brintos

brintos / linux-shallow public Read only

0
0
Text · 6.3 KiB · a9ed899 Raw
203 lines · plain
1.. SPDX-License-Identifier: (GPL-2.0-only OR BSD-2-Clause)2 3================4bpftool-net5================6-------------------------------------------------------------------------------7tool for inspection of networking related bpf prog attachments8-------------------------------------------------------------------------------9 10:Manual section: 811 12.. include:: substitutions.rst13 14SYNOPSIS15========16 17**bpftool** [*OPTIONS*] **net** *COMMAND*18 19*OPTIONS* := { |COMMON_OPTIONS| }20 21*COMMANDS* := { **show** | **list** | **attach** | **detach** | **help** }22 23NET COMMANDS24============25 26| **bpftool** **net** { **show** | **list** } [ **dev** *NAME* ]27| **bpftool** **net attach** *ATTACH_TYPE* *PROG* **dev** *NAME* [ **overwrite** ]28| **bpftool** **net detach** *ATTACH_TYPE* **dev** *NAME*29| **bpftool** **net help**30|31| *PROG* := { **id** *PROG_ID* | **pinned** *FILE* | **tag** *PROG_TAG* | **name** *PROG_NAME* }32| *ATTACH_TYPE* := { **xdp** | **xdpgeneric** | **xdpdrv** | **xdpoffload** | **tcx_ingress** | **tcx_egress** }33 34DESCRIPTION35===========36bpftool net { show | list } [ dev *NAME* ]37    List bpf program attachments in the kernel networking subsystem.38 39    Currently, device driver xdp attachments, tcx, netkit and old-style tc40    classifier/action attachments, flow_dissector as well as netfilter41    attachments are implemented, i.e., for program types **BPF_PROG_TYPE_XDP**,42    **BPF_PROG_TYPE_SCHED_CLS**, **BPF_PROG_TYPE_SCHED_ACT**,43    **BPF_PROG_TYPE_FLOW_DISSECTOR**, **BPF_PROG_TYPE_NETFILTER**.44 45    For programs attached to a particular cgroup, e.g.,46    **BPF_PROG_TYPE_CGROUP_SKB**, **BPF_PROG_TYPE_CGROUP_SOCK**,47    **BPF_PROG_TYPE_SOCK_OPS** and **BPF_PROG_TYPE_CGROUP_SOCK_ADDR**, users48    can use **bpftool cgroup** to dump cgroup attachments. For sk_{filter, skb,49    msg, reuseport} and lwt/seg6 bpf programs, users should consult other50    tools, e.g., iproute2.51 52    The current output will start with all xdp program attachments, followed by53    all tcx, netkit, then tc class/qdisc bpf program attachments, then54    flow_dissector and finally netfilter programs. Both xdp programs and55    tcx/netkit/tc programs are ordered based on ifindex number. If multiple bpf56    programs attached to the same networking device through **tc**, the order57    will be first all bpf programs attached to tcx, netkit, then tc classes,58    then all bpf programs attached to non clsact qdiscs, and finally all bpf59    programs attached to root and clsact qdisc.60 61bpftool net attach *ATTACH_TYPE* *PROG* dev *NAME* [ overwrite ]62    Attach bpf program *PROG* to network interface *NAME* with type specified63    by *ATTACH_TYPE*. Previously attached bpf program can be replaced by the64    command used with **overwrite** option. Currently, only XDP-related modes65    are supported for *ATTACH_TYPE*.66 67    *ATTACH_TYPE* can be of:68    **xdp** - try native XDP and fallback to generic XDP if NIC driver does not support it;69    **xdpgeneric** - Generic XDP. runs at generic XDP hook when packet already enters receive path as skb;70    **xdpdrv** - Native XDP. runs earliest point in driver's receive path;71    **xdpoffload** - Offload XDP. runs directly on NIC on each packet reception;72    **tcx_ingress** - Ingress TCX. runs on ingress net traffic;73    **tcx_egress** - Egress TCX. runs on egress net traffic;74 75bpftool net detach *ATTACH_TYPE* dev *NAME*76    Detach bpf program attached to network interface *NAME* with type specified77    by *ATTACH_TYPE*. To detach bpf program, same *ATTACH_TYPE* previously used78    for attach must be specified. Currently, only XDP-related modes are79    supported for *ATTACH_TYPE*.80 81bpftool net help82    Print short help message.83 84OPTIONS85=======86.. include:: common_options.rst87 88EXAMPLES89========90 91| **# bpftool net**92 93::94 95      xdp:96      eth0(2) driver id 19897 98      tc:99      eth0(2) htb name prefix_matcher.o:[cls_prefix_matcher_htb] id 111727 act []100      eth0(2) clsact/ingress fbflow_icmp id 130246 act []101      eth0(2) clsact/egress prefix_matcher.o:[cls_prefix_matcher_clsact] id 111726102      eth0(2) clsact/egress cls_fg_dscp id 108619 act []103      eth0(2) clsact/egress fbflow_egress id 130245104 105|106| **# bpftool -jp net**107 108::109 110    [{111            "xdp": [{112                    "devname": "eth0",113                    "ifindex": 2,114                    "mode": "driver",115                    "id": 198116                }117            ],118            "tc": [{119                    "devname": "eth0",120                    "ifindex": 2,121                    "kind": "htb",122                    "name": "prefix_matcher.o:[cls_prefix_matcher_htb]",123                    "id": 111727,124                    "act": []125                },{126                    "devname": "eth0",127                    "ifindex": 2,128                    "kind": "clsact/ingress",129                    "name": "fbflow_icmp",130                    "id": 130246,131                    "act": []132                },{133                    "devname": "eth0",134                    "ifindex": 2,135                    "kind": "clsact/egress",136                    "name": "prefix_matcher.o:[cls_prefix_matcher_clsact]",137                    "id": 111726,138                },{139                    "devname": "eth0",140                    "ifindex": 2,141                    "kind": "clsact/egress",142                    "name": "cls_fg_dscp",143                    "id": 108619,144                    "act": []145                },{146                    "devname": "eth0",147                    "ifindex": 2,148                    "kind": "clsact/egress",149                    "name": "fbflow_egress",150                    "id": 130245,151                }152            ]153        }154    ]155 156|157| **# bpftool net attach xdpdrv id 16 dev enp6s0np0**158| **# bpftool net**159 160::161 162      xdp:163      enp6s0np0(4) driver id 16164 165|166| **# bpftool net attach xdpdrv id 16 dev enp6s0np0**167| **# bpftool net attach xdpdrv id 20 dev enp6s0np0 overwrite**168| **# bpftool net**169 170::171 172      xdp:173      enp6s0np0(4) driver id 20174 175|176| **# bpftool net attach xdpdrv id 16 dev enp6s0np0**177| **# bpftool net detach xdpdrv dev enp6s0np0**178| **# bpftool net**179 180::181 182      xdp:183 184|185| **# bpftool net attach tcx_ingress name tc_prog dev lo**186| **# bpftool net**187|188 189::190 191      tc:192      lo(1) tcx/ingress tc_prog prog_id 29193 194|195| **# bpftool net attach tcx_ingress name tc_prog dev lo**196| **# bpftool net detach tcx_ingress dev lo**197| **# bpftool net**198|199 200::201 202      tc:203