2 * SPDX-License-Identifier: BSD-3-Clause
4 * Copyright (c) 2013 Gleb Smirnoff <glebius@FreeBSD.org>
5 * Copyright (c) 1983, 1988, 1993
6 * The Regents of the University of California. All rights reserved.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
11 * 1. Redistributions of source code must retain the above copyright
12 * notice, this list of conditions and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the above copyright
14 * notice, this list of conditions and the following disclaimer in the
15 * documentation and/or other materials provided with the distribution.
16 * 3. Neither the name of the University nor the names of its contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
35 static char sccsid[] = "@(#)if.c 8.3 (Berkeley) 4/28/95";
39 #include <sys/cdefs.h>
40 #include <sys/param.h>
41 #include <sys/protosw.h>
42 #include <sys/socket.h>
43 #include <sys/socketvar.h>
47 #include <net/if_dl.h>
48 #include <net/if_types.h>
49 #include <net/ethernet.h>
50 #include <netinet/in.h>
51 #include <netinet/in_var.h>
52 #include <arpa/inet.h>
54 #include <net/pfvar.h>
55 #include <net/if_pfsync.h>
77 static void sidewaysintpr(void);
80 static const char* pfsyncacts[] = {
81 /* PFSYNC_ACT_CLR */ "clear all request",
82 /* PFSYNC_ACT_INS_1301 */ "13.1 state insert",
83 /* PFSYNC_ACT_INS_ACK */ "state inserted ack",
84 /* PFSYNC_ACT_UPD_1301 */ "13.1 state update",
85 /* PFSYNC_ACT_UPD_C */ "compressed state update",
86 /* PFSYNC_ACT_UPD_REQ */ "uncompressed state request",
87 /* PFSYNC_ACT_DEL */ "state delete",
88 /* PFSYNC_ACT_DEL_C */ "compressed state delete",
89 /* PFSYNC_ACT_INS_F */ "fragment insert",
90 /* PFSYNC_ACT_DEL_F */ "fragment delete",
91 /* PFSYNC_ACT_BUS */ "bulk update mark",
92 /* PFSYNC_ACT_TDB */ "TDB replay counter update",
93 /* PFSYNC_ACT_EOF */ "end of frame mark",
94 /* PFSYNC_ACT_INS_1400 */ "state insert",
95 /* PFSYNC_ACT_UPD_1400 */ "state update",
98 static const char* pfsyncacts_name[] = {
99 /* PFSYNC_ACT_CLR */ "clear-all-request",
100 /* PFSYNC_ACT_INS_1301 */ "state-insert-1301",
101 /* PFSYNC_ACT_INS_ACK */ "state-inserted-ack",
102 /* PFSYNC_ACT_UPD_1301 */ "state-update-1301",
103 /* PFSYNC_ACT_UPD_C */ "compressed-state-update",
104 /* PFSYNC_ACT_UPD_REQ */ "uncompressed-state-request",
105 /* PFSYNC_ACT_DEL */ "state-delete",
106 /* PFSYNC_ACT_DEL_C */ "compressed-state-delete",
107 /* PFSYNC_ACT_INS_F */ "fragment-insert",
108 /* PFSYNC_ACT_DEL_F */ "fragment-delete",
109 /* PFSYNC_ACT_BUS */ "bulk-update-mark",
110 /* PFSYNC_ACT_TDB */ "TDB-replay-counter-update",
111 /* PFSYNC_ACT_EOF */ "end-of-frame-mark",
112 /* PFSYNC_ACT_INS_1400 */ "state-insert",
113 /* PFSYNC_ACT_UPD_1400 */ "state-update",
117 pfsync_acts_stats(const char *list, const char *desc, uint64_t *a)
122 for (i = 0; i < PFSYNC_ACT_MAX; i++, a++) {
123 if (*a || sflag <= 1) {
124 xo_open_instance(list);
125 xo_emit("\t\t{e:name}{:count/%ju} {N:/%s%s %s}\n",
126 pfsyncacts_name[i], (uintmax_t)(*a),
127 pfsyncacts[i], plural(*a), desc);
128 xo_close_instance(list);
135 * Dump pfsync statistics structure.
138 pfsync_stats(u_long off, const char *name, int af1 __unused, int proto __unused)
140 struct pfsyncstats pfsyncstat;
142 if (fetch_stats("net.pfsync.stats", off, &pfsyncstat,
143 sizeof(pfsyncstat), kread) != 0)
146 xo_emit("{T:/%s}:\n", name);
147 xo_open_container(name);
149 #define p(f, m) if (pfsyncstat.f || sflag <= 1) \
150 xo_emit(m, (uintmax_t)pfsyncstat.f, plural(pfsyncstat.f))
152 p(pfsyncs_ipackets, "\t{:received-inet-packets/%ju} "
153 "{N:/packet%s received (IPv4)}\n");
154 p(pfsyncs_ipackets6, "\t{:received-inet6-packets/%ju} "
155 "{N:/packet%s received (IPv6)}\n");
156 pfsync_acts_stats("input-histogram", "received",
157 &pfsyncstat.pfsyncs_iacts[0]);
158 p(pfsyncs_badif, "\t\t{:dropped-bad-interface/%ju} "
159 "{N:/packet%s discarded for bad interface}\n");
160 p(pfsyncs_badttl, "\t\t{:dropped-bad-ttl/%ju} "
161 "{N:/packet%s discarded for bad ttl}\n");
162 p(pfsyncs_hdrops, "\t\t{:dropped-short-header/%ju} "
163 "{N:/packet%s shorter than header}\n");
164 p(pfsyncs_badver, "\t\t{:dropped-bad-version/%ju} "
165 "{N:/packet%s discarded for bad version}\n");
166 p(pfsyncs_badauth, "\t\t{:dropped-bad-auth/%ju} "
167 "{N:/packet%s discarded for bad HMAC}\n");
168 p(pfsyncs_badact,"\t\t{:dropped-bad-action/%ju} "
169 "{N:/packet%s discarded for bad action}\n");
170 p(pfsyncs_badlen, "\t\t{:dropped-short/%ju} "
171 "{N:/packet%s discarded for short packet}\n");
172 p(pfsyncs_badval, "\t\t{:dropped-bad-values/%ju} "
173 "{N:/state%s discarded for bad values}\n");
174 p(pfsyncs_stale, "\t\t{:dropped-stale-state/%ju} "
175 "{N:/stale state%s}\n");
176 p(pfsyncs_badstate, "\t\t{:dropped-failed-lookup/%ju} "
177 "{N:/failed state lookup\\/insert%s}\n");
178 p(pfsyncs_opackets, "\t{:sent-inet-packets/%ju} "
179 "{N:/packet%s sent (IPv4})\n");
180 p(pfsyncs_opackets6, "\t{:send-inet6-packets/%ju} "
181 "{N:/packet%s sent (IPv6})\n");
182 pfsync_acts_stats("output-histogram", "sent",
183 &pfsyncstat.pfsyncs_oacts[0]);
184 p(pfsyncs_onomem, "\t\t{:discarded-no-memory/%ju} "
185 "{N:/failure%s due to mbuf memory error}\n");
186 p(pfsyncs_oerrors, "\t\t{:send-errors/%ju} "
187 "{N:/send error%s}\n");
189 xo_close_container(name);
194 * Display a formatted value, or a '-' in the same space.
197 show_stat(const char *fmt, int width, const char *name,
198 u_long value, short showvalue, int div1000)
200 const char *lsep, *rsep;
204 if (strncmp(fmt, "LS", 2) == 0) {
209 if (strncmp(fmt, "NRS", 3) == 0) {
213 if (showvalue == 0) {
214 /* Print just dash. */
215 xo_emit("{P:/%s}{D:/%*s}{P:/%s}", lsep, width, "-", rsep);
220 * XXX: workaround {P:} modifier can't be empty and doesn't seem to
221 * take args... so we need to conditionally include it in the format.
223 #define maybe_pad(pad) do { \
225 snprintf(newfmt, sizeof(newfmt), "{P:%s}", pad); \
233 /* Format in human readable form. */
234 humanize_number(buf, sizeof(buf), (int64_t)value, "",
235 HN_AUTOSCALE, HN_NOSPACE | HN_DECIMAL | \
236 ((div1000) ? HN_DIVISOR_1000 : 0));
238 snprintf(newfmt, sizeof(newfmt), "{:%s/%%%ds}", name, width);
239 xo_emit(newfmt, buf);
242 /* Construct the format string. */
244 snprintf(newfmt, sizeof(newfmt), "{:%s/%%%d%s}",
246 xo_emit(newfmt, value);
252 * Find next multiaddr for a given interface name.
254 static struct ifmaddrs *
255 next_ifma(struct ifmaddrs *ifma, const char *name, const sa_family_t family)
258 for(; ifma != NULL; ifma = ifma->ifma_next) {
259 struct sockaddr_dl *sdl;
261 sdl = (struct sockaddr_dl *)ifma->ifma_name;
262 if (ifma->ifma_addr->sa_family == family &&
263 strcmp(sdl->sdl_data, name) == 0)
270 enum process_op { MEASURE, EMIT };
273 process_ifa_addr(enum process_op op, struct ifaddrs *ifa, int *max_net_len,
274 int *max_addr_len, bool *network, bool *link)
276 int net_len, addr_len;
280 net_len = *max_net_len;
281 addr_len = *max_addr_len;
284 switch (ifa->ifa_addr->sa_family) {
287 net_len = strlen("none");
288 addr_len = strlen("none");
290 xo_emit("{:network/%-*.*s} ", net_len, net_len,
292 xo_emit("{:address/%-*.*s} ", addr_len, addr_len,
300 nn = netname(ifa->ifa_addr, ifa->ifa_netmask);
301 rn = routename(ifa->ifa_addr, numeric_addr);
303 net_len = strlen(nn);
304 addr_len = strlen(rn);
306 xo_emit("{t:network/%-*s} ", net_len, nn);
307 xo_emit("{t:address/%-*s} ", addr_len, rn);
315 struct sockaddr_dl *sdl;
316 char linknum[sizeof("<Link#32767>")];
318 sdl = (struct sockaddr_dl *)ifa->ifa_addr;
319 snprintf(linknum, sizeof(linknum), "<Link#%d>", sdl->sdl_index);
321 net_len = strlen(linknum);
322 if (sdl->sdl_nlen == 0 &&
323 sdl->sdl_alen == 0 &&
327 addr_len = strlen(routename(ifa->ifa_addr, 1));
329 xo_emit("{t:network/%-*.*s} ", net_len, net_len,
331 if (sdl->sdl_nlen == 0 &&
332 sdl->sdl_alen == 0 &&
334 xo_emit("{P:/%*s} ", addr_len, "");
336 xo_emit("{t:address/%-*.*s} ", addr_len,
337 addr_len, routename(ifa->ifa_addr, 1));
346 if (net_len > *max_net_len)
347 *max_net_len = net_len;
348 if (addr_len > *max_addr_len)
349 *max_addr_len = addr_len;
354 max_num_len(int max_len, u_long num)
356 int len = 2; /* include space */
358 for (; num > 10; len++)
360 return (MAX(max_len, len));
364 * Print a description of the network interfaces.
367 intpr(void (*pfunc)(char *), int af)
369 struct ifaddrs *ifap, *ifa;
370 struct ifmaddrs *ifmap, *ifma;
371 u_int ifn_len_max = 5, ifn_len;
372 u_int net_len = strlen("Network "), addr_len = strlen("Address ");
373 u_int npkt_len = 8, nbyte_len = 10, nerr_len = 5;
376 return sidewaysintpr();
378 if (getifaddrs(&ifap) != 0)
379 err(EX_OSERR, "getifaddrs");
380 if (aflag && getifmaddrs(&ifmap) != 0)
381 err(EX_OSERR, "getifmaddrs");
383 for (ifa = ifap; ifa; ifa = ifa->ifa_next) {
384 if (interface != NULL &&
385 strcmp(ifa->ifa_name, interface) != 0)
387 if (af != AF_UNSPEC && ifa->ifa_addr->sa_family != af)
389 ifn_len = strlen(ifa->ifa_name);
390 if ((ifa->ifa_flags & IFF_UP) == 0)
392 ifn_len_max = MAX(ifn_len_max, ifn_len);
393 process_ifa_addr(MEASURE, ifa, &net_len, &addr_len,
396 #define IFA_STAT(s) (((struct if_data *)ifa->ifa_data)->ifi_ ## s)
398 npkt_len = max_num_len(npkt_len, IFA_STAT(ipackets));
399 npkt_len = max_num_len(npkt_len, IFA_STAT(opackets));
400 nerr_len = max_num_len(nerr_len, IFA_STAT(ierrors));
401 nerr_len = max_num_len(nerr_len, IFA_STAT(iqdrops));
402 nerr_len = max_num_len(nerr_len, IFA_STAT(collisions));
404 nerr_len = max_num_len(nerr_len,
407 nbyte_len = max_num_len(nbyte_len,
409 nbyte_len = max_num_len(nbyte_len,
415 xo_open_list("interface");
417 xo_emit("{T:/%-*.*s}", ifn_len_max, ifn_len_max, "Name");
418 xo_emit(" {T:/%5.5s} {T:/%-*.*s} {T:/%-*.*s} {T:/%*.*s} "
419 "{T:/%*.*s} {T:/%*.*s}",
420 "Mtu", net_len, net_len, "Network", addr_len, addr_len,
421 "Address", npkt_len, npkt_len, "Ipkts",
422 nerr_len, nerr_len, "Ierrs", nerr_len, nerr_len, "Idrop");
424 xo_emit(" {T:/%*.*s}", nbyte_len, nbyte_len, "Ibytes");
425 xo_emit(" {T:/%*.*s} {T:/%*.*s}", npkt_len, npkt_len, "Opkts",
426 nerr_len, nerr_len, "Oerrs");
428 xo_emit(" {T:/%*.*s}", nbyte_len, nbyte_len, "Obytes");
429 xo_emit(" {T:/%*s}", nerr_len, "Coll");
431 xo_emit(" {T:/%*.*s}", nerr_len, nerr_len, "Drop");
435 for (ifa = ifap; ifa; ifa = ifa->ifa_next) {
436 bool network = false, link = false;
437 char *name, *xname, buf[IFNAMSIZ+1];
439 if (interface != NULL && strcmp(ifa->ifa_name, interface) != 0)
442 name = ifa->ifa_name;
449 * Skip all ifaddrs belonging to same interface.
451 while(ifa->ifa_next != NULL &&
452 (strcmp(ifa->ifa_next->ifa_name, name) == 0)) {
458 if (af != AF_UNSPEC && ifa->ifa_addr->sa_family != af)
461 xo_open_instance("interface");
463 if ((ifa->ifa_flags & IFF_UP) == 0) {
464 xname = stpcpy(buf, name);
471 xo_emit("{d:/%-*.*s}{etk:name}{eq:flags/0x%x}",
472 ifn_len_max, ifn_len_max, xname, name, ifa->ifa_flags);
474 #define IFA_MTU(ifa) (((struct if_data *)(ifa)->ifa_data)->ifi_mtu)
475 show_stat("lu", 6, "mtu", IFA_MTU(ifa), IFA_MTU(ifa), 0);
478 process_ifa_addr(EMIT, ifa, &net_len, &addr_len,
481 show_stat("lu", npkt_len, "received-packets",
482 IFA_STAT(ipackets), link|network, 1);
483 show_stat("lu", nerr_len, "received-errors", IFA_STAT(ierrors),
485 show_stat("lu", nerr_len, "dropped-packets", IFA_STAT(iqdrops),
488 show_stat("lu", nbyte_len, "received-bytes",
489 IFA_STAT(ibytes), link|network, 0);
490 show_stat("lu", npkt_len, "sent-packets", IFA_STAT(opackets),
492 show_stat("lu", nerr_len, "send-errors", IFA_STAT(oerrors),
495 show_stat("lu", nbyte_len, "sent-bytes",
496 IFA_STAT(obytes), link|network, 0);
497 show_stat("NRSlu", nerr_len, "collisions", IFA_STAT(collisions),
500 show_stat("LSlu", nerr_len, "dropped-packets",
501 IFA_STAT(oqdrops), link, 1);
505 xo_close_instance("interface");
510 * Print family's multicast addresses.
512 xo_open_list("multicast-address");
513 for (ifma = next_ifma(ifmap, ifa->ifa_name,
514 ifa->ifa_addr->sa_family);
516 ifma = next_ifma(ifma, ifa->ifa_name,
517 ifa->ifa_addr->sa_family)) {
518 const char *fmt = NULL;
520 xo_open_instance("multicast-address");
521 switch (ifma->ifma_addr->sa_family) {
524 struct sockaddr_dl *sdl;
526 sdl = (struct sockaddr_dl *)ifma->ifma_addr;
527 if (sdl->sdl_type != IFT_ETHER &&
528 sdl->sdl_type != IFT_FDDI)
536 fmt = routename(ifma->ifma_addr, numeric_addr);
542 "{t:address/%-17s/}", "", fmt);
545 "{t:address/%-17.17s/}", "", fmt);
546 if (ifma->ifma_addr->sa_family == AF_LINK) {
547 xo_emit(" {:received-packets/%8lu}",
549 xo_emit("{P:/%*s}", bflag? 17 : 6, "");
550 xo_emit(" {:sent-packets/%8lu}",
555 xo_close_instance("multicast-address");
556 ifma = ifma->ifma_next;
558 xo_close_list("multicast-address");
559 xo_close_instance("interface");
561 xo_close_list("interface");
569 u_long ift_ip; /* input packets */
570 u_long ift_ie; /* input errors */
571 u_long ift_id; /* input drops */
572 u_long ift_op; /* output packets */
573 u_long ift_oe; /* output errors */
574 u_long ift_od; /* output drops */
575 u_long ift_co; /* collisions */
576 u_long ift_ib; /* input bytes */
577 u_long ift_ob; /* output bytes */
581 * Obtain stats for interface(s).
584 fill_iftot(struct iftot *st)
586 struct ifaddrs *ifap, *ifa;
589 if (getifaddrs(&ifap) != 0)
590 xo_err(EX_OSERR, "getifaddrs");
592 bzero(st, sizeof(*st));
594 for (ifa = ifap; ifa; ifa = ifa->ifa_next) {
595 if (ifa->ifa_addr->sa_family != AF_LINK)
598 if (strcmp(ifa->ifa_name, interface) == 0)
604 st->ift_ip += IFA_STAT(ipackets);
605 st->ift_ie += IFA_STAT(ierrors);
606 st->ift_id += IFA_STAT(iqdrops);
607 st->ift_ib += IFA_STAT(ibytes);
608 st->ift_op += IFA_STAT(opackets);
609 st->ift_oe += IFA_STAT(oerrors);
610 st->ift_od += IFA_STAT(oqdrops);
611 st->ift_ob += IFA_STAT(obytes);
612 st->ift_co += IFA_STAT(collisions);
615 if (interface && found == false)
616 xo_err(EX_DATAERR, "interface %s not found", interface);
622 * Set a flag to indicate that a signal from the periodic itimer has been
625 static sig_atomic_t signalled;
627 catchalarm(int signo __unused)
633 * Print a running summary of interface statistics.
634 * Repeat display every interval seconds, showing statistics
635 * collected over that interval. Assumes that interval is non-zero.
636 * First line printed at top of screen is always cumulative.
641 struct iftot ift[2], *new, *old;
642 struct itimerval interval_it;
649 (void)signal(SIGALRM, catchalarm);
651 interval_it.it_interval.tv_sec = interval;
652 interval_it.it_interval.tv_usec = 0;
653 interval_it.it_value = interval_it.it_interval;
654 setitimer(ITIMER_REAL, &interval_it, NULL);
655 xo_open_list("interface-statistics");
658 xo_emit("{T:/%17s} {T:/%14s} {T:/%16s}\n", "input",
659 interface != NULL ? interface : "(Total)", "output");
660 xo_emit("{T:/%10s} {T:/%5s} {T:/%5s} {T:/%10s} {T:/%10s} {T:/%5s} "
661 "{T:/%10s} {T:/%5s}",
662 "packets", "errs", "idrops", "bytes", "packets", "errs", "bytes",
665 xo_emit(" {T:/%5.5s}", "drops");
671 if ((noutputs != 0) && (--noutputs == 0)) {
672 xo_close_list("interface-statistics");
675 oldmask = sigblock(sigmask(SIGALRM));
684 xo_open_instance("stats");
685 show_stat("lu", 10, "received-packets",
686 new->ift_ip - old->ift_ip, 1, 1);
687 show_stat("lu", 5, "received-errors",
688 new->ift_ie - old->ift_ie, 1, 1);
689 show_stat("lu", 5, "dropped-packets",
690 new->ift_id - old->ift_id, 1, 1);
691 show_stat("lu", 10, "received-bytes",
692 new->ift_ib - old->ift_ib, 1, 0);
693 show_stat("lu", 10, "sent-packets",
694 new->ift_op - old->ift_op, 1, 1);
695 show_stat("lu", 5, "send-errors",
696 new->ift_oe - old->ift_oe, 1, 1);
697 show_stat("lu", 10, "sent-bytes",
698 new->ift_ob - old->ift_ob, 1, 0);
699 show_stat("NRSlu", 5, "collisions",
700 new->ift_co - old->ift_co, 1, 1);
702 show_stat("LSlu", 5, "dropped-packets",
703 new->ift_od - old->ift_od, 1, 1);
704 xo_close_instance("stats");
708 if (new == &ift[0]) {