */
  334. static void ebpf_socket_set_hash_tables(struct socket_bpf *obj)
  335. {
  336. socket_maps[NETDATA_SOCKET_GLOBAL].map_fd = bpf_map__fd(obj->maps.tbl_global_sock);
  337. socket_maps[NETDATA_SOCKET_LPORTS].map_fd = bpf_map__fd(obj->maps.tbl_lports);
  338. socket_maps[NETDATA_SOCKET_OPEN_SOCKET].map_fd = bpf_map__fd(obj->maps.tbl_nd_socket);
  339. socket_maps[NETDATA_SOCKET_TABLE_UDP].map_fd = bpf_map__fd(obj->maps.tbl_nv_udp);
  340. socket_maps[NETDATA_SOCKET_TABLE_CTRL].map_fd = bpf_map__fd(obj->maps.socket_ctrl);
  341. }
  342. /**
  343. * Adjust Map Size
  344. *
  345. * Resize maps according input from users.
  346. *
  347. * @param obj is the main structure for bpf objects.
  348. * @param em structure with configuration
  349. */
  350. static void ebpf_socket_adjust_map(struct socket_bpf *obj, ebpf_module_t *em)
  351. {
  352. ebpf_update_map_size(obj->maps.tbl_nd_socket, &socket_maps[NETDATA_SOCKET_OPEN_SOCKET],
  353. em, bpf_map__name(obj->maps.tbl_nd_socket));
  354. ebpf_update_map_size(obj->maps.tbl_nv_udp, &socket_maps[NETDATA_SOCKET_TABLE_UDP],
  355. em, bpf_map__name(obj->maps.tbl_nv_udp));
  356. ebpf_update_map_type(obj->maps.tbl_nd_socket, &socket_maps[NETDATA_SOCKET_OPEN_SOCKET]);
  357. ebpf_update_map_type(obj->maps.tbl_nv_udp, &socket_maps[NETDATA_SOCKET_TABLE_UDP]);
  358. ebpf_update_map_type(obj->maps.socket_ctrl, &socket_maps[NETDATA_SOCKET_TABLE_CTRL]);
  359. ebpf_update_map_type(obj->maps.tbl_global_sock, &socket_maps[NETDATA_SOCKET_GLOBAL]);
  360. ebpf_update_map_type(obj->maps.tbl_lports, &socket_maps[NETDATA_SOCKET_LPORTS]);
  361. }
  362. /**
  363. * Load and attach
  364. *
  365. * Load and attach the eBPF code in kernel.
  366. *
  367. * @param obj is the main structure for bpf objects.
  368. * @param em structure with configuration
  369. *
  370. * @return it returns 0 on success and -1 otherwise
  371. */
  372. static inline int ebpf_socket_load_and_attach(struct socket_bpf *obj, ebpf_module_t *em)
  373. {
  374. netdata_ebpf_targets_t *mt = em->targets;
  375. netdata_ebpf_program_loaded_t test = mt[NETDATA_FCNT_INET_CSK_ACCEPT].mode;
  376. if (test == EBPF_LOAD_TRAMPOLINE) {
  377. ebpf_socket_disable_probes(obj);
  378. ebpf_set_trampoline_target(obj);
  379. ebpf_socket_disable_specific_trampoline(obj, em->mode);
  380. } else { // We are not using tracepoints for this thread.
  381. ebpf_socket_disable_trampoline(obj);
  382. ebpf_socket_disable_specific_probe(obj, em->mode);
  383. }
  384. ebpf_socket_adjust_map(obj, em);
  385. int ret = socket_bpf__load(obj);
  386. if (ret) {
  387. fprintf(stderr, "failed to load BPF object: %d\n", ret);
  388. return ret;
  389. }
  390. if (test == EBPF_LOAD_TRAMPOLINE) {
  391. ret = socket_bpf__attach(obj);
  392. } else {
  393. ret = (int)ebpf_socket_attach_probes(obj, em->mode);
  394. }
  395. if (!ret) {
  396. ebpf_socket_set_hash_tables(obj);
  397. ebpf_update_controller(socket_maps[NETDATA_SOCKET_TABLE_CTRL].map_fd, em);
  398. }
  399. return ret;
  400. }
  401. #endif
  402. /*****************************************************************
  403. *
  404. * FUNCTIONS TO CLOSE THE THREAD
  405. *
  406. *****************************************************************/
  407. /**
  408. * Socket Free
  409. *
  410. * Cleanup variables after child threads to stop
  411. *
  412. * @param ptr thread data.
  413. */
  414. static void ebpf_socket_free(ebpf_module_t *em )
  415. {
  416. pthread_mutex_lock(&ebpf_exit_cleanup);
  417. em->enabled = NETDATA_THREAD_EBPF_STOPPED;
  418. ebpf_update_stats(&plugin_statistics, em);
  419. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_REMOVE);
  420. pthread_mutex_unlock(&ebpf_exit_cleanup);
  421. }
  422. /**
  423. * Obsolete Systemd Socket Charts
  424. *
  425. * Obsolete charts when systemd is enabled
  426. *
  427. * @param update_every value to overwrite the update frequency set by the server.
  428. **/
  429. static void ebpf_obsolete_systemd_socket_charts(int update_every)
  430. {
  431. int order = 20080;
  432. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  433. NETDATA_NET_APPS_CONNECTION_TCP_V4,
  434. "Calls to tcp_v4_connection",
  435. EBPF_COMMON_DIMENSION_CONNECTIONS,
  436. NETDATA_APPS_NET_GROUP,
  437. NETDATA_EBPF_CHART_TYPE_STACKED,
  438. NETDATA_SERVICES_SOCKET_TCP_V4_CONN_CONTEXT,
  439. order++,
  440. update_every);
  441. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  442. NETDATA_NET_APPS_CONNECTION_TCP_V6,
  443. "Calls to tcp_v6_connection",
  444. EBPF_COMMON_DIMENSION_CONNECTIONS,
  445. NETDATA_APPS_NET_GROUP,
  446. NETDATA_EBPF_CHART_TYPE_STACKED,
  447. NETDATA_SERVICES_SOCKET_TCP_V6_CONN_CONTEXT,
  448. order++,
  449. update_every);
  450. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  451. NETDATA_NET_APPS_BANDWIDTH_RECV,
  452. "Bytes received",
  453. EBPF_COMMON_DIMENSION_BITS,
  454. NETDATA_APPS_NET_GROUP,
  455. NETDATA_EBPF_CHART_TYPE_STACKED,
  456. NETDATA_SERVICES_SOCKET_BYTES_RECV_CONTEXT,
  457. order++,
  458. update_every);
  459. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  460. NETDATA_NET_APPS_BANDWIDTH_SENT,
  461. "Bytes sent",
  462. EBPF_COMMON_DIMENSION_BITS,
  463. NETDATA_APPS_NET_GROUP,
  464. NETDATA_EBPF_CHART_TYPE_STACKED,
  465. NETDATA_SERVICES_SOCKET_BYTES_SEND_CONTEXT,
  466. order++,
  467. update_every);
  468. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  469. NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS,
  470. "Calls to tcp_cleanup_rbuf.",
  471. EBPF_COMMON_DIMENSION_CALL,
  472. NETDATA_APPS_NET_GROUP,
  473. NETDATA_EBPF_CHART_TYPE_STACKED,
  474. NETDATA_SERVICES_SOCKET_TCP_RECV_CONTEXT,
  475. order++,
  476. update_every);
  477. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  478. NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS,
  479. "Calls to tcp_sendmsg.",
  480. EBPF_COMMON_DIMENSION_CALL,
  481. NETDATA_APPS_NET_GROUP,
  482. NETDATA_EBPF_CHART_TYPE_STACKED,
  483. NETDATA_SERVICES_SOCKET_TCP_SEND_CONTEXT,
  484. order++,
  485. update_every);
  486. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  487. NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT,
  488. "Calls to tcp_retransmit",
  489. EBPF_COMMON_DIMENSION_CALL,
  490. NETDATA_APPS_NET_GROUP,
  491. NETDATA_EBPF_CHART_TYPE_STACKED,
  492. NETDATA_SERVICES_SOCKET_TCP_RETRANSMIT_CONTEXT,
  493. order++,
  494. update_every);
  495. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  496. NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS,
  497. "Calls to udp_sendmsg",
  498. EBPF_COMMON_DIMENSION_CALL,
  499. NETDATA_APPS_NET_GROUP,
  500. NETDATA_EBPF_CHART_TYPE_STACKED,
  501. NETDATA_SERVICES_SOCKET_UDP_SEND_CONTEXT,
  502. order++,
  503. update_every);
  504. ebpf_write_chart_obsolete(NETDATA_SERVICE_FAMILY,
  505. NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS,
  506. "Calls to udp_recvmsg",
  507. EBPF_COMMON_DIMENSION_CALL,
  508. NETDATA_APPS_NET_GROUP,
  509. NETDATA_EBPF_CHART_TYPE_STACKED,
  510. NETDATA_SERVICES_SOCKET_UDP_RECV_CONTEXT,
  511. order++,
  512. update_every);
  513. }
  514. static void ebpf_obsolete_specific_socket_charts(char *type, int update_every);
  515. /**
  516. * Obsolete cgroup chart
  517. *
  518. * Send obsolete for all charts created before to close.
  519. *
  520. * @param em a pointer to `struct ebpf_module`
  521. */
  522. static inline void ebpf_obsolete_socket_cgroup_charts(ebpf_module_t *em) {
  523. pthread_mutex_lock(&mutex_cgroup_shm);
  524. ebpf_obsolete_systemd_socket_charts(em->update_every);
  525. ebpf_cgroup_target_t *ect;
  526. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  527. if (ect->systemd)
  528. continue;
  529. ebpf_obsolete_specific_socket_charts(ect->name, em->update_every);
  530. }
  531. pthread_mutex_unlock(&mutex_cgroup_shm);
  532. }
  533. /**
  534. * Create apps charts
  535. *
  536. * Call ebpf_create_chart to create the charts on apps submenu.
  537. *
  538. * @param em a pointer to the structure with the default values.
  539. */
  540. void ebpf_socket_obsolete_apps_charts(struct ebpf_module *em)
  541. {
  542. int order = 20080;
  543. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  544. NETDATA_NET_APPS_CONNECTION_TCP_V4,
  545. "Calls to tcp_v4_connection",
  546. EBPF_COMMON_DIMENSION_CONNECTIONS,
  547. NETDATA_APPS_NET_GROUP,
  548. NETDATA_EBPF_CHART_TYPE_STACKED,
  549. NULL,
  550. order++,
  551. em->update_every);
  552. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  553. NETDATA_NET_APPS_CONNECTION_TCP_V6,
  554. "Calls to tcp_v6_connection",
  555. EBPF_COMMON_DIMENSION_CONNECTIONS,
  556. NETDATA_APPS_NET_GROUP,
  557. NETDATA_EBPF_CHART_TYPE_STACKED,
  558. NULL,
  559. order++,
  560. em->update_every);
  561. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  562. NETDATA_NET_APPS_BANDWIDTH_SENT,
  563. "Bytes sent",
  564. EBPF_COMMON_DIMENSION_BITS,
  565. NETDATA_APPS_NET_GROUP,
  566. NETDATA_EBPF_CHART_TYPE_STACKED,
  567. NULL,
  568. order++,
  569. em->update_every);
  570. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  571. NETDATA_NET_APPS_BANDWIDTH_RECV,
  572. "bytes received",
  573. EBPF_COMMON_DIMENSION_BITS,
  574. NETDATA_APPS_NET_GROUP,
  575. NETDATA_EBPF_CHART_TYPE_STACKED,
  576. NULL,
  577. order++,
  578. em->update_every);
  579. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  580. NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS,
  581. "Calls for tcp_sendmsg",
  582. EBPF_COMMON_DIMENSION_CALL,
  583. NETDATA_APPS_NET_GROUP,
  584. NETDATA_EBPF_CHART_TYPE_STACKED,
  585. NULL,
  586. order++,
  587. em->update_every);
  588. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  589. NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS,
  590. "Calls for tcp_cleanup_rbuf",
  591. EBPF_COMMON_DIMENSION_CALL,
  592. NETDATA_APPS_NET_GROUP,
  593. NETDATA_EBPF_CHART_TYPE_STACKED,
  594. NULL,
  595. order++,
  596. em->update_every);
  597. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  598. NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT,
  599. "Calls for tcp_retransmit",
  600. EBPF_COMMON_DIMENSION_CALL,
  601. NETDATA_APPS_NET_GROUP,
  602. NETDATA_EBPF_CHART_TYPE_STACKED,
  603. NULL,
  604. order++,
  605. em->update_every);
  606. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  607. NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS,
  608. "Calls for udp_sendmsg",
  609. EBPF_COMMON_DIMENSION_CALL,
  610. NETDATA_APPS_NET_GROUP,
  611. NETDATA_EBPF_CHART_TYPE_STACKED,
  612. NULL,
  613. order++,
  614. em->update_every);
  615. ebpf_write_chart_obsolete(NETDATA_APPS_FAMILY,
  616. NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS,
  617. "Calls for udp_recvmsg",
  618. EBPF_COMMON_DIMENSION_CALL,
  619. NETDATA_APPS_NET_GROUP,
  620. NETDATA_EBPF_CHART_TYPE_STACKED,
  621. NULL,
  622. order++,
  623. em->update_every);
  624. }
  625. /**
  626. * Obsolete global charts
  627. *
  628. * Obsolete charts created.
  629. *
  630. * @param em a pointer to the structure with the default values.
  631. */
  632. static void ebpf_socket_obsolete_global_charts(ebpf_module_t *em)
  633. {
  634. int order = 21070;
  635. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  636. NETDATA_INBOUND_CONNECTIONS,
  637. "Inbound connections.",
  638. EBPF_COMMON_DIMENSION_CONNECTIONS,
  639. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  640. NETDATA_EBPF_CHART_TYPE_LINE,
  641. NULL,
  642. order++,
  643. em->update_every);
  644. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  645. NETDATA_TCP_OUTBOUND_CONNECTIONS,
  646. "TCP outbound connections.",
  647. EBPF_COMMON_DIMENSION_CONNECTIONS,
  648. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  649. NETDATA_EBPF_CHART_TYPE_LINE,
  650. NULL,
  651. order++,
  652. em->update_every);
  653. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  654. NETDATA_TCP_FUNCTION_COUNT,
  655. "Calls to internal functions",
  656. EBPF_COMMON_DIMENSION_CALL,
  657. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  658. NETDATA_EBPF_CHART_TYPE_LINE,
  659. NULL,
  660. order++,
  661. em->update_every);
  662. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  663. NETDATA_TCP_FUNCTION_BITS,
  664. "TCP bandwidth",
  665. EBPF_COMMON_DIMENSION_BITS,
  666. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  667. NETDATA_EBPF_CHART_TYPE_LINE,
  668. NULL,
  669. order++,
  670. em->update_every);
  671. if (em->mode < MODE_ENTRY) {
  672. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  673. NETDATA_TCP_FUNCTION_ERROR,
  674. "TCP errors",
  675. EBPF_COMMON_DIMENSION_CALL,
  676. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  677. NETDATA_EBPF_CHART_TYPE_LINE,
  678. NULL,
  679. order++,
  680. em->update_every);
  681. }
  682. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  683. NETDATA_TCP_RETRANSMIT,
  684. "Packages retransmitted",
  685. EBPF_COMMON_DIMENSION_CALL,
  686. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  687. NETDATA_EBPF_CHART_TYPE_LINE,
  688. NULL,
  689. order++,
  690. em->update_every);
  691. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  692. NETDATA_UDP_FUNCTION_COUNT,
  693. "UDP calls",
  694. EBPF_COMMON_DIMENSION_CALL,
  695. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  696. NETDATA_EBPF_CHART_TYPE_LINE,
  697. NULL,
  698. order++,
  699. em->update_every);
  700. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  701. NETDATA_UDP_FUNCTION_BITS,
  702. "UDP bandwidth",
  703. EBPF_COMMON_DIMENSION_BITS,
  704. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  705. NETDATA_EBPF_CHART_TYPE_LINE,
  706. NULL,
  707. order++,
  708. em->update_every);
  709. if (em->mode < MODE_ENTRY) {
  710. ebpf_write_chart_obsolete(NETDATA_EBPF_IP_FAMILY,
  711. NETDATA_UDP_FUNCTION_ERROR,
  712. "UDP errors",
  713. EBPF_COMMON_DIMENSION_CALL,
  714. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  715. NETDATA_EBPF_CHART_TYPE_LINE,
  716. NULL,
  717. order++,
  718. em->update_every);
  719. }
  720. fflush(stdout);
  721. }
  722. /**
  723. * Socket exit
  724. *
  725. * Clean up the main thread.
  726. *
  727. * @param ptr thread data.
  728. */
  729. static void ebpf_socket_exit(void *ptr)
  730. {
  731. ebpf_module_t *em = (ebpf_module_t *)ptr;
  732. if (ebpf_read_socket.thread)
  733. netdata_thread_cancel(*ebpf_read_socket.thread);
  734. if (em->enabled == NETDATA_THREAD_EBPF_FUNCTION_RUNNING) {
  735. pthread_mutex_lock(&lock);
  736. if (em->cgroup_charts) {
  737. ebpf_obsolete_socket_cgroup_charts(em);
  738. fflush(stdout);
  739. }
  740. if (em->apps_charts & NETDATA_EBPF_APPS_FLAG_CHART_CREATED) {
  741. ebpf_socket_obsolete_apps_charts(em);
  742. fflush(stdout);
  743. }
  744. ebpf_socket_obsolete_global_charts(em);
  745. #ifdef NETDATA_DEV_MODE
  746. if (ebpf_aral_socket_pid)
  747. ebpf_statistic_obsolete_aral_chart(em, socket_disable_priority);
  748. #endif
  749. pthread_mutex_unlock(&lock);
  750. }
  751. ebpf_socket_free(em);
  752. }
  753. /*****************************************************************
  754. *
  755. * PROCESS DATA AND SEND TO NETDATA
  756. *
  757. *****************************************************************/
  758. /**
  759. * Update publish structure before to send data to Netdata.
  760. *
  761. * @param publish the first output structure with independent dimensions
  762. * @param tcp structure to store IO from tcp sockets
  763. * @param udp structure to store IO from udp sockets
  764. * @param input the structure with the input data.
  765. */
  766. static void ebpf_update_global_publish(
  767. netdata_publish_syscall_t *publish, netdata_publish_vfs_common_t *tcp, netdata_publish_vfs_common_t *udp,
  768. netdata_syscall_stat_t *input)
  769. {
  770. netdata_publish_syscall_t *move = publish;
  771. while (move) {
  772. if (input->call != move->pcall) {
  773. // This condition happens to avoid initial values with dimensions higher than normal values.
  774. if (move->pcall) {
  775. move->ncall = (input->call > move->pcall) ? input->call - move->pcall : move->pcall - input->call;
  776. move->nbyte = (input->bytes > move->pbyte) ? input->bytes - move->pbyte : move->pbyte - input->bytes;
  777. move->nerr = (input->ecall > move->nerr) ? input->ecall - move->perr : move->perr - input->ecall;
  778. } else {
  779. move->ncall = 0;
  780. move->nbyte = 0;
  781. move->nerr = 0;
  782. }
  783. move->pcall = input->call;
  784. move->pbyte = input->bytes;
  785. move->perr = input->ecall;
  786. } else {
  787. move->ncall = 0;
  788. move->nbyte = 0;
  789. move->nerr = 0;
  790. }
  791. input = input->next;
  792. move = move->next;
  793. }
  794. tcp->write = -(long)publish[0].nbyte;
  795. tcp->read = (long)publish[1].nbyte;
  796. udp->write = -(long)publish[3].nbyte;
  797. udp->read = (long)publish[4].nbyte;
  798. }
  799. /**
  800. * Send Global Inbound connection
  801. *
  802. * Send number of connections read per protocol.
  803. */
  804. static void ebpf_socket_send_global_inbound_conn()
  805. {
  806. uint64_t udp_conn = 0;
  807. uint64_t tcp_conn = 0;
  808. ebpf_network_viewer_port_list_t *move = listen_ports;
  809. while (move) {
  810. if (move->protocol == IPPROTO_TCP)
  811. tcp_conn += move->connections;
  812. else
  813. udp_conn += move->connections;
  814. move = move->next;
  815. }
  816. write_begin_chart(NETDATA_EBPF_IP_FAMILY, NETDATA_INBOUND_CONNECTIONS);
  817. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_INCOMING_CONNECTION_TCP].name, (long long) tcp_conn);
  818. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_INCOMING_CONNECTION_UDP].name, (long long) udp_conn);
  819. write_end_chart();
  820. }
  821. /**
  822. * Send data to Netdata calling auxiliary functions.
  823. *
  824. * @param em the structure with thread information
  825. */
  826. static void ebpf_socket_send_data(ebpf_module_t *em)
  827. {
  828. netdata_publish_vfs_common_t common_tcp;
  829. netdata_publish_vfs_common_t common_udp;
  830. ebpf_update_global_publish(socket_publish_aggregated, &common_tcp, &common_udp, socket_aggregated_data);
  831. ebpf_socket_send_global_inbound_conn();
  832. write_count_chart(NETDATA_TCP_OUTBOUND_CONNECTIONS, NETDATA_EBPF_IP_FAMILY,
  833. &socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V4], 2);
  834. // We read bytes from function arguments, but bandwidth is given in bits,
  835. // so we need to multiply by 8 to convert for the final value.
  836. write_count_chart(NETDATA_TCP_FUNCTION_COUNT, NETDATA_EBPF_IP_FAMILY, socket_publish_aggregated, 3);
  837. write_io_chart(NETDATA_TCP_FUNCTION_BITS, NETDATA_EBPF_IP_FAMILY, socket_id_names[0],
  838. common_tcp.read * 8/BITS_IN_A_KILOBIT, socket_id_names[1],
  839. common_tcp.write * 8/BITS_IN_A_KILOBIT);
  840. if (em->mode < MODE_ENTRY) {
  841. write_err_chart(NETDATA_TCP_FUNCTION_ERROR, NETDATA_EBPF_IP_FAMILY, socket_publish_aggregated, 2);
  842. }
  843. write_count_chart(NETDATA_TCP_RETRANSMIT, NETDATA_EBPF_IP_FAMILY,
  844. &socket_publish_aggregated[NETDATA_IDX_TCP_RETRANSMIT],1);
  845. write_count_chart(NETDATA_UDP_FUNCTION_COUNT, NETDATA_EBPF_IP_FAMILY,
  846. &socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF],2);
  847. write_io_chart(NETDATA_UDP_FUNCTION_BITS, NETDATA_EBPF_IP_FAMILY,
  848. socket_id_names[3], (long long)common_udp.read * 8/BITS_IN_A_KILOBIT,
  849. socket_id_names[4], (long long)common_udp.write * 8/BITS_IN_A_KILOBIT);
  850. if (em->mode < MODE_ENTRY) {
  851. write_err_chart(NETDATA_UDP_FUNCTION_ERROR, NETDATA_EBPF_IP_FAMILY,
  852. &socket_publish_aggregated[NETDATA_UDP_START], 2);
  853. }
  854. }
  855. /**
  856. * Sum values for pid
  857. *
  858. * @param root the structure with all available PIDs
  859. *
  860. * @param offset the address that we are reading
  861. *
  862. * @return it returns the sum of all PIDs
  863. */
  864. long long ebpf_socket_sum_values_for_pids(struct ebpf_pid_on_target *root, size_t offset)
  865. {
  866. long long ret = 0;
  867. while (root) {
  868. int32_t pid = root->pid;
  869. ebpf_socket_publish_apps_t *w = socket_bandwidth_curr[pid];
  870. if (w) {
  871. ret += get_value_from_structure((char *)w, offset);
  872. }
  873. root = root->next;
  874. }
  875. return ret;
  876. }
  877. /**
  878. * Send data to Netdata calling auxiliary functions.
  879. *
  880. * @param em the structure with thread information
  881. * @param root the target list.
  882. */
  883. void ebpf_socket_send_apps_data(ebpf_module_t *em, struct ebpf_target *root)
  884. {
  885. UNUSED(em);
  886. struct ebpf_target *w;
  887. collected_number value;
  888. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_CONNECTION_TCP_V4);
  889. for (w = root; w; w = w->next) {
  890. if (unlikely(w->exposed && w->processes)) {
  891. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  892. call_tcp_v4_connection));
  893. write_chart_dimension(w->name, value);
  894. }
  895. }
  896. write_end_chart();
  897. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_CONNECTION_TCP_V6);
  898. for (w = root; w; w = w->next) {
  899. if (unlikely(w->exposed && w->processes)) {
  900. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  901. call_tcp_v6_connection));
  902. write_chart_dimension(w->name, value);
  903. }
  904. }
  905. write_end_chart();
  906. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_SENT);
  907. for (w = root; w; w = w->next) {
  908. if (unlikely(w->exposed && w->processes)) {
  909. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  910. bytes_sent));
  911. // We multiply by 0.008, because we read bytes, but we display bits
  912. write_chart_dimension(w->name, ((value)*8)/1000);
  913. }
  914. }
  915. write_end_chart();
  916. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_RECV);
  917. for (w = root; w; w = w->next) {
  918. if (unlikely(w->exposed && w->processes)) {
  919. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  920. bytes_received));
  921. // We multiply by 0.008, because we read bytes, but we display bits
  922. write_chart_dimension(w->name, ((value)*8)/1000);
  923. }
  924. }
  925. write_end_chart();
  926. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS);
  927. for (w = root; w; w = w->next) {
  928. if (unlikely(w->exposed && w->processes)) {
  929. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  930. call_tcp_sent));
  931. write_chart_dimension(w->name, value);
  932. }
  933. }
  934. write_end_chart();
  935. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS);
  936. for (w = root; w; w = w->next) {
  937. if (unlikely(w->exposed && w->processes)) {
  938. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  939. call_tcp_received));
  940. write_chart_dimension(w->name, value);
  941. }
  942. }
  943. write_end_chart();
  944. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT);
  945. for (w = root; w; w = w->next) {
  946. if (unlikely(w->exposed && w->processes)) {
  947. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  948. retransmit));
  949. write_chart_dimension(w->name, value);
  950. }
  951. }
  952. write_end_chart();
  953. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS);
  954. for (w = root; w; w = w->next) {
  955. if (unlikely(w->exposed && w->processes)) {
  956. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  957. call_udp_sent));
  958. write_chart_dimension(w->name, value);
  959. }
  960. }
  961. write_end_chart();
  962. write_begin_chart(NETDATA_APPS_FAMILY, NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS);
  963. for (w = root; w; w = w->next) {
  964. if (unlikely(w->exposed && w->processes)) {
  965. value = ebpf_socket_sum_values_for_pids(w->root_pid, offsetof(ebpf_socket_publish_apps_t,
  966. call_udp_received));
  967. write_chart_dimension(w->name, value);
  968. }
  969. }
  970. write_end_chart();
  971. }
  972. /*****************************************************************
  973. *
  974. * FUNCTIONS TO CREATE CHARTS
  975. *
  976. *****************************************************************/
  977. /**
  978. * Create global charts
  979. *
  980. * Call ebpf_create_chart to create the charts for the collector.
  981. *
  982. * @param em a pointer to the structure with the default values.
  983. */
  984. static void ebpf_socket_create_global_charts(ebpf_module_t *em)
  985. {
  986. int order = 21070;
  987. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  988. NETDATA_INBOUND_CONNECTIONS,
  989. "Inbound connections.",
  990. EBPF_COMMON_DIMENSION_CONNECTIONS,
  991. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  992. NULL,
  993. NETDATA_EBPF_CHART_TYPE_LINE,
  994. order++,
  995. ebpf_create_global_dimension,
  996. &socket_publish_aggregated[NETDATA_IDX_INCOMING_CONNECTION_TCP],
  997. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  998. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  999. NETDATA_TCP_OUTBOUND_CONNECTIONS,
  1000. "TCP outbound connections.",
  1001. EBPF_COMMON_DIMENSION_CONNECTIONS,
  1002. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1003. NULL,
  1004. NETDATA_EBPF_CHART_TYPE_LINE,
  1005. order++,
  1006. ebpf_create_global_dimension,
  1007. &socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V4],
  1008. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1009. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  1010. NETDATA_TCP_FUNCTION_COUNT,
  1011. "Calls to internal functions",
  1012. EBPF_COMMON_DIMENSION_CALL,
  1013. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1014. NULL,
  1015. NETDATA_EBPF_CHART_TYPE_LINE,
  1016. order++,
  1017. ebpf_create_global_dimension,
  1018. socket_publish_aggregated,
  1019. 3, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1020. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY, NETDATA_TCP_FUNCTION_BITS,
  1021. "TCP bandwidth", EBPF_COMMON_DIMENSION_BITS,
  1022. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1023. NULL,
  1024. NETDATA_EBPF_CHART_TYPE_LINE,
  1025. order++,
  1026. ebpf_create_global_dimension,
  1027. socket_publish_aggregated,
  1028. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1029. if (em->mode < MODE_ENTRY) {
  1030. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  1031. NETDATA_TCP_FUNCTION_ERROR,
  1032. "TCP errors",
  1033. EBPF_COMMON_DIMENSION_CALL,
  1034. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1035. NULL,
  1036. NETDATA_EBPF_CHART_TYPE_LINE,
  1037. order++,
  1038. ebpf_create_global_dimension,
  1039. socket_publish_aggregated,
  1040. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1041. }
  1042. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  1043. NETDATA_TCP_RETRANSMIT,
  1044. "Packages retransmitted",
  1045. EBPF_COMMON_DIMENSION_CALL,
  1046. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1047. NULL,
  1048. NETDATA_EBPF_CHART_TYPE_LINE,
  1049. order++,
  1050. ebpf_create_global_dimension,
  1051. &socket_publish_aggregated[NETDATA_IDX_TCP_RETRANSMIT],
  1052. 1, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1053. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  1054. NETDATA_UDP_FUNCTION_COUNT,
  1055. "UDP calls",
  1056. EBPF_COMMON_DIMENSION_CALL,
  1057. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1058. NULL,
  1059. NETDATA_EBPF_CHART_TYPE_LINE,
  1060. order++,
  1061. ebpf_create_global_dimension,
  1062. &socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF],
  1063. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1064. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY, NETDATA_UDP_FUNCTION_BITS,
  1065. "UDP bandwidth", EBPF_COMMON_DIMENSION_BITS,
  1066. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1067. NULL,
  1068. NETDATA_EBPF_CHART_TYPE_LINE,
  1069. order++,
  1070. ebpf_create_global_dimension,
  1071. &socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF],
  1072. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1073. if (em->mode < MODE_ENTRY) {
  1074. ebpf_create_chart(NETDATA_EBPF_IP_FAMILY,
  1075. NETDATA_UDP_FUNCTION_ERROR,
  1076. "UDP errors",
  1077. EBPF_COMMON_DIMENSION_CALL,
  1078. NETDATA_SOCKET_KERNEL_FUNCTIONS,
  1079. NULL,
  1080. NETDATA_EBPF_CHART_TYPE_LINE,
  1081. order++,
  1082. ebpf_create_global_dimension,
  1083. &socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF],
  1084. 2, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1085. }
  1086. fflush(stdout);
  1087. }
  1088. /**
  1089. * Create apps charts
  1090. *
  1091. * Call ebpf_create_chart to create the charts on apps submenu.
  1092. *
  1093. * @param em a pointer to the structure with the default values.
  1094. * @param ptr a pointer for targets
  1095. */
  1096. void ebpf_socket_create_apps_charts(struct ebpf_module *em, void *ptr)
  1097. {
  1098. struct ebpf_target *root = ptr;
  1099. int order = 20080;
  1100. ebpf_create_charts_on_apps(NETDATA_NET_APPS_CONNECTION_TCP_V4,
  1101. "Calls to tcp_v4_connection", EBPF_COMMON_DIMENSION_CONNECTIONS,
  1102. NETDATA_APPS_NET_GROUP,
  1103. NETDATA_EBPF_CHART_TYPE_STACKED,
  1104. order++,
  1105. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1106. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1107. ebpf_create_charts_on_apps(NETDATA_NET_APPS_CONNECTION_TCP_V6,
  1108. "Calls to tcp_v6_connection", EBPF_COMMON_DIMENSION_CONNECTIONS,
  1109. NETDATA_APPS_NET_GROUP,
  1110. NETDATA_EBPF_CHART_TYPE_STACKED,
  1111. order++,
  1112. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1113. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1114. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_SENT,
  1115. "Bytes sent", EBPF_COMMON_DIMENSION_BITS,
  1116. NETDATA_APPS_NET_GROUP,
  1117. NETDATA_EBPF_CHART_TYPE_STACKED,
  1118. order++,
  1119. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1120. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1121. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_RECV,
  1122. "bytes received", EBPF_COMMON_DIMENSION_BITS,
  1123. NETDATA_APPS_NET_GROUP,
  1124. NETDATA_EBPF_CHART_TYPE_STACKED,
  1125. order++,
  1126. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1127. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1128. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS,
  1129. "Calls for tcp_sendmsg",
  1130. EBPF_COMMON_DIMENSION_CALL,
  1131. NETDATA_APPS_NET_GROUP,
  1132. NETDATA_EBPF_CHART_TYPE_STACKED,
  1133. order++,
  1134. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1135. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1136. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS,
  1137. "Calls for tcp_cleanup_rbuf",
  1138. EBPF_COMMON_DIMENSION_CALL,
  1139. NETDATA_APPS_NET_GROUP,
  1140. NETDATA_EBPF_CHART_TYPE_STACKED,
  1141. order++,
  1142. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1143. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1144. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT,
  1145. "Calls for tcp_retransmit",
  1146. EBPF_COMMON_DIMENSION_CALL,
  1147. NETDATA_APPS_NET_GROUP,
  1148. NETDATA_EBPF_CHART_TYPE_STACKED,
  1149. order++,
  1150. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1151. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1152. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS,
  1153. "Calls for udp_sendmsg",
  1154. EBPF_COMMON_DIMENSION_CALL,
  1155. NETDATA_APPS_NET_GROUP,
  1156. NETDATA_EBPF_CHART_TYPE_STACKED,
  1157. order++,
  1158. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1159. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1160. ebpf_create_charts_on_apps(NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS,
  1161. "Calls for udp_recvmsg",
  1162. EBPF_COMMON_DIMENSION_CALL,
  1163. NETDATA_APPS_NET_GROUP,
  1164. NETDATA_EBPF_CHART_TYPE_STACKED,
  1165. order++,
  1166. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1167. root, em->update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1168. em->apps_charts |= NETDATA_EBPF_APPS_FLAG_CHART_CREATED;
  1169. }
  1170. /*****************************************************************
  1171. *
  1172. * READ INFORMATION FROM KERNEL RING
  1173. *
  1174. *****************************************************************/
  1175. /**
  1176. * Is specific ip inside the range
  1177. *
  1178. * Check if the ip is inside a IP range previously defined
  1179. *
  1180. * @param cmp the IP to compare
  1181. * @param family the IP family
  1182. *
  1183. * @return It returns 1 if the IP is inside the range and 0 otherwise
  1184. */
  1185. static int ebpf_is_specific_ip_inside_range(union netdata_ip_t *cmp, int family)
  1186. {
  1187. if (!network_viewer_opt.excluded_ips && !network_viewer_opt.included_ips)
  1188. return 1;
  1189. uint32_t ipv4_test = htonl(cmp->addr32[0]);
  1190. ebpf_network_viewer_ip_list_t *move = network_viewer_opt.excluded_ips;
  1191. while (move) {
  1192. if (family == AF_INET) {
  1193. if (move->first.addr32[0] <= ipv4_test &&
  1194. ipv4_test <= move->last.addr32[0])
  1195. return 0;
  1196. } else {
  1197. if (memcmp(move->first.addr8, cmp->addr8, sizeof(union netdata_ip_t)) <= 0 &&
  1198. memcmp(move->last.addr8, cmp->addr8, sizeof(union netdata_ip_t)) >= 0) {
  1199. return 0;
  1200. }
  1201. }
  1202. move = move->next;
  1203. }
  1204. move = network_viewer_opt.included_ips;
  1205. while (move) {
  1206. if (family == AF_INET && move->ver == AF_INET) {
  1207. if (move->first.addr32[0] <= ipv4_test &&
  1208. move->last.addr32[0] >= ipv4_test)
  1209. return 1;
  1210. } else {
  1211. if (move->ver == AF_INET6 &&
  1212. memcmp(move->first.addr8, cmp->addr8, sizeof(union netdata_ip_t)) <= 0 &&
  1213. memcmp(move->last.addr8, cmp->addr8, sizeof(union netdata_ip_t)) >= 0) {
  1214. return 1;
  1215. }
  1216. }
  1217. move = move->next;
  1218. }
  1219. return 0;
  1220. }
  1221. /**
  1222. * Is port inside range
  1223. *
  1224. * Verify if the cmp port is inside the range [first, last].
  1225. * This function expects only the last parameter as big endian.
  1226. *
  1227. * @param cmp the value to compare
  1228. *
  1229. * @return It returns 1 when cmp is inside and 0 otherwise.
  1230. */
  1231. static int ebpf_is_port_inside_range(uint16_t cmp)
  1232. {
  1233. // We do not have restrictions for ports.
  1234. if (!network_viewer_opt.excluded_port && !network_viewer_opt.included_port)
  1235. return 1;
  1236. // Test if port is excluded
  1237. ebpf_network_viewer_port_list_t *move = network_viewer_opt.excluded_port;
  1238. while (move) {
  1239. if (move->cmp_first <= cmp && cmp <= move->cmp_last)
  1240. return 0;
  1241. move = move->next;
  1242. }
  1243. // Test if the port is inside allowed range
  1244. move = network_viewer_opt.included_port;
  1245. while (move) {
  1246. if (move->cmp_first <= cmp && cmp <= move->cmp_last)
  1247. return 1;
  1248. move = move->next;
  1249. }
  1250. return 0;
  1251. }
  1252. /**
  1253. * Hostname matches pattern
  1254. *
  1255. * @param cmp the value to compare
  1256. *
  1257. * @return It returns 1 when the value matches and zero otherwise.
  1258. */
  1259. int hostname_matches_pattern(char *cmp)
  1260. {
  1261. if (!network_viewer_opt.included_hostnames && !network_viewer_opt.excluded_hostnames)
  1262. return 1;
  1263. ebpf_network_viewer_hostname_list_t *move = network_viewer_opt.excluded_hostnames;
  1264. while (move) {
  1265. if (simple_pattern_matches(move->value_pattern, cmp))
  1266. return 0;
  1267. move = move->next;
  1268. }
  1269. move = network_viewer_opt.included_hostnames;
  1270. while (move) {
  1271. if (simple_pattern_matches(move->value_pattern, cmp))
  1272. return 1;
  1273. move = move->next;
  1274. }
  1275. return 0;
  1276. }
  1277. /**
  1278. * Is socket allowed?
  1279. *
  1280. * Compare destination addresses and destination ports to define next steps
  1281. *
  1282. * @param key the socket read from kernel ring
  1283. * @param data the socket data used also used to refuse some sockets.
  1284. *
  1285. * @return It returns 1 if this socket is inside the ranges and 0 otherwise.
  1286. */
  1287. int ebpf_is_socket_allowed(netdata_socket_idx_t *key, netdata_socket_t *data)
  1288. {
  1289. int ret = 0;
  1290. // If family is not AF_UNSPEC and it is different of specified
  1291. if (network_viewer_opt.family && network_viewer_opt.family != data->family)
  1292. goto endsocketallowed;
  1293. if (!ebpf_is_port_inside_range(key->dport))
  1294. goto endsocketallowed;
  1295. ret = ebpf_is_specific_ip_inside_range(&key->daddr, data->family);
  1296. endsocketallowed:
  1297. return ret;
  1298. }
  1299. /**
  1300. * Hash accumulator
  1301. *
  1302. * @param values the values used to calculate the data.
  1303. * @param family the connection family
  1304. * @param end the values size.
  1305. */
  1306. static void ebpf_hash_socket_accumulator(netdata_socket_t *values, int end)
  1307. {
  1308. int i;
  1309. uint8_t protocol = values[0].protocol;
  1310. uint64_t ct = values[0].current_timestamp;
  1311. uint64_t ft = values[0].first_timestamp;
  1312. uint16_t family = AF_UNSPEC;
  1313. uint32_t external_origin = values[0].external_origin;
  1314. for (i = 1; i < end; i++) {
  1315. netdata_socket_t *w = &values[i];
  1316. values[0].tcp.call_tcp_sent += w->tcp.call_tcp_sent;
  1317. values[0].tcp.call_tcp_received += w->tcp.call_tcp_received;
  1318. values[0].tcp.tcp_bytes_received += w->tcp.tcp_bytes_received;
  1319. values[0].tcp.tcp_bytes_sent += w->tcp.tcp_bytes_sent;
  1320. values[0].tcp.close += w->tcp.close;
  1321. values[0].tcp.retransmit += w->tcp.retransmit;
  1322. values[0].tcp.ipv4_connect += w->tcp.ipv4_connect;
  1323. values[0].tcp.ipv6_connect += w->tcp.ipv6_connect;
  1324. if (!protocol)
  1325. protocol = w->protocol;
  1326. if (family == AF_UNSPEC)
  1327. family = w->family;
  1328. if (w->current_timestamp > ct)
  1329. ct = w->current_timestamp;
  1330. if (!ft)
  1331. ft = w->first_timestamp;
  1332. if (w->external_origin)
  1333. external_origin = NETDATA_EBPF_SRC_IP_ORIGIN_EXTERNAL;
  1334. }
  1335. values[0].protocol = (!protocol)?IPPROTO_TCP:protocol;
  1336. values[0].current_timestamp = ct;
  1337. values[0].first_timestamp = ft;
  1338. values[0].external_origin = external_origin;
  1339. }
  1340. /**
  1341. * Translate socket
  1342. *
  1343. * Convert socket address to string
  1344. *
  1345. * @param dst structure where we will store
  1346. * @param key the socket address
  1347. */
  1348. static void ebpf_socket_translate(netdata_socket_plus_t *dst, netdata_socket_idx_t *key)
  1349. {
  1350. uint32_t resolve = network_viewer_opt.service_resolution_enabled;
  1351. char service[NI_MAXSERV];
  1352. int ret;
  1353. if (dst->data.family == AF_INET) {
  1354. struct sockaddr_in ipv4_addr = { };
  1355. ipv4_addr.sin_port = 0;
  1356. ipv4_addr.sin_addr.s_addr = key->saddr.addr32[0];
  1357. ipv4_addr.sin_family = AF_INET;
  1358. if (resolve) {
  1359. // NI_NAMEREQD : It is too slow
  1360. ret = getnameinfo((struct sockaddr *) &ipv4_addr, sizeof(ipv4_addr), dst->socket_string.src_ip,
  1361. INET6_ADDRSTRLEN, service, NI_MAXSERV, NI_NUMERICHOST | NI_NUMERICSERV);
  1362. if (ret) {
  1363. collector_error("Cannot resolve name: %s", gai_strerror(ret));
  1364. resolve = 0;
  1365. } else {
  1366. ipv4_addr.sin_addr.s_addr = key->daddr.addr32[0];
  1367. ipv4_addr.sin_port = key->dport;
  1368. ret = getnameinfo((struct sockaddr *) &ipv4_addr, sizeof(ipv4_addr), dst->socket_string.dst_ip,
  1369. INET6_ADDRSTRLEN, dst->socket_string.dst_port, NI_MAXSERV,
  1370. NI_NUMERICHOST);
  1371. if (ret) {
  1372. collector_error("Cannot resolve name: %s", gai_strerror(ret));
  1373. resolve = 0;
  1374. }
  1375. }
  1376. }
  1377. // When resolution fail, we should use addresses
  1378. if (!resolve) {
  1379. ipv4_addr.sin_addr.s_addr = key->saddr.addr32[0];
  1380. if(!inet_ntop(AF_INET, &ipv4_addr.sin_addr, dst->socket_string.src_ip, INET6_ADDRSTRLEN))
  1381. netdata_log_info("Cannot convert IP %u .", ipv4_addr.sin_addr.s_addr);
  1382. ipv4_addr.sin_addr.s_addr = key->daddr.addr32[0];
  1383. if(!inet_ntop(AF_INET, &ipv4_addr.sin_addr, dst->socket_string.dst_ip, INET6_ADDRSTRLEN))
  1384. netdata_log_info("Cannot convert IP %u .", ipv4_addr.sin_addr.s_addr);
  1385. snprintfz(dst->socket_string.dst_port, NI_MAXSERV, "%u", ntohs(key->dport));
  1386. }
  1387. } else {
  1388. struct sockaddr_in6 ipv6_addr = { };
  1389. memcpy(&ipv6_addr.sin6_addr, key->saddr.addr8, sizeof(key->saddr.addr8));
  1390. ipv6_addr.sin6_family = AF_INET6;
  1391. if (resolve) {
  1392. ret = getnameinfo((struct sockaddr *) &ipv6_addr, sizeof(ipv6_addr), dst->socket_string.src_ip,
  1393. INET6_ADDRSTRLEN, service, NI_MAXSERV, NI_NUMERICHOST | NI_NUMERICSERV);
  1394. if (ret) {
  1395. collector_error("Cannot resolve name: %s", gai_strerror(ret));
  1396. resolve = 0;
  1397. } else {
  1398. memcpy(&ipv6_addr.sin6_addr, key->daddr.addr8, sizeof(key->daddr.addr8));
  1399. ret = getnameinfo((struct sockaddr *) &ipv6_addr, sizeof(ipv6_addr), dst->socket_string.dst_ip,
  1400. INET6_ADDRSTRLEN, dst->socket_string.dst_port, NI_MAXSERV,
  1401. NI_NUMERICHOST);
  1402. if (ret) {
  1403. collector_error("Cannot resolve name: %s", gai_strerror(ret));
  1404. resolve = 0;
  1405. }
  1406. }
  1407. }
  1408. if (!resolve) {
  1409. memcpy(&ipv6_addr.sin6_addr, key->saddr.addr8, sizeof(key->saddr.addr8));
  1410. if(!inet_ntop(AF_INET6, &ipv6_addr.sin6_addr, dst->socket_string.src_ip, INET6_ADDRSTRLEN))
  1411. netdata_log_info("Cannot convert IPv6 Address.");
  1412. memcpy(&ipv6_addr.sin6_addr, key->daddr.addr8, sizeof(key->daddr.addr8));
  1413. if(!inet_ntop(AF_INET6, &ipv6_addr.sin6_addr, dst->socket_string.dst_ip, INET6_ADDRSTRLEN))
  1414. netdata_log_info("Cannot convert IPv6 Address.");
  1415. snprintfz(dst->socket_string.dst_port, NI_MAXSERV, "%u", ntohs(key->dport));
  1416. }
  1417. }
  1418. dst->pid = key->pid;
  1419. if (!strcmp(dst->socket_string.dst_port, "0"))
  1420. snprintfz(dst->socket_string.dst_port, NI_MAXSERV, "%u", ntohs(key->dport));
  1421. #ifdef NETDATA_DEV_MODE
  1422. collector_info("New socket: { ORIGIN IP: %s, ORIGIN : %u, DST IP:%s, DST PORT: %s, PID: %u, PROTO: %d, FAMILY: %d}",
  1423. dst->socket_string.src_ip,
  1424. dst->data.external_origin,
  1425. dst->socket_string.dst_ip,
  1426. dst->socket_string.dst_port,
  1427. dst->pid,
  1428. dst->data.protocol,
  1429. dst->data.family
  1430. );
  1431. #endif
  1432. }
  1433. /**
  1434. * Update array vectors
  1435. *
  1436. * Read data from hash table and update vectors.
  1437. *
  1438. * @param em the structure with configuration
  1439. */
  1440. static void ebpf_update_array_vectors(ebpf_module_t *em)
  1441. {
  1442. netdata_thread_disable_cancelability();
  1443. netdata_socket_idx_t key = {};
  1444. netdata_socket_idx_t next_key = {};
  1445. int maps_per_core = em->maps_per_core;
  1446. int fd = em->maps[NETDATA_SOCKET_OPEN_SOCKET].map_fd;
  1447. netdata_socket_t *values = socket_values;
  1448. size_t length = sizeof(netdata_socket_t);
  1449. int test, end;
  1450. if (maps_per_core) {
  1451. length *= ebpf_nprocs;
  1452. end = ebpf_nprocs;
  1453. } else
  1454. end = 1;
  1455. // We need to reset the values when we are working on kernel 4.15 or newer, because kernel does not create
  1456. // values for specific processor unless it is used to store data. As result of this behavior one the next socket
  1457. // can have values from the previous one.
  1458. memset(values, 0, length);
  1459. time_t update_time = time(NULL);
  1460. while (bpf_map_get_next_key(fd, &key, &next_key) == 0) {
  1461. test = bpf_map_lookup_elem(fd, &key, values);
  1462. if (test < 0) {
  1463. goto end_socket_loop;
  1464. }
  1465. if (key.pid > (uint32_t)pid_max) {
  1466. goto end_socket_loop;
  1467. }
  1468. ebpf_hash_socket_accumulator(values, end);
  1469. ebpf_socket_fill_publish_apps(key.pid, values);
  1470. // We update UDP to show info with charts, but we do not show them with functions
  1471. /*
  1472. if (key.dport == NETDATA_EBPF_UDP_PORT && values[0].protocol == IPPROTO_UDP) {
  1473. bpf_map_delete_elem(fd, &key);
  1474. goto end_socket_loop;
  1475. }
  1476. */
  1477. // Discard non-bind sockets
  1478. if (!key.daddr.addr64[0] && !key.daddr.addr64[1] && !key.saddr.addr64[0] && !key.saddr.addr64[1]) {
  1479. bpf_map_delete_elem(fd, &key);
  1480. goto end_socket_loop;
  1481. }
  1482. // When socket is not allowed, we do not append it to table, but we are still keeping it to accumulate data.
  1483. if (!ebpf_is_socket_allowed(&key, values)) {
  1484. goto end_socket_loop;
  1485. }
  1486. // Get PID structure
  1487. rw_spinlock_write_lock(&ebpf_judy_pid.index.rw_spinlock);
  1488. PPvoid_t judy_array = &ebpf_judy_pid.index.JudyLArray;
  1489. netdata_ebpf_judy_pid_stats_t *pid_ptr = ebpf_get_pid_from_judy_unsafe(judy_array, key.pid);
  1490. if (!pid_ptr) {
  1491. goto end_socket_loop;
  1492. }
  1493. // Get Socket structure
  1494. rw_spinlock_write_lock(&pid_ptr->socket_stats.rw_spinlock);
  1495. netdata_socket_plus_t **socket_pptr = (netdata_socket_plus_t **)ebpf_judy_insert_unsafe(
  1496. &pid_ptr->socket_stats.JudyLArray, values[0].first_timestamp);
  1497. netdata_socket_plus_t *socket_ptr = *socket_pptr;
  1498. bool translate = false;
  1499. if (likely(*socket_pptr == NULL)) {
  1500. *socket_pptr = aral_mallocz(aral_socket_table);
  1501. socket_ptr = *socket_pptr;
  1502. translate = true;
  1503. }
  1504. uint64_t prev_period = socket_ptr->data.current_timestamp;
  1505. memcpy(&socket_ptr->data, &values[0], sizeof(netdata_socket_t));
  1506. if (translate)
  1507. ebpf_socket_translate(socket_ptr, &key);
  1508. else { // Check socket was updated
  1509. if (prev_period) {
  1510. if (values[0].current_timestamp > prev_period) // Socket updated
  1511. socket_ptr->last_update = update_time;
  1512. else if ((update_time - socket_ptr->last_update) > em->update_every) {
  1513. // Socket was not updated since last read
  1514. JudyLDel(&pid_ptr->socket_stats.JudyLArray, values[0].first_timestamp, PJE0);
  1515. aral_freez(aral_socket_table, socket_ptr);
  1516. }
  1517. } else // First time
  1518. socket_ptr->last_update = update_time;
  1519. }
  1520. rw_spinlock_write_unlock(&pid_ptr->socket_stats.rw_spinlock);
  1521. rw_spinlock_write_unlock(&ebpf_judy_pid.index.rw_spinlock);
  1522. end_socket_loop:
  1523. memset(values, 0, length);
  1524. memcpy(&key, &next_key, sizeof(key));
  1525. }
  1526. netdata_thread_enable_cancelability();
  1527. }
  1528. /**
  1529. * Socket thread
  1530. *
  1531. * Thread used to generate socket charts.
  1532. *
  1533. * @param ptr a pointer to `struct ebpf_module`
  1534. *
  1535. * @return It always return NULL
  1536. */
  1537. void *ebpf_read_socket_thread(void *ptr)
  1538. {
  1539. heartbeat_t hb;
  1540. heartbeat_init(&hb);
  1541. ebpf_module_t *em = (ebpf_module_t *)ptr;
  1542. ebpf_update_array_vectors(em);
  1543. int update_every = em->update_every;
  1544. int counter = update_every - 1;
  1545. uint32_t running_time = 0;
  1546. uint32_t lifetime = em->lifetime;
  1547. usec_t period = update_every * USEC_PER_SEC;
  1548. while (!ebpf_plugin_exit && running_time < lifetime) {
  1549. (void)heartbeat_next(&hb, period);
  1550. if (ebpf_plugin_exit || ++counter != update_every)
  1551. continue;
  1552. ebpf_update_array_vectors(em);
  1553. counter = 0;
  1554. }
  1555. return NULL;
  1556. }
  1557. /**
  1558. * Fill Network Viewer Port list
  1559. *
  1560. * Fill the structure with values read from /proc or hash table.
  1561. *
  1562. * @param out the structure where we will store data.
  1563. * @param value the ports we are listen to.
  1564. * @param proto the protocol used for this connection.
  1565. * @param in the structure with values read form different sources.
  1566. */
  1567. static inline void fill_nv_port_list(ebpf_network_viewer_port_list_t *out, uint16_t value, uint16_t proto,
  1568. netdata_passive_connection_t *in)
  1569. {
  1570. out->first = value;
  1571. out->protocol = proto;
  1572. out->pid = in->pid;
  1573. out->tgid = in->tgid;
  1574. out->connections = in->counter;
  1575. }
  1576. /**
  1577. * Update listen table
  1578. *
  1579. * Update link list when it is necessary.
  1580. *
  1581. * @param value the ports we are listen to.
  1582. * @param proto the protocol used with port connection.
  1583. * @param in the structure with values read form different sources.
  1584. */
  1585. void update_listen_table(uint16_t value, uint16_t proto, netdata_passive_connection_t *in)
  1586. {
  1587. ebpf_network_viewer_port_list_t *w;
  1588. if (likely(listen_ports)) {
  1589. ebpf_network_viewer_port_list_t *move = listen_ports, *store = listen_ports;
  1590. while (move) {
  1591. if (move->protocol == proto && move->first == value) {
  1592. move->pid = in->pid;
  1593. move->tgid = in->tgid;
  1594. move->connections = in->counter;
  1595. return;
  1596. }
  1597. store = move;
  1598. move = move->next;
  1599. }
  1600. w = callocz(1, sizeof(ebpf_network_viewer_port_list_t));
  1601. store->next = w;
  1602. } else {
  1603. w = callocz(1, sizeof(ebpf_network_viewer_port_list_t));
  1604. listen_ports = w;
  1605. }
  1606. fill_nv_port_list(w, value, proto, in);
  1607. #ifdef NETDATA_INTERNAL_CHECKS
  1608. netdata_log_info("The network viewer is monitoring inbound connections for port %u", ntohs(value));
  1609. #endif
  1610. }
  1611. /**
  1612. * Read listen table
  1613. *
  1614. * Read the table with all ports that we are listen on host.
  1615. */
  1616. static void read_listen_table()
  1617. {
  1618. netdata_passive_connection_idx_t key = {};
  1619. netdata_passive_connection_idx_t next_key = {};
  1620. int fd = socket_maps[NETDATA_SOCKET_LPORTS].map_fd;
  1621. netdata_passive_connection_t value = {};
  1622. while (bpf_map_get_next_key(fd, &key, &next_key) == 0) {
  1623. int test = bpf_map_lookup_elem(fd, &key, &value);
  1624. if (test < 0) {
  1625. key = next_key;
  1626. continue;
  1627. }
  1628. // The correct protocol must come from kernel
  1629. update_listen_table(key.port, key.protocol, &value);
  1630. key = next_key;
  1631. memset(&value, 0, sizeof(value));
  1632. }
  1633. if (next_key.port && value.pid) {
  1634. // The correct protocol must come from kernel
  1635. update_listen_table(next_key.port, next_key.protocol, &value);
  1636. }
  1637. }
  1638. /**
  1639. * Read the hash table and store data to allocated vectors.
  1640. *
  1641. * @param stats vector used to read data from control table.
  1642. * @param maps_per_core do I need to read all cores?
  1643. */
  1644. static void ebpf_socket_read_hash_global_tables(netdata_idx_t *stats, int maps_per_core)
  1645. {
  1646. netdata_idx_t res[NETDATA_SOCKET_COUNTER];
  1647. ebpf_read_global_table_stats(res,
  1648. socket_hash_values,
  1649. socket_maps[NETDATA_SOCKET_GLOBAL].map_fd,
  1650. maps_per_core,
  1651. NETDATA_KEY_CALLS_TCP_SENDMSG,
  1652. NETDATA_SOCKET_COUNTER);
  1653. ebpf_read_global_table_stats(stats,
  1654. socket_hash_values,
  1655. socket_maps[NETDATA_SOCKET_TABLE_CTRL].map_fd,
  1656. maps_per_core,
  1657. NETDATA_CONTROLLER_PID_TABLE_ADD,
  1658. NETDATA_CONTROLLER_END);
  1659. socket_aggregated_data[NETDATA_IDX_TCP_SENDMSG].call = res[NETDATA_KEY_CALLS_TCP_SENDMSG];
  1660. socket_aggregated_data[NETDATA_IDX_TCP_CLEANUP_RBUF].call = res[NETDATA_KEY_CALLS_TCP_CLEANUP_RBUF];
  1661. socket_aggregated_data[NETDATA_IDX_TCP_CLOSE].call = res[NETDATA_KEY_CALLS_TCP_CLOSE];
  1662. socket_aggregated_data[NETDATA_IDX_UDP_RECVBUF].call = res[NETDATA_KEY_CALLS_UDP_RECVMSG];
  1663. socket_aggregated_data[NETDATA_IDX_UDP_SENDMSG].call = res[NETDATA_KEY_CALLS_UDP_SENDMSG];
  1664. socket_aggregated_data[NETDATA_IDX_TCP_RETRANSMIT].call = res[NETDATA_KEY_TCP_RETRANSMIT];
  1665. socket_aggregated_data[NETDATA_IDX_TCP_CONNECTION_V4].call = res[NETDATA_KEY_CALLS_TCP_CONNECT_IPV4];
  1666. socket_aggregated_data[NETDATA_IDX_TCP_CONNECTION_V6].call = res[NETDATA_KEY_CALLS_TCP_CONNECT_IPV6];
  1667. socket_aggregated_data[NETDATA_IDX_TCP_SENDMSG].ecall = res[NETDATA_KEY_ERROR_TCP_SENDMSG];
  1668. socket_aggregated_data[NETDATA_IDX_TCP_CLEANUP_RBUF].ecall = res[NETDATA_KEY_ERROR_TCP_CLEANUP_RBUF];
  1669. socket_aggregated_data[NETDATA_IDX_UDP_RECVBUF].ecall = res[NETDATA_KEY_ERROR_UDP_RECVMSG];
  1670. socket_aggregated_data[NETDATA_IDX_UDP_SENDMSG].ecall = res[NETDATA_KEY_ERROR_UDP_SENDMSG];
  1671. socket_aggregated_data[NETDATA_IDX_TCP_CONNECTION_V4].ecall = res[NETDATA_KEY_ERROR_TCP_CONNECT_IPV4];
  1672. socket_aggregated_data[NETDATA_IDX_TCP_CONNECTION_V6].ecall = res[NETDATA_KEY_ERROR_TCP_CONNECT_IPV6];
  1673. socket_aggregated_data[NETDATA_IDX_TCP_SENDMSG].bytes = res[NETDATA_KEY_BYTES_TCP_SENDMSG];
  1674. socket_aggregated_data[NETDATA_IDX_TCP_CLEANUP_RBUF].bytes = res[NETDATA_KEY_BYTES_TCP_CLEANUP_RBUF];
  1675. socket_aggregated_data[NETDATA_IDX_UDP_RECVBUF].bytes = res[NETDATA_KEY_BYTES_UDP_RECVMSG];
  1676. socket_aggregated_data[NETDATA_IDX_UDP_SENDMSG].bytes = res[NETDATA_KEY_BYTES_UDP_SENDMSG];
  1677. }
  1678. /**
  1679. * Fill publish apps when necessary.
  1680. *
  1681. * @param current_pid the PID that I am updating
  1682. * @param ns the structure with data read from memory.
  1683. */
  1684. void ebpf_socket_fill_publish_apps(uint32_t current_pid, netdata_socket_t *ns)
  1685. {
  1686. ebpf_socket_publish_apps_t *curr = socket_bandwidth_curr[current_pid];
  1687. if (!curr) {
  1688. curr = ebpf_socket_stat_get();
  1689. socket_bandwidth_curr[current_pid] = curr;
  1690. }
  1691. curr->bytes_sent += ns->tcp.tcp_bytes_sent;
  1692. curr->bytes_received += ns->tcp.tcp_bytes_received;
  1693. curr->call_tcp_sent += ns->tcp.call_tcp_sent;
  1694. curr->call_tcp_received += ns->tcp.call_tcp_received;
  1695. curr->retransmit += ns->tcp.retransmit;
  1696. curr->call_close += ns->tcp.close;
  1697. curr->call_tcp_v4_connection += ns->tcp.ipv4_connect;
  1698. curr->call_tcp_v6_connection += ns->tcp.ipv6_connect;
  1699. curr->call_udp_sent += ns->udp.call_udp_sent;
  1700. curr->call_udp_received += ns->udp.call_udp_received;
  1701. }
  1702. /**
  1703. * Update cgroup
  1704. *
  1705. * Update cgroup data based in PIDs.
  1706. */
  1707. static void ebpf_update_socket_cgroup()
  1708. {
  1709. ebpf_cgroup_target_t *ect ;
  1710. pthread_mutex_lock(&mutex_cgroup_shm);
  1711. for (ect = ebpf_cgroup_pids; ect; ect = ect->next) {
  1712. struct pid_on_target2 *pids;
  1713. for (pids = ect->pids; pids; pids = pids->next) {
  1714. int pid = pids->pid;
  1715. ebpf_socket_publish_apps_t *publish = &ect->publish_socket;
  1716. if (likely(socket_bandwidth_curr) && socket_bandwidth_curr[pid]) {
  1717. ebpf_socket_publish_apps_t *in = socket_bandwidth_curr[pid];
  1718. publish->bytes_sent = in->bytes_sent;
  1719. publish->bytes_received = in->bytes_received;
  1720. publish->call_tcp_sent = in->call_tcp_sent;
  1721. publish->call_tcp_received = in->call_tcp_received;
  1722. publish->retransmit = in->retransmit;
  1723. publish->call_udp_sent = in->call_udp_sent;
  1724. publish->call_udp_received = in->call_udp_received;
  1725. publish->call_close = in->call_close;
  1726. publish->call_tcp_v4_connection = in->call_tcp_v4_connection;
  1727. publish->call_tcp_v6_connection = in->call_tcp_v6_connection;
  1728. }
  1729. }
  1730. }
  1731. pthread_mutex_unlock(&mutex_cgroup_shm);
  1732. }
  1733. /**
  1734. * Sum PIDs
  1735. *
  1736. * Sum values for all targets.
  1737. *
  1738. * @param fd structure used to store data
  1739. * @param pids input data
  1740. */
  1741. static void ebpf_socket_sum_cgroup_pids(ebpf_socket_publish_apps_t *socket, struct pid_on_target2 *pids)
  1742. {
  1743. ebpf_socket_publish_apps_t accumulator;
  1744. memset(&accumulator, 0, sizeof(accumulator));
  1745. while (pids) {
  1746. netdata_socket_t *w = &pids->socket;
  1747. accumulator.bytes_received += w->tcp.tcp_bytes_received;
  1748. accumulator.bytes_sent += w->tcp.tcp_bytes_sent;
  1749. accumulator.call_tcp_received += w->tcp.call_tcp_received;
  1750. accumulator.call_tcp_sent += w->tcp.call_tcp_sent;
  1751. accumulator.retransmit += w->tcp.retransmit;
  1752. accumulator.call_close += w->tcp.close;
  1753. accumulator.call_tcp_v4_connection += w->tcp.ipv4_connect;
  1754. accumulator.call_tcp_v6_connection += w->tcp.ipv6_connect;
  1755. accumulator.call_udp_received += w->udp.call_udp_received;
  1756. accumulator.call_udp_sent += w->udp.call_udp_sent;
  1757. pids = pids->next;
  1758. }
  1759. socket->bytes_sent = (accumulator.bytes_sent >= socket->bytes_sent) ? accumulator.bytes_sent : socket->bytes_sent;
  1760. socket->bytes_received = (accumulator.bytes_received >= socket->bytes_received) ? accumulator.bytes_received : socket->bytes_received;
  1761. socket->call_tcp_sent = (accumulator.call_tcp_sent >= socket->call_tcp_sent) ? accumulator.call_tcp_sent : socket->call_tcp_sent;
  1762. socket->call_tcp_received = (accumulator.call_tcp_received >= socket->call_tcp_received) ? accumulator.call_tcp_received : socket->call_tcp_received;
  1763. socket->retransmit = (accumulator.retransmit >= socket->retransmit) ? accumulator.retransmit : socket->retransmit;
  1764. socket->call_udp_sent = (accumulator.call_udp_sent >= socket->call_udp_sent) ? accumulator.call_udp_sent : socket->call_udp_sent;
  1765. socket->call_udp_received = (accumulator.call_udp_received >= socket->call_udp_received) ? accumulator.call_udp_received : socket->call_udp_received;
  1766. socket->call_close = (accumulator.call_close >= socket->call_close) ? accumulator.call_close : socket->call_close;
  1767. socket->call_tcp_v4_connection = (accumulator.call_tcp_v4_connection >= socket->call_tcp_v4_connection) ?
  1768. accumulator.call_tcp_v4_connection : socket->call_tcp_v4_connection;
  1769. socket->call_tcp_v6_connection = (accumulator.call_tcp_v6_connection >= socket->call_tcp_v6_connection) ?
  1770. accumulator.call_tcp_v6_connection : socket->call_tcp_v6_connection;
  1771. }
  1772. /**
  1773. * Create specific socket charts
  1774. *
  1775. * Create charts for cgroup/application.
  1776. *
  1777. * @param type the chart type.
  1778. * @param update_every value to overwrite the update frequency set by the server.
  1779. */
  1780. static void ebpf_create_specific_socket_charts(char *type, int update_every)
  1781. {
  1782. int order_basis = 5300;
  1783. ebpf_create_chart(type, NETDATA_NET_APPS_CONNECTION_TCP_V4,
  1784. "Calls to tcp_v4_connection",
  1785. EBPF_COMMON_DIMENSION_CONNECTIONS, NETDATA_CGROUP_NET_GROUP,
  1786. NETDATA_CGROUP_TCP_V4_CONN_CONTEXT,
  1787. NETDATA_EBPF_CHART_TYPE_LINE,
  1788. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1789. ebpf_create_global_dimension,
  1790. &socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V4], 1,
  1791. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1792. ebpf_create_chart(type, NETDATA_NET_APPS_CONNECTION_TCP_V6,
  1793. "Calls to tcp_v6_connection",
  1794. EBPF_COMMON_DIMENSION_CONNECTIONS, NETDATA_CGROUP_NET_GROUP,
  1795. NETDATA_CGROUP_TCP_V6_CONN_CONTEXT,
  1796. NETDATA_EBPF_CHART_TYPE_LINE,
  1797. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1798. ebpf_create_global_dimension,
  1799. &socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V6], 1,
  1800. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1801. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_RECV,
  1802. "Bytes received",
  1803. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1804. NETDATA_CGROUP_SOCKET_BYTES_RECV_CONTEXT,
  1805. NETDATA_EBPF_CHART_TYPE_LINE,
  1806. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1807. ebpf_create_global_dimension,
  1808. &socket_publish_aggregated[NETDATA_IDX_TCP_CLEANUP_RBUF], 1,
  1809. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1810. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_SENT,
  1811. "Bytes sent",
  1812. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1813. NETDATA_CGROUP_SOCKET_BYTES_SEND_CONTEXT,
  1814. NETDATA_EBPF_CHART_TYPE_LINE,
  1815. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1816. ebpf_create_global_dimension,
  1817. socket_publish_aggregated, 1,
  1818. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1819. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS,
  1820. "Calls to tcp_cleanup_rbuf.",
  1821. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1822. NETDATA_CGROUP_SOCKET_TCP_RECV_CONTEXT,
  1823. NETDATA_EBPF_CHART_TYPE_LINE,
  1824. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1825. ebpf_create_global_dimension,
  1826. &socket_publish_aggregated[NETDATA_IDX_TCP_CLEANUP_RBUF], 1,
  1827. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1828. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS,
  1829. "Calls to tcp_sendmsg.",
  1830. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1831. NETDATA_CGROUP_SOCKET_TCP_SEND_CONTEXT,
  1832. NETDATA_EBPF_CHART_TYPE_LINE,
  1833. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1834. ebpf_create_global_dimension,
  1835. socket_publish_aggregated, 1,
  1836. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1837. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT,
  1838. "Calls to tcp_retransmit.",
  1839. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1840. NETDATA_CGROUP_SOCKET_TCP_RETRANSMIT_CONTEXT,
  1841. NETDATA_EBPF_CHART_TYPE_LINE,
  1842. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1843. ebpf_create_global_dimension,
  1844. &socket_publish_aggregated[NETDATA_IDX_TCP_RETRANSMIT], 1,
  1845. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1846. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS,
  1847. "Calls to udp_sendmsg",
  1848. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1849. NETDATA_CGROUP_SOCKET_UDP_SEND_CONTEXT,
  1850. NETDATA_EBPF_CHART_TYPE_LINE,
  1851. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1852. ebpf_create_global_dimension,
  1853. &socket_publish_aggregated[NETDATA_IDX_UDP_SENDMSG], 1,
  1854. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1855. ebpf_create_chart(type, NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS,
  1856. "Calls to udp_recvmsg",
  1857. EBPF_COMMON_DIMENSION_CALL, NETDATA_CGROUP_NET_GROUP,
  1858. NETDATA_CGROUP_SOCKET_UDP_RECV_CONTEXT,
  1859. NETDATA_EBPF_CHART_TYPE_LINE,
  1860. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++,
  1861. ebpf_create_global_dimension,
  1862. &socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF], 1,
  1863. update_every, NETDATA_EBPF_MODULE_NAME_SOCKET);
  1864. }
  1865. /**
  1866. * Obsolete specific socket charts
  1867. *
  1868. * Obsolete charts for cgroup/application.
  1869. *
  1870. * @param type the chart type.
  1871. * @param update_every value to overwrite the update frequency set by the server.
  1872. */
  1873. static void ebpf_obsolete_specific_socket_charts(char *type, int update_every)
  1874. {
  1875. int order_basis = 5300;
  1876. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_CONNECTION_TCP_V4, "Calls to tcp_v4_connection",
  1877. EBPF_COMMON_DIMENSION_CONNECTIONS, NETDATA_APPS_NET_GROUP,
  1878. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_TCP_V4_CONN_CONTEXT,
  1879. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1880. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_CONNECTION_TCP_V6,"Calls to tcp_v6_connection",
  1881. EBPF_COMMON_DIMENSION_CONNECTIONS, NETDATA_APPS_NET_GROUP,
  1882. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_TCP_V6_CONN_CONTEXT,
  1883. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1884. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_RECV, "Bytes received",
  1885. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1886. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_BYTES_RECV_CONTEXT,
  1887. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1888. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_SENT,"Bytes sent",
  1889. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1890. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_BYTES_SEND_CONTEXT,
  1891. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1892. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS, "Calls to tcp_cleanup_rbuf.",
  1893. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1894. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_TCP_RECV_CONTEXT,
  1895. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1896. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS, "Calls to tcp_sendmsg.",
  1897. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1898. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_TCP_SEND_CONTEXT,
  1899. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1900. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT, "Calls to tcp_retransmit.",
  1901. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1902. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_TCP_RETRANSMIT_CONTEXT,
  1903. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1904. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS, "Calls to udp_sendmsg",
  1905. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP,
  1906. NETDATA_EBPF_CHART_TYPE_LINE, NETDATA_SERVICES_SOCKET_UDP_SEND_CONTEXT,
  1907. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1908. ebpf_write_chart_obsolete(type, NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS, "Calls to udp_recvmsg",
  1909. EBPF_COMMON_DIMENSION_CALL, NETDATA_APPS_NET_GROUP, NETDATA_EBPF_CHART_TYPE_LINE,
  1910. NETDATA_SERVICES_SOCKET_UDP_RECV_CONTEXT,
  1911. NETDATA_CHART_PRIO_CGROUPS_CONTAINERS + order_basis++, update_every);
  1912. }
  1913. /*
  1914. * Send Specific Swap data
  1915. *
  1916. * Send data for specific cgroup/apps.
  1917. *
  1918. * @param type chart type
  1919. * @param values structure with values that will be sent to netdata
  1920. */
  1921. static void ebpf_send_specific_socket_data(char *type, ebpf_socket_publish_apps_t *values)
  1922. {
  1923. write_begin_chart(type, NETDATA_NET_APPS_CONNECTION_TCP_V4);
  1924. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V4].name,
  1925. (long long) values->call_tcp_v4_connection);
  1926. write_end_chart();
  1927. write_begin_chart(type, NETDATA_NET_APPS_CONNECTION_TCP_V6);
  1928. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_CONNECTION_V6].name,
  1929. (long long) values->call_tcp_v6_connection);
  1930. write_end_chart();
  1931. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_SENT);
  1932. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_SENDMSG].name,
  1933. (long long) values->bytes_sent);
  1934. write_end_chart();
  1935. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_RECV);
  1936. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_CLEANUP_RBUF].name,
  1937. (long long) values->bytes_received);
  1938. write_end_chart();
  1939. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS);
  1940. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_SENDMSG].name,
  1941. (long long) values->call_tcp_sent);
  1942. write_end_chart();
  1943. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS);
  1944. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_CLEANUP_RBUF].name,
  1945. (long long) values->call_tcp_received);
  1946. write_end_chart();
  1947. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT);
  1948. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_TCP_RETRANSMIT].name,
  1949. (long long) values->retransmit);
  1950. write_end_chart();
  1951. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS);
  1952. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_UDP_SENDMSG].name,
  1953. (long long) values->call_udp_sent);
  1954. write_end_chart();
  1955. write_begin_chart(type, NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS);
  1956. write_chart_dimension(socket_publish_aggregated[NETDATA_IDX_UDP_RECVBUF].name,
  1957. (long long) values->call_udp_received);
  1958. write_end_chart();
  1959. }
  1960. /**
  1961. * Create Systemd Socket Charts
  1962. *
  1963. * Create charts when systemd is enabled
  1964. *
  1965. * @param update_every value to overwrite the update frequency set by the server.
  1966. **/
  1967. static void ebpf_create_systemd_socket_charts(int update_every)
  1968. {
  1969. int order = 20080;
  1970. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_CONNECTION_TCP_V4,
  1971. "Calls to tcp_v4_connection", EBPF_COMMON_DIMENSION_CONNECTIONS,
  1972. NETDATA_APPS_NET_GROUP,
  1973. NETDATA_EBPF_CHART_TYPE_STACKED,
  1974. order++,
  1975. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1976. NETDATA_SERVICES_SOCKET_TCP_V4_CONN_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  1977. update_every);
  1978. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_CONNECTION_TCP_V6,
  1979. "Calls to tcp_v6_connection", EBPF_COMMON_DIMENSION_CONNECTIONS,
  1980. NETDATA_APPS_NET_GROUP,
  1981. NETDATA_EBPF_CHART_TYPE_STACKED,
  1982. order++,
  1983. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1984. NETDATA_SERVICES_SOCKET_TCP_V6_CONN_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  1985. update_every);
  1986. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_RECV,
  1987. "Bytes received", EBPF_COMMON_DIMENSION_BITS,
  1988. NETDATA_APPS_NET_GROUP,
  1989. NETDATA_EBPF_CHART_TYPE_STACKED,
  1990. order++,
  1991. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  1992. NETDATA_SERVICES_SOCKET_BYTES_RECV_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  1993. update_every);
  1994. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_SENT,
  1995. "Bytes sent", EBPF_COMMON_DIMENSION_BITS,
  1996. NETDATA_APPS_NET_GROUP,
  1997. NETDATA_EBPF_CHART_TYPE_STACKED,
  1998. order++,
  1999. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2000. NETDATA_SERVICES_SOCKET_BYTES_SEND_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2001. update_every);
  2002. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS,
  2003. "Calls to tcp_cleanup_rbuf.",
  2004. EBPF_COMMON_DIMENSION_CALL,
  2005. NETDATA_APPS_NET_GROUP,
  2006. NETDATA_EBPF_CHART_TYPE_STACKED,
  2007. order++,
  2008. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2009. NETDATA_SERVICES_SOCKET_TCP_RECV_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2010. update_every);
  2011. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS,
  2012. "Calls to tcp_sendmsg.",
  2013. EBPF_COMMON_DIMENSION_CALL,
  2014. NETDATA_APPS_NET_GROUP,
  2015. NETDATA_EBPF_CHART_TYPE_STACKED,
  2016. order++,
  2017. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2018. NETDATA_SERVICES_SOCKET_TCP_SEND_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2019. update_every);
  2020. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT,
  2021. "Calls to tcp_retransmit",
  2022. EBPF_COMMON_DIMENSION_CALL,
  2023. NETDATA_APPS_NET_GROUP,
  2024. NETDATA_EBPF_CHART_TYPE_STACKED,
  2025. order++,
  2026. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2027. NETDATA_SERVICES_SOCKET_TCP_RETRANSMIT_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2028. update_every);
  2029. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS,
  2030. "Calls to udp_sendmsg",
  2031. EBPF_COMMON_DIMENSION_CALL,
  2032. NETDATA_APPS_NET_GROUP,
  2033. NETDATA_EBPF_CHART_TYPE_STACKED,
  2034. order++,
  2035. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2036. NETDATA_SERVICES_SOCKET_UDP_SEND_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2037. update_every);
  2038. ebpf_create_charts_on_systemd(NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS,
  2039. "Calls to udp_recvmsg",
  2040. EBPF_COMMON_DIMENSION_CALL,
  2041. NETDATA_APPS_NET_GROUP,
  2042. NETDATA_EBPF_CHART_TYPE_STACKED,
  2043. order++,
  2044. ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX],
  2045. NETDATA_SERVICES_SOCKET_UDP_RECV_CONTEXT, NETDATA_EBPF_MODULE_NAME_SOCKET,
  2046. update_every);
  2047. }
  2048. /**
  2049. * Send Systemd charts
  2050. *
  2051. * Send collected data to Netdata.
  2052. */
  2053. static void ebpf_send_systemd_socket_charts()
  2054. {
  2055. ebpf_cgroup_target_t *ect;
  2056. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_CONNECTION_TCP_V4);
  2057. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2058. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2059. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_tcp_v4_connection);
  2060. }
  2061. }
  2062. write_end_chart();
  2063. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_CONNECTION_TCP_V6);
  2064. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2065. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2066. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_tcp_v6_connection);
  2067. }
  2068. }
  2069. write_end_chart();
  2070. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_SENT);
  2071. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2072. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2073. write_chart_dimension(ect->name, (long long)ect->publish_socket.bytes_sent);
  2074. }
  2075. }
  2076. write_end_chart();
  2077. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_RECV);
  2078. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2079. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2080. write_chart_dimension(ect->name, (long long)ect->publish_socket.bytes_received);
  2081. }
  2082. }
  2083. write_end_chart();
  2084. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_SEND_CALLS);
  2085. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2086. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2087. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_tcp_sent);
  2088. }
  2089. }
  2090. write_end_chart();
  2091. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_RECV_CALLS);
  2092. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2093. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2094. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_tcp_received);
  2095. }
  2096. }
  2097. write_end_chart();
  2098. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_TCP_RETRANSMIT);
  2099. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2100. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2101. write_chart_dimension(ect->name, (long long)ect->publish_socket.retransmit);
  2102. }
  2103. }
  2104. write_end_chart();
  2105. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_UDP_SEND_CALLS);
  2106. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2107. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2108. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_udp_sent);
  2109. }
  2110. }
  2111. write_end_chart();
  2112. write_begin_chart(NETDATA_SERVICE_FAMILY, NETDATA_NET_APPS_BANDWIDTH_UDP_RECV_CALLS);
  2113. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2114. if (unlikely(ect->systemd) && unlikely(ect->updated)) {
  2115. write_chart_dimension(ect->name, (long long)ect->publish_socket.call_udp_received);
  2116. }
  2117. }
  2118. write_end_chart();
  2119. }
  2120. /**
  2121. * Update Cgroup algorithm
  2122. *
  2123. * Change algorithm from absolute to incremental
  2124. */
  2125. void ebpf_socket_update_cgroup_algorithm()
  2126. {
  2127. int i;
  2128. for (i = 0; i < NETDATA_MAX_SOCKET_VECTOR; i++) {
  2129. netdata_publish_syscall_t *ptr = &socket_publish_aggregated[i];
  2130. ptr->algorithm = ebpf_algorithms[NETDATA_EBPF_INCREMENTAL_IDX];
  2131. }
  2132. }
  2133. /**
  2134. * Send data to Netdata calling auxiliary functions.
  2135. *
  2136. * @param update_every value to overwrite the update frequency set by the server.
  2137. */
  2138. static void ebpf_socket_send_cgroup_data(int update_every)
  2139. {
  2140. if (!ebpf_cgroup_pids)
  2141. return;
  2142. pthread_mutex_lock(&mutex_cgroup_shm);
  2143. ebpf_cgroup_target_t *ect;
  2144. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2145. ebpf_socket_sum_cgroup_pids(&ect->publish_socket, ect->pids);
  2146. }
  2147. int has_systemd = shm_ebpf_cgroup.header->systemd_enabled;
  2148. if (has_systemd) {
  2149. if (send_cgroup_chart) {
  2150. ebpf_create_systemd_socket_charts(update_every);
  2151. }
  2152. ebpf_send_systemd_socket_charts();
  2153. }
  2154. for (ect = ebpf_cgroup_pids; ect ; ect = ect->next) {
  2155. if (ect->systemd)
  2156. continue;
  2157. if (!(ect->flags & NETDATA_EBPF_CGROUP_HAS_SOCKET_CHART)) {
  2158. ebpf_create_specific_socket_charts(ect->name, update_every);
  2159. ect->flags |= NETDATA_EBPF_CGROUP_HAS_SOCKET_CHART;
  2160. }
  2161. if (ect->flags & NETDATA_EBPF_CGROUP_HAS_SOCKET_CHART && ect->updated) {
  2162. ebpf_send_specific_socket_data(ect->name, &ect->publish_socket);
  2163. } else {
  2164. ebpf_obsolete_specific_socket_charts(ect->name, update_every);
  2165. ect->flags &= ~NETDATA_EBPF_CGROUP_HAS_SOCKET_CHART;
  2166. }
  2167. }
  2168. pthread_mutex_unlock(&mutex_cgroup_shm);
  2169. }
  2170. /*****************************************************************
  2171. *
  2172. * FUNCTIONS WITH THE MAIN LOOP
  2173. *
  2174. *****************************************************************/
  2175. /**
  2176. * Main loop for this collector.
  2177. *
  2178. * @param em the structure with thread information
  2179. */
  2180. static void socket_collector(ebpf_module_t *em)
  2181. {
  2182. heartbeat_t hb;
  2183. heartbeat_init(&hb);
  2184. int cgroups = em->cgroup_charts;
  2185. if (cgroups)
  2186. ebpf_socket_update_cgroup_algorithm();
  2187. int socket_global_enabled = em->global_charts;
  2188. int update_every = em->update_every;
  2189. int maps_per_core = em->maps_per_core;
  2190. int counter = update_every - 1;
  2191. uint32_t running_time = 0;
  2192. uint32_t lifetime = em->lifetime;
  2193. netdata_idx_t *stats = em->hash_table_stats;
  2194. memset(stats, 0, sizeof(em->hash_table_stats));
  2195. while (!ebpf_plugin_exit && running_time < lifetime) {
  2196. (void)heartbeat_next(&hb, USEC_PER_SEC);
  2197. if (ebpf_plugin_exit || ++counter != update_every)
  2198. continue;
  2199. counter = 0;
  2200. netdata_apps_integration_flags_t socket_apps_enabled = em->apps_charts;
  2201. if (socket_global_enabled) {
  2202. read_listen_table();
  2203. ebpf_socket_read_hash_global_tables(stats, maps_per_core);
  2204. }
  2205. pthread_mutex_lock(&collect_data_mutex);
  2206. if (cgroups)
  2207. ebpf_update_socket_cgroup();
  2208. pthread_mutex_lock(&lock);
  2209. if (socket_global_enabled)
  2210. ebpf_socket_send_data(em);
  2211. if (socket_apps_enabled & NETDATA_EBPF_APPS_FLAG_CHART_CREATED)
  2212. ebpf_socket_send_apps_data(em, apps_groups_root_target);
  2213. #ifdef NETDATA_DEV_MODE
  2214. if (ebpf_aral_socket_pid)
  2215. ebpf_send_data_aral_chart(ebpf_aral_socket_pid, em);
  2216. #endif
  2217. if (cgroups)
  2218. ebpf_socket_send_cgroup_data(update_every);
  2219. fflush(stdout);
  2220. pthread_mutex_unlock(&lock);
  2221. pthread_mutex_unlock(&collect_data_mutex);
  2222. pthread_mutex_lock(&ebpf_exit_cleanup);
  2223. if (running_time && !em->running_time)
  2224. running_time = update_every;
  2225. else
  2226. running_time += update_every;
  2227. em->running_time = running_time;
  2228. pthread_mutex_unlock(&ebpf_exit_cleanup);
  2229. }
  2230. }
  2231. /*****************************************************************
  2232. *
  2233. * FUNCTIONS TO START THREAD
  2234. *
  2235. *****************************************************************/
  2236. /**
  2237. * Initialize vectors used with this thread.
  2238. *
  2239. * We are not testing the return, because callocz does this and shutdown the software
  2240. * case it was not possible to allocate.
  2241. */
  2242. static void ebpf_socket_initialize_global_vectors()
  2243. {
  2244. memset(socket_aggregated_data, 0 ,NETDATA_MAX_SOCKET_VECTOR * sizeof(netdata_syscall_stat_t));
  2245. memset(socket_publish_aggregated, 0 ,NETDATA_MAX_SOCKET_VECTOR * sizeof(netdata_publish_syscall_t));
  2246. socket_hash_values = callocz(ebpf_nprocs, sizeof(netdata_idx_t));
  2247. ebpf_socket_aral_init();
  2248. socket_bandwidth_curr = callocz((size_t)pid_max, sizeof(ebpf_socket_publish_apps_t *));
  2249. aral_socket_table = ebpf_allocate_pid_aral(NETDATA_EBPF_SOCKET_ARAL_TABLE_NAME,
  2250. sizeof(netdata_socket_plus_t));
  2251. socket_values = callocz((size_t)ebpf_nprocs, sizeof(netdata_socket_t));
  2252. }
  2253. /*****************************************************************
  2254. *
  2255. * EBPF SOCKET THREAD
  2256. *
  2257. *****************************************************************/
  2258. /**
  2259. * Link dimension name
  2260. *
  2261. * Link user specified names inside a link list.
  2262. *
  2263. * @param port the port number associated to the dimension name.
  2264. * @param hash the calculated hash for the dimension name.
  2265. * @param name the dimension name.
  2266. */
  2267. static void ebpf_link_dimension_name(char *port, uint32_t hash, char *value)
  2268. {
  2269. int test = str2i(port);
  2270. if (test < NETDATA_MINIMUM_PORT_VALUE || test > NETDATA_MAXIMUM_PORT_VALUE){
  2271. netdata_log_error("The dimension given (%s = %s) has an invalid value and it will be ignored.", port, value);
  2272. return;
  2273. }
  2274. ebpf_network_viewer_dim_name_t *w;
  2275. w = callocz(1, sizeof(ebpf_network_viewer_dim_name_t));
  2276. w->name = strdupz(value);
  2277. w->hash = hash;
  2278. w->port = (uint16_t) htons(test);
  2279. ebpf_network_viewer_dim_name_t *names = network_viewer_opt.names;
  2280. if (unlikely(!names)) {
  2281. network_viewer_opt.names = w;
  2282. } else {
  2283. for (; names->next; names = names->next) {
  2284. if (names->port == w->port) {
  2285. netdata_log_info("Duplicated definition for a service, the name %s will be ignored. ", names->name);
  2286. freez(names->name);
  2287. names->name = w->name;
  2288. names->hash = w->hash;
  2289. freez(w);
  2290. return;
  2291. }
  2292. }
  2293. names->next = w;
  2294. }
  2295. #ifdef NETDATA_INTERNAL_CHECKS
  2296. netdata_log_info("Adding values %s( %u) to dimension name list used on network viewer", w->name, htons(w->port));
  2297. #endif
  2298. }
  2299. /**
  2300. * Parse service Name section.
  2301. *
  2302. * This function gets the values that will be used to overwrite dimensions.
  2303. *
  2304. * @param cfg the configuration structure
  2305. */
  2306. void ebpf_parse_service_name_section(struct config *cfg)
  2307. {
  2308. struct section *co = appconfig_get_section(cfg, EBPF_SERVICE_NAME_SECTION);
  2309. if (co) {
  2310. struct config_option *cv;
  2311. for (cv = co->values; cv ; cv = cv->next) {
  2312. ebpf_link_dimension_name(cv->name, cv->hash, cv->value);
  2313. }
  2314. }
  2315. // Always associated the default port to Netdata
  2316. ebpf_network_viewer_dim_name_t *names = network_viewer_opt.names;
  2317. if (names) {
  2318. uint16_t default_port = htons(19999);
  2319. while (names) {
  2320. if (names->port == default_port)
  2321. return;
  2322. names = names->next;
  2323. }
  2324. }
  2325. char *port_string = getenv("NETDATA_LISTEN_PORT");
  2326. if (port_string) {
  2327. // if variable has an invalid value, we assume netdata is using 19999
  2328. int default_port = str2i(port_string);
  2329. if (default_port > 0 && default_port < 65536)
  2330. ebpf_link_dimension_name(port_string, simple_hash(port_string), "Netdata");
  2331. }
  2332. }
  2333. /**
  2334. * Parse table size options
  2335. *
  2336. * @param cfg configuration options read from user file.
  2337. */
  2338. void parse_table_size_options(struct config *cfg)
  2339. {
  2340. socket_maps[NETDATA_SOCKET_OPEN_SOCKET].user_input = (uint32_t) appconfig_get_number(cfg,
  2341. EBPF_GLOBAL_SECTION,
  2342. EBPF_CONFIG_SOCKET_MONITORING_SIZE,
  2343. NETDATA_MAXIMUM_CONNECTIONS_ALLOWED);
  2344. socket_maps[NETDATA_SOCKET_TABLE_UDP].user_input = (uint32_t) appconfig_get_number(cfg,
  2345. EBPF_GLOBAL_SECTION,
  2346. EBPF_CONFIG_UDP_SIZE, NETDATA_MAXIMUM_UDP_CONNECTIONS_ALLOWED);
  2347. }
  2348. /*
  2349. * Load BPF
  2350. *
  2351. * Load BPF files.
  2352. *
  2353. * @param em the structure with configuration
  2354. */
  2355. static int ebpf_socket_load_bpf(ebpf_module_t *em)
  2356. {
  2357. #ifdef LIBBPF_MAJOR_VERSION
  2358. ebpf_define_map_type(em->maps, em->maps_per_core, running_on_kernel);
  2359. #endif
  2360. int ret = 0;
  2361. if (em->load & EBPF_LOAD_LEGACY) {
  2362. em->probe_links = ebpf_load_program(ebpf_plugin_dir, em, running_on_kernel, isrh, &em->objects);
  2363. if (!em->probe_links) {
  2364. ret = -1;
  2365. }
  2366. }
  2367. #ifdef LIBBPF_MAJOR_VERSION
  2368. else {
  2369. socket_bpf_obj = socket_bpf__open();
  2370. if (!socket_bpf_obj)
  2371. ret = -1;
  2372. else
  2373. ret = ebpf_socket_load_and_attach(socket_bpf_obj, em);
  2374. }
  2375. #endif
  2376. if (ret) {
  2377. netdata_log_error("%s %s", EBPF_DEFAULT_ERROR_MSG, em->info.thread_name);
  2378. }
  2379. return ret;
  2380. }
  2381. /**
  2382. * Socket thread
  2383. *
  2384. * Thread used to generate socket charts.
  2385. *
  2386. * @param ptr a pointer to `struct ebpf_module`
  2387. *
  2388. * @return It always return NULL
  2389. */
  2390. void *ebpf_socket_thread(void *ptr)
  2391. {
  2392. netdata_thread_cleanup_push(ebpf_socket_exit, ptr);
  2393. ebpf_module_t *em = (ebpf_module_t *)ptr;
  2394. if (em->enabled > NETDATA_THREAD_EBPF_FUNCTION_RUNNING) {
  2395. collector_error("There is already a thread %s running", em->info.thread_name);
  2396. return NULL;
  2397. }
  2398. em->maps = socket_maps;
  2399. rw_spinlock_write_lock(&network_viewer_opt.rw_spinlock);
  2400. // It was not enabled from main config file (ebpf.d.conf)
  2401. if (!network_viewer_opt.enabled)
  2402. network_viewer_opt.enabled = appconfig_get_boolean(&socket_config, EBPF_NETWORK_VIEWER_SECTION, "enabled",
  2403. CONFIG_BOOLEAN_YES);
  2404. rw_spinlock_write_unlock(&network_viewer_opt.rw_spinlock);
  2405. parse_table_size_options(&socket_config);
  2406. ebpf_socket_initialize_global_vectors();
  2407. if (running_on_kernel < NETDATA_EBPF_KERNEL_5_0)
  2408. em->mode = MODE_ENTRY;
  2409. #ifdef LIBBPF_MAJOR_VERSION
  2410. ebpf_adjust_thread_load(em, default_btf);
  2411. #endif
  2412. if (ebpf_socket_load_bpf(em)) {
  2413. pthread_mutex_unlock(&lock);
  2414. goto endsocket;
  2415. }
  2416. int algorithms[NETDATA_MAX_SOCKET_VECTOR] = {
  2417. NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_ABSOLUTE_IDX,
  2418. NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_ABSOLUTE_IDX,
  2419. NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_ABSOLUTE_IDX, NETDATA_EBPF_INCREMENTAL_IDX,
  2420. NETDATA_EBPF_INCREMENTAL_IDX
  2421. };
  2422. ebpf_global_labels(
  2423. socket_aggregated_data, socket_publish_aggregated, socket_dimension_names, socket_id_names,
  2424. algorithms, NETDATA_MAX_SOCKET_VECTOR);
  2425. ebpf_read_socket.thread = mallocz(sizeof(netdata_thread_t));
  2426. netdata_thread_create(ebpf_read_socket.thread,
  2427. ebpf_read_socket.name,
  2428. NETDATA_THREAD_OPTION_DEFAULT,
  2429. ebpf_read_socket_thread,
  2430. em);
  2431. pthread_mutex_lock(&lock);
  2432. ebpf_socket_create_global_charts(em);
  2433. ebpf_update_stats(&plugin_statistics, em);
  2434. ebpf_update_kernel_memory_with_vector(&plugin_statistics, em->maps, EBPF_ACTION_STAT_ADD);
  2435. #ifdef NETDATA_DEV_MODE
  2436. if (ebpf_aral_socket_pid)
  2437. socket_disable_priority = ebpf_statistic_create_aral_chart(NETDATA_EBPF_SOCKET_ARAL_NAME, em);
  2438. #endif
  2439. pthread_mutex_unlock(&lock);
  2440. socket_collector(em);
  2441. endsocket:
  2442. ebpf_update_disabled_plugin_stats(em);
  2443. netdata_thread_cleanup_pop(1);
  2444. return NULL;
  2445. }