Linux network protocol stack-based tc packet loss analysis method

By defining and analyzing the function return value of the tc rule in the Linux kernel, writing a monitoring program to output a packet loss stack, solving the packet loss problem caused by the tc rule in the existing technology, and implementing a method to quickly locate and solve the packet loss problem.

CN120034462AInactive Publication Date: 2025-05-23KYLIN CORP

Patent Information

Application Number
CN202510481873.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-23
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art lacks intuitive and fast methods to determine and deal with packet loss caused by TC rules in the Linux kernel.

Method used

Provide a tc packet loss analysis method based on the Linux network protocol stack. By defining the action meaning of the return value of the tcf_classify function and the reason for the return value of the kfree_skb function, a monitoring program is written to obtain and analyze this information and output the packet loss stack.

Benefits of technology

It quickly determines the causes of packet loss caused by TC rules, and improves the stability and management efficiency of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034462A_ABST
    Figure CN120034462A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network transmission, and particularly provides a tc packet loss analysis method based on a linux network protocol stack, which comprises the following steps: S1, defining an action meaning corresponding to a tcfclass function return value in a linux kernel, and defining a packet loss reason corresponding to a kfreeskb function return value; s2, a monitoring program is written in a user space, and a tcfclassfy function and a kfreeskb function in a linux kernel are monitored; s3, in a monitoring program, obtaining corresponding context stack information according to a bpfgetstackid function by using a parameter ctx, and storing the corresponding context stack information in a corresponding skb through a hash table; and S4, in the monitoring program, outputting a packet loss stack by obtaining a function return value and combining the context stack information. According to the scheme, whether packet loss is caused by the tc rule or not and the reason of the packet loss can be quickly determined.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the technical field of network transmission, and specifically provides a tc packet loss analysis method based on a linux network protocol stack. Background Art

[0002] In many network usage scenarios today, packet loss is a common problem in network transmission. Currently, various rules may cause network packet loss, such as xdp, tc, netfilter, etc. How to quickly determine the cause of network packet loss is very important.

[0003] Traffic Control (tc) is a tool in the Linux kernel for controlling and managing network traffic. It allows users to define and manipulate network traffic policies to achieve QoS (Quality of Service) management. tc is widely used in scenarios such as network traffic management, bandwidth allocation, priority control, and delay guarantee. Administrators can flexibly configure network policies through tc to meet the needs of different businesses. Currently, there is a lack of intuitive and fast processing methods for tc packet loss problems in the Linux kernel.

[0004] Accordingly, there is a need in the art for a method that can quickly determine whether packet loss is caused by tc rules and the cause of the packet loss. Summary of the invention

[0005] In order to overcome the above defects, the present invention provides a tc packet loss analysis method based on the linux network protocol stack, comprising the following steps: S1: Define the action meaning corresponding to the return value of the tcf_classify function in the Linux kernel, and define the packet loss reason corresponding to the return value of the kfree_skb function; S2: Write a monitoring program in the user space to monitor the tcf_classify function and kfree_skb function in the Linux kernel. When packet loss occurs, obtain the return value of the tcf_classify function and the kfree_skb function, and upload the data to the monitoring program after processing. S3: In the monitoring program, use the parameter ctx to obtain the corresponding context stack information according to the bpf_get_stackid function, and store the context stack information and the source address, source port, destination address and destination port of the packet into the corresponding skb through the hash table; S4: In the monitoring program, by obtaining the return value of the tcf_classify function and the return value of the kfree_skb function, refer to the definition in S1 to obtain the packet loss reason, combine the context stack information to output the packet loss stack, store and print it.

[0006] Furthermore, the definition of the tcf_classify function and the kfree_skb function can be implemented by macro definition or enumeration variable definition.

[0007] Furthermore, the action meanings corresponding to the return value of the tcf_classify function are defined as follows: When the return value of the tcf_classify function is TC_ACT_UNSPEC, the action means that the default configuration action should be taken; When the tcf_classify function returns TC_ACT_OK, the action means that the data packet should continue; When the tcf_classify function returns TC_ACT_RECLASSIFY, the action means that the packet must be reclassified from the root queuing discipline; When the return value of the tcf_classify function is TC_ACT_SHOT, the action means that the data packet is discarded and no other tc processing should be performed; When the tcf_classify function returns TC_ACT_PIPE, the action means that the packet should be passed to the next filter chain or action for processing; When the return value of the tcf_classify function is TC_ACT_STOLEN, the action means that the data packet has been processed by a certain action; When the tcf_classify function returns TC_ACT_QUEUED, the action means that the packet should be queued for subsequent processing; When the tcf_classify function returns TC_ACT_REPEAT, the action means that the same filter chain or action should be re-executed on the packet; When the tcf_classify function returns TC_ACT_REDIRECT, the action means that the packet should be redirected; When the tcf_classify function returns TC_ACT_TRAP, the action means that the packet should be captured.

[0008] Furthermore, the action meanings corresponding to the tcf_classify function return values ​​of TC_ACT_SHOT, TC_ACT_STOLEN, TC_ACT_QUEUED and TC_ACT_TRAP will result in packet loss, while the action meanings corresponding to the tcf_classify function return values ​​of TC_ACT_UNSPEC, TC_ACT_OK, TC_ACT_RECLASSIFY, TC_ACT_PIPE, TC_ACT_REPEAT and TC_ACT_REDIRECT will not result in packet loss.

[0009] Furthermore, the return value of the kfree_skb function represents the specific packet loss reason corresponding to the return value of the tcf_classify function as TC_ACT_SHOT. The packet loss reasons corresponding to the return value of the kfree_skb function are defined as follows: When the return value of the kfree_skb function is TC_EGRESS, the packet loss is caused by egress packet loss; When the kfree_skb function returns QDISC_DROP, the packet loss is caused by queue discipline. When the return value of the kfree_skb function is TC_INGRESS, the packet loss is caused by ingress packet loss; When the kfree_skb function returns TC_COOKIE_ERROR, the packet loss is caused by an error in processing the tc ext cookie. When the kfree_skb function returns TC_CHAIN_NOTFOUND, the packet loss is caused by the failure of tc chain search; When the kfree_skb function returns TC_RECLASSIFY_LOOP, the packet loss is caused by tc exceeding the maximum number of reclassification loop iterations.

[0010] Furthermore, in the Linux kernel, based on the eBPF technology, the kprobe method is used to mount the hook function for the tcf_classify function, and the tracepoint method is used to mount the hook function for the kfree_skb function.

[0011] Working principle and beneficial effects of the present invention: In the technical solution of the present invention, for the packet loss problem in tc rules or tc ebpf programs, in the Linux kernel network protocol stack, the function return value result of tc processing data packets is obtained, and the relevant meaning is defined to illustrate the result of tc execution, and the packet loss reason of the function that processes the packet loss action is further obtained. At the same time, the code is written using ebpf technology to monitor the Linux kernel tc function for processing data packets and the kernel network protocol stack function for processing packet loss reasons. When packet loss occurs, the monitoring program extracts and collects the current information, and saves and outputs it. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The disclosure of the present invention will become more easily understood with reference to the accompanying drawings. It is easy for those skilled in the art to understand that these drawings are only for illustrative purposes and are not intended to limit the scope of protection of the present invention. Among them: Figure 1 This is a schematic flow chart of the main steps of a tc packet loss analysis method based on a linux network protocol stack in the present invention; Figure 2 The invention discloses a linux kernel processing flow chart of a tc packet loss analysis method based on a linux network protocol stack. DETAILED DESCRIPTION

[0013] Some embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the protection scope of the present invention.

[0014] Figure 1 This is a schematic flow chart of the main steps of a tc packet loss analysis method based on the Linux network protocol stack of the present invention. Figure 1 As shown, a tc packet loss analysis method based on the Linux network protocol stack in this embodiment mainly includes the following steps S1 to S4.

[0015] S1: Define the action meaning corresponding to the return value of the tcf_classify function in the Linux kernel, and define the packet loss reason corresponding to the return value of the kfree_skb function.

[0016] In one implementation, the redefinition of the tcf_classify function and the kfree_skb function can be implemented by macro definition or enumeration variable definition. The macro definition and the enumeration constant are just different in code writing. When implemented by macro definition, the return value is the macro definition value, and when implemented by enumeration variable definition, the return value is the enumeration value. Redefine the corresponding return value according to the relevant macro definition defined in the kernel pkt_cls.h, and define the relevant action meaning and packet loss reason. After the corresponding action occurs, its return value corresponds to this action.

[0017] In this embodiment, the functions related to the packet loss action of the Linux kernel network protocol stack tc are tcf_classify and kfree_skb. The tcf_classify function is used to classify the incoming data packets according to preset rules. It allows the administrator to define complex traffic control policies and process the data packets according to these policies, such as speed limiting, redirection, and discarding. The kfree_skb function is a function in the Linux kernel for releasing a sk_buff structure and contains the reason for the packet loss.

[0018] In one implementation, the action meaning corresponding to the return value of the tcf_classify function is defined to specifically include the content of Table 1.

[0019] Table 1

[0020] The actions corresponding to the return values ​​of the tcf_classify function TC_ACT_SHOT, TC_ACT_STOLEN, TC_ACT_QUEUED, and TC_ACT_TRAP will result in packet loss, while the actions corresponding to other return values ​​will not result in packet loss.

[0021] In one implementation, the packet loss reason corresponding to the return value of the kfree_skb function is defined to specifically include the content of Table 2.

[0022] Table 2

[0023] In this embodiment, the return value of the kfree_skb function represents the specific packet loss reason corresponding to the return value of the tcf_classify function is TC_ACT_SHOT.

[0024] TC_ACT_STOLEN, TC_ACT_QUEUED and TC_ACT_TRAP will release skb through consume_skb, pretending that the transmission is successful. TC_ACT_SHOT is similar to it, and will also notify the kernel to discard the message, but it is released through kfree_skb. Therefore, for the packet loss of skb released through consume_skb, the return value of tcf_classify function is obtained and uploaded to the monitoring program for parsing the meaning of the action. For the packet loss released by kfree_skb, that is, when the return value of tcf_classify function is TC_ACT_SHOT, the return value of kfree_skb function can be further obtained and uploaded to the monitoring program for parsing the specific cause of the packet loss.

[0025] The kernel will release skb through consume_skb and kfree_skb. consume_skb represents normal release, such as the release of the data packet after being received and used normally, while kfree_skb represents abnormal release, such as the release of the data packet due to firewall rules. The action TC_ACT_SHOT notifies the kernel to discard the packet. TC_ACT_SHOT and TC_ACT_STOLEN are essentially similar, with only some differences: TC_ACT_SHOT will notify the kernel to release skb through kfree_skb; while TC_ACT_STOLEN will release skb through consume_skb, pretending that the transmission was successful. General discard monitoring will record the operation of kfree_skb, so it will not record any packets discarded due to TC_ACT_STOLEN, because semantically, these skbs are consumed or queued instead of discarded. Therefore, every time packet loss occurs, the action meaning of packet loss is obtained through the return value of tcf_classify function (Table 1). The TC_ACT_SHOT action can obtain more specific reasons for packet loss through kfree_skb function (Table 2), and the action meanings corresponding to the three return values ​​of TC_ACT_STOLEN, TC_ACT_QUEUED and TC_ACT_TRAP are actually the reasons for packet loss.

[0026] Figure 2 The present invention is a linux kernel processing flow chart of a tc packet loss analysis method based on a linux network protocol stack, such as Figure 2 As shown, the tcf_classify function is first used to determine whether the skb is released (i.e., whether the packet is lost). If there is no packet loss, the return value of the tcf_classify function is TC_ACT_UNSPEC, TC_ACT_OK, TC_ACT_RECLASSIFY, TC_ACT_PIPE, TC_ACT_REPEAT, TC_ACT_REDIRECT. If packet loss occurs, the return value of the tcf_classify function is TC_ACT_SHOT, TC_ACT_STOLEN, TC_ACT_QUEUED, TC_ACT_TRAP.

[0027] Furthermore, when the return value of the tcf_classify function is TC_ACT_SHOT, the skb is released through kfree_skb, and the return value of the kfree_skb function is further obtained to determine the specific cause of packet loss. When the return value of the tcf_classify function is TC_ACT_STOLEN, TC_ACT_QUEUED, or TC_ACT_TRAP, the skb is released through consume_skb and the process ends directly.

[0028] S2: Write a monitoring program in user space to monitor the tcf_classify function of tc in the Linux kernel to process data packets and the kfree_skb function of the kernel network protocol stack to process packet loss. When packet loss occurs, get the return value of the tcf_classify function and the return value of the kfree_skb function. After data processing, upload it to the monitoring program through ringbuf.

[0029] In one implementation, based on the eBPF technology, the function tcf_classify that processes kernel data packet actions uses the kprobe method to mount a hook function, and the function kfree_skb that processes kernel packet loss causes uses the tracepoint method to mount a hook function. The hook function refers to a custom function that is hooked to this kernel function, that is, after the kernel executes the kfree_skb function, it will also execute the hook function that is hooked to it.

[0030] After receiving the data uploaded by the Linux kernel, the monitoring program obtains the return values ​​of the two functions, and finds the corresponding information according to the packet loss cause troubleshooting information defined in S1. For example, when the return value of the tcf_classify function is TC_ACT_SHOT and the return value of the kfree_skb function is TC_EGRESS, it means that the packet is lost at the TC exit, and the corresponding troubleshooting information is to check the TC exit rules.

[0031] S3: Add detailed information about the reasons for packet loss in the monitoring program, and add possible reasons for this problem based on the packet loss results.

[0032] In one implementation, the parameter ctx is used to obtain the function context stack with the help of the bpf_get_stackid function, and the corresponding context stack information is obtained according to the bpf_get_stackid function. The context stack information and the source address, source port, destination address and destination port of the packet are stored in the corresponding skb through a hash table. The skb is used to obtain connection information. This information is passed from the kernel space (Linux kernel) to the user space (monitoring program) through RINGBUF to achieve output and storage.

[0033] Among them, ctx is the default parameter of the hook function, and the bpf_get_stackid function is a helper function provided by the Linux kernel to the ebpf monitoring program. It can directly obtain the context stack information. The context stack information is the specific function call relationship of the data packet, and it can also analyze the packet loss process. The context stack information obtained by the bpf_get_stackid function will return an id. skb is the abbreviation of the kernel sk_buff structure. The data of the data packet is in this structure, and the skb address represents the address of this structure. The hash table is stored in key-value pairs. Here, the key is the address of the skb, and the value is the data needed to analyze the packet loss of this skb, including the context stack id (this is obtained through bpf_get_stackid), the source address port, the destination address port (these are obtained through the data in the sk_buff structure), and the packet loss reason (these are the return values). The hash table stores the id and some other data in the corresponding skb, and the user space can directly print out the complete context stack information based on this id.

[0034] S4: In the monitoring program, by obtaining the return values ​​of the two functions, referring to the kernel symbol table defined in S1 (i.e., defining the packet loss reason) and the saved context stack information, the packet loss stack is output, stored and printed.

[0035] It should be pointed out that although the various steps in the above embodiments are described in a specific order, those skilled in the art can understand that in order to achieve the effects of the present invention, different steps do not have to be performed in such an order, and they can be performed simultaneously (in parallel) or in other orders. These changes are within the scope of protection of the present invention.

[0036] Based on the above steps S1 to S4, the present invention proposes a tc packet loss analysis method based on the Linux network protocol stack. For the packet loss problem occurring in the tc rule or the tc eBPF program, in the Linux kernel network protocol stack, the function return value result of the tc processing data packet is obtained, and the relevant enumeration body is defined to illustrate the action result executed by tc, and the packet loss reason of the function that processes the reason for the packet loss is obtained.

[0037] At the same time, eBPF technology is used to write code to monitor the Linux kernel tc function that processes data packets and the kernel network protocol stack function that processes the cause of packet loss. When packet loss occurs, the monitoring program (that is, the code written by eBPF technology) will extract and collect the current information, including the source address, source port, destination address, destination port, packet protocol, executed CPU, function context stack, packet loss cause, classification action and other information of the packet, and save and output it.

[0038] Compared with the prior art, the advantages of the present invention are: The present invention is based on the tc packet loss analysis method under the linux network protocol stack. When packet loss occurs in the network, the problem cause of the situation is defined and described from the linux kernel network protocol stack, and then the corresponding information data is obtained and output by synchronously triggering a monitoring program.

[0039] By applying the tc packet loss analysis processing method proposed in the present invention in the Linux usage scenario, the cause of tc packet loss, data packet information and kernel process can be clearly known in the application, so as to quickly locate the cause of the problem, effectively solve the packet loss problem in production applications, improve efficiency, and further ensure the security and stability of the network environment.

[0040] Here are some terms involved in the present invention.

[0041] TC: TC (Traffic Control) is a tool in the Linux kernel for controlling and managing network traffic. It allows users to define and manipulate network traffic policies to achieve QoS (Quality of Service) management.

[0042] eBPF: Extended Berkeley Packet Filter. A technology used in many fields such as network and security to track and detect abnormal conditions.

[0043] SKB: sk_buff (socket buffer), is an important data structure in Linux network code, used to manage and control the information of receiving or sending data packets.

[0044] CTX: stands for the concept of "context". Context refers to the environment or state information when the program is running, including all information related to the current task or scenario.

[0045] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A tc packet loss analysis method based on the linux network protocol stack, characterized in that: The following steps are involved: S1: Define the action meaning corresponding to the return value of the tcf_classify function in the Linux kernel, and define the packet loss reason corresponding to the return value of the kfree_skb function; S2: Write a monitoring program in the user space to monitor the tcf_classify function and kfree_skb function in the Linux kernel. When packet loss occurs, obtain the return value of the tcf_classify function and the kfree_skb function, and upload the data to the monitoring program after processing. S3: In the monitoring program, use the parameter ctx to obtain the corresponding context stack information according to the bpf_get_stackid function, and store the context stack information and the source address, source port, destination address and destination port of the packet into the corresponding skb through the hash table; S4: In the monitoring program, by obtaining the return value of the tcf_classify function and the return value of the kfree_skb function, refer to the definition in S1 to obtain the packet loss reason, combine the context stack information to output the packet loss stack, store and print it.

2. According to a tc packet loss analysis method based on the linux network protocol stack according to claim 1, it is characterized in that: The definition of tcf_classify function and kfree_skb function can be realized by macro definition or enumeration variable definition.

3. According to a tc packet loss analysis method based on linux network protocol stack according to claim 1, it is characterized in that: The action meanings corresponding to the return value of the tcf_classify function are defined as follows: When the return value of the tcf_classify function is TC_ACT_UNSPEC, the action means that the default configuration action should be taken; When the tcf_classify function returns TC_ACT_OK, the action means that the data packet should continue; When the tcf_classify function returns TC_ACT_RECLASSIFY, the action means that the packet must be reclassified from the root queuing discipline; When the return value of the tcf_classify function is TC_ACT_SHOT, the action means that the data packet is discarded and no other tc processing should be performed; When the tcf_classify function returns TC_ACT_PIPE, the action means that the packet should be passed to the next filter chain or action for processing; When the return value of the tcf_classify function is TC_ACT_STOLEN, the action means that the data packet has been processed by a certain action; When the tcf_classify function returns TC_ACT_QUEUED, the action means that the packet should be queued for subsequent processing; When the tcf_classify function returns TC_ACT_REPEAT, the action means that the same filter chain or action should be re-executed on the packet; When the tcf_classify function returns TC_ACT_REDIRECT, the action means that the packet should be redirected; When the tcf_classify function returns TC_ACT_TRAP, the action means that the packet should be captured.

4. According to a tc packet loss analysis method based on linux network protocol stack according to claim 3, it is characterized in that: The actions corresponding to the return values ​​of the tcf_classify function TC_ACT_SHOT, TC_ACT_STOLEN, TC_ACT_QUEUED and TC_ACT_TRAP will result in packet loss, while the actions corresponding to the return values ​​of the tcf_classify function TC_ACT_UNSPEC, TC_ACT_OK, TC_ACT_RECLASSIFY, TC_ACT_PIPE, TC_ACT_REPEAT and TC_ACT_REDIRECT will not result in packet loss.

5. According to a tc packet loss analysis method based on linux network protocol stack according to claim 3, it is characterized in that: The return value of the kfree_skb function represents the specific packet loss reason corresponding to the return value of the tcf_classify function, which is TC_ACT_SHOT. The packet loss reasons corresponding to the return value of the kfree_skb function are defined as follows: When the return value of the kfree_skb function is TC_EGRESS, the packet loss is caused by egress packet loss; When the kfree_skb function returns QDISC_DROP, the packet loss is caused by queue discipline. When the return value of the kfree_skb function is TC_INGRESS, the packet loss is caused by ingress packet loss; When the kfree_skb function returns TC_COOKIE_ERROR, the packet loss is caused by an error in processing the tc ext cookie. When the kfree_skb function returns TC_CHAIN_NOTFOUND, the packet loss is caused by the failure of tc chain search; When the kfree_skb function returns TC_RECLASSIFY_LOOP, the packet loss is caused by tc exceeding the maximum number of reclassification loop iterations.

6. The method for analyzing tc packet loss based on the Linux network protocol stack according to claim 1, characterized in that: In the Linux kernel, based on the eBPF technology, the kprobe method is used to mount the hook function for the tcf_classify function, and the tracepoint method is used to mount the hook function for the kfree_skb function.

Citation Information

Patent Citations

  • Link monitoring method and device, equipment and storage medium

    CN117955875A

  • Network connection reset information acquisition method and device and storage medium

    CN118101739A

Cited By

  • Packet loss information processing method and device, electronic equipment, storage medium and program

    CN122476082A