|
(gdb) thread 8
|
|
[Switching to thread 8 (Thread 0x7f8f01a83700 (LWP 4153))]#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
(gdb) bt full
|
|
#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
#1 0x00007f8f05f6813c in ReceiveAFPLoop (tv=0x7f8f0b0b8810, data=0x7f8ef80008f0, slot=<value optimized out>)
|
|
at source-af-packet.c:1002
|
|
packet_q_len = <value optimized out>
|
|
ptv = 0x7f8ef80008f0
|
|
fds = {fd = 8, events = 1, revents = 0}
|
|
r = <value optimized out>
|
|
s = <value optimized out>
|
|
last_dump = 1373040893
|
|
current_time = {tv_sec = 1373040893, tv_usec = 442512}
|
|
__FUNCTION__ = "ReceiveAFPLoop"
|
|
#2 0x00007f8f05f8ca76 in TmThreadsSlotPktAcqLoop (td=0x7f8f0b0b8810) at tm-threads.c:682
|
|
tv = 0x7f8f0b0b8810
|
|
s = 0x7f8f0bcc5880
|
|
run = <value optimized out>
|
|
r = <value optimized out>
|
|
slot = 0x0
|
|
__FUNCTION__ = "TmThreadsSlotPktAcqLoop"
|
|
#3 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#4 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 7
|
|
[Switching to thread 7 (Thread 0x7f8f00f22700 (LWP 4154))]#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
(gdb) bt full
|
|
#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
#1 0x00007f8f05f6813c in ReceiveAFPLoop (tv=0x7f8f0b0b8990, data=0x7f8ef00008f0, slot=<value optimized out>)
|
|
at source-af-packet.c:1002
|
|
packet_q_len = <value optimized out>
|
|
ptv = 0x7f8ef00008f0
|
|
fds = {fd = 9, events = 1, revents = 0}
|
|
r = <value optimized out>
|
|
s = <value optimized out>
|
|
last_dump = 1373040893
|
|
current_time = {tv_sec = 1373040893, tv_usec = 446570}
|
|
__FUNCTION__ = "ReceiveAFPLoop"
|
|
#2 0x00007f8f05f8ca76 in TmThreadsSlotPktAcqLoop (td=0x7f8f0b0b8990) at tm-threads.c:682
|
|
tv = 0x7f8f0b0b8990
|
|
s = 0x7f8f0b0fba70
|
|
run = <value optimized out>
|
|
r = <value optimized out>
|
|
slot = 0x0
|
|
__FUNCTION__ = "TmThreadsSlotPktAcqLoop"
|
|
#3 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#4 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 6
|
|
[Switching to thread 6 (Thread 0x7f8f00721700 (LWP 4155))]#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
(gdb) bt full
|
|
#0 0x00007f8f03035253 in poll () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
#1 0x00007f8f05f6813c in ReceiveAFPLoop (tv=0x7f8f0b0eae30, data=0x7f8ef40008f0, slot=<value optimized out>)
|
|
at source-af-packet.c:1002
|
|
packet_q_len = <value optimized out>
|
|
ptv = 0x7f8ef40008f0
|
|
fds = {fd = 10, events = 1, revents = 0}
|
|
r = <value optimized out>
|
|
s = <value optimized out>
|
|
last_dump = 1373040893
|
|
current_time = {tv_sec = 1373040893, tv_usec = 190517}
|
|
__FUNCTION__ = "ReceiveAFPLoop"
|
|
#2 0x00007f8f05f8ca76 in TmThreadsSlotPktAcqLoop (td=0x7f8f0b0eae30) at tm-threads.c:682
|
|
tv = 0x7f8f0b0eae30
|
|
s = 0x7f8f0bbc6290
|
|
run = <value optimized out>
|
|
r = <value optimized out>
|
|
slot = 0x0
|
|
__FUNCTION__ = "TmThreadsSlotPktAcqLoop"
|
|
#3 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#4 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 5
|
|
[Switching to thread 5 (Thread 0x7f8efff20700 (LWP 4156))]#0 list_array_get (_l=<value optimized out>, idx=5464)
|
|
at dslib.c:242
|
|
242 while (idx--) {
|
|
(gdb) bt full
|
|
#0 list_array_get (_l=<value optimized out>, idx=5464) at dslib.c:242
|
|
l = <value optimized out>
|
|
r = 0x0
|
|
i = 634
|
|
#1 0x00007f8f05ec2217 in DetectMpmPrefilter (th_v=0x7f8f0b0e1430, de_ctx=0x7f8f07efd2b0, det_ctx=0x7f8ee8016790,
|
|
p=0x7f8f07bccab0) at detect.c:994
|
|
tx = <value optimized out>
|
|
htp_state = 0x7f8ee922dff0
|
|
tx_progress = <value optimized out>
|
|
idx = 6099
|
|
total_txs = 9973
|
|
#2 SigMatchSignatures (th_v=0x7f8f0b0e1430, de_ctx=0x7f8f07efd2b0, det_ctx=0x7f8ee8016790, p=0x7f8f07bccab0) at detect.c:1400
|
|
sms_runflags = 3 '\003'
|
|
alert_flags = 0 '\000'
|
|
alproto = 1
|
|
idx = <value optimized out>
|
|
flags = 8 '\b'
|
|
alstate = 0x7f8ee922dff0
|
|
smsg = 0x0
|
|
s = 0x0
|
|
sm = 0x0
|
|
alversion = 16059
|
|
reset_de_state = <value optimized out>
|
|
app_decoder_events = <value optimized out>
|
|
app_decoder_events_cnt = 0
|
|
alerts = 0
|
|
i = <value optimized out>
|
|
mask = <value optimized out>
|
|
#3 0x00007f8f05ec2cff in Detect (tv=<value optimized out>, p=<value optimized out>, data=<value optimized out>,
|
|
pq=<value optimized out>, postpq=<value optimized out>) at detect.c:1801
|
|
det_ctx = <value optimized out>
|
|
de_ctx = <value optimized out>
|
|
r = <value optimized out>
|
|
#4 0x00007f8f05f8ce38 in TmThreadsSlotVarRun (tv=0x7f8f0b0e1430, p=0x7f8f07bccab0, slot=<value optimized out>)
|
|
at tm-threads.c:542
|
|
SlotFunc = <value optimized out>
|
|
r = <value optimized out>
|
|
s = 0x7f8f0bbd28c0
|
|
extra_p = <value optimized out>
|
|
#5 0x00007f8f05f67c30 in TmThreadsSlotProcessPkt (ptv=<value optimized out>) at tm-threads.h:139
|
|
r = TM_ECODE_OK
|
|
#6 AFPReadFromRing (ptv=<value optimized out>) at source-af-packet.c:829
|
|
p = 0x7f8f07bccab0
|
|
from = <value optimized out>
|
|
emergency_flush = 0 '\000'
|
|
read_pkts = 124
|
|
loop_start = -1
|
|
#7 0x00007f8f05f68174 in ReceiveAFPLoop (tv=0x7f8f0b0e1430, data=0x7f8ee80008f0, slot=<value optimized out>)
|
|
at source-af-packet.c:1030
|
|
packet_q_len = <value optimized out>
|
|
ptv = 0x7f8ee80008f0
|
|
fds = {fd = 11, events = 1, revents = 1}
|
|
r = <value optimized out>
|
|
s = <value optimized out>
|
|
last_dump = 1373040891
|
|
current_time = {tv_sec = 1373040891, tv_usec = 290118}
|
|
__FUNCTION__ = "ReceiveAFPLoop"
|
|
#8 0x00007f8f05f8ca76 in TmThreadsSlotPktAcqLoop (td=0x7f8f0b0e1430) at tm-threads.c:682
|
|
tv = 0x7f8f0b0e1430
|
|
s = 0x7f8f0af6eea0
|
|
run = <value optimized out>
|
|
r = <value optimized out>
|
|
slot = 0x0
|
|
__FUNCTION__ = "TmThreadsSlotPktAcqLoop"
|
|
#9 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#10 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 4
|
|
[Switching to thread 4 (Thread 0x7f8eff71f700 (LWP 4157))]#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 ()
|
|
from /lib64/libpthread.so.0
|
|
(gdb) bt full
|
|
#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#1 0x00007f8f05f3dbf5 in FlowManagerThread (td=0x7f8f0b0e12b0) at flow-manager.c:543
|
|
counters = {new = 0, est = 8, clo = 5}
|
|
flow_memuse = <value optimized out>
|
|
len = <value optimized out>
|
|
th_v = 0x7f8f0b0e12b0
|
|
ts = {tv_sec = 1373040893, tv_usec = 82}
|
|
emerg = 0
|
|
prev_emerg = 0
|
|
last_sec = <value optimized out>
|
|
cond_time = {tv_sec = 1373040894, tv_nsec = 0}
|
|
flow_update_delay_sec = 1
|
|
flow_update_delay_nsec = 0
|
|
flow_mgr_cnt_clo = 1
|
|
flow_mgr_cnt_new = 2
|
|
flow_mgr_cnt_est = 3
|
|
flow_mgr_memuse = 4
|
|
flow_mgr_spare = 5
|
|
flow_emerg_mode_enter = 6
|
|
flow_emerg_mode_over = 58896
|
|
__FUNCTION__ = "FlowManagerThread"
|
|
#2 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#3 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 3
|
|
[Switching to thread 3 (Thread 0x7f8efd96d700 (LWP 4158))]#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 ()
|
|
from /lib64/libpthread.so.0
|
|
(gdb) bt full
|
|
#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#1 0x00007f8f05ea3e30 in SCPerfWakeupThread (arg=0x7f8f0bc482c0) at counters.c:547
|
|
tv_local = 0x7f8f0bc482c0
|
|
run = 1 '\001'
|
|
tv = <value optimized out>
|
|
q = <value optimized out>
|
|
cond_time = {tv_sec = 1373040895, tv_nsec = 0}
|
|
__FUNCTION__ = "SCPerfWakeupThread"
|
|
#2 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#3 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 2
|
|
[Switching to thread 2 (Thread 0x7f8efd16c700 (LWP 4159))]#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 ()
|
|
from /lib64/libpthread.so.0
|
|
(gdb) bt full
|
|
#0 0x00007f8f034f87bb in pthread_cond_timedwait@@GLIBC_2.3.2 () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#1 0x00007f8f05ea59d8 in SCPerfMgmtThread (arg=0x7f8f0b6e6a60) at counters.c:479
|
|
tv_local = 0x7f8f0b6e6a60
|
|
run = 1 '\001'
|
|
cond_time = {tv_sec = 1373040896, tv_nsec = 0}
|
|
__FUNCTION__ = "SCPerfMgmtThread"
|
|
#2 0x00007f8f034f4851 in start_thread () from /lib64/libpthread.so.0
|
|
No symbol table info available.
|
|
#3 0x00007f8f0303e90d in clone () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
|
|
-------------------------------------------------------------------------------------------------------------------------------
|
|
|
|
(gdb) thread 1
|
|
[Switching to thread 1 (Thread 0x7f8f05e3f720 (LWP 4149))]#0 0x00007f8f03002b8d in nanosleep () from /lib64/libc.so.6
|
|
(gdb) bt full
|
|
#0 0x00007f8f03002b8d in nanosleep () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
#1 0x00007f8f03037d64 in usleep () from /lib64/libc.so.6
|
|
No symbol table info available.
|
|
#2 0x00007f8f05f8339b in main (argc=239188248, argv=<value optimized out>) at suricata.c:2047
|
|
opt = <value optimized out>
|
|
pcap_dev = "eth1", '\000' <repeats 123 times>
|
|
sig_file = 0x0
|
|
sig_file_exclusive = 0
|
|
conf_test = 0
|
|
pid_filename = 0x7fff0e41c85b "/var/lock/subsys/suricata"
|
|
dump_config = 0
|
|
list_app_layer_protocols = 0
|
|
list_unittests = 0
|
|
list_cuda_cards = 0
|
|
list_runmodes = 0
|
|
list_keywords = 0
|
|
keyword_info = <value optimized out>
|
|
runmode_custom_mode = 0x0
|
|
daemon = 1
|
|
user_name = 0x7fff0e41c88d "suri"
|
|
group_name = 0x7fff0e41c89a "suri"
|
|
do_setuid = 1 '\001'
|
|
do_setgid = 1 '\001'
|
|
userid = 495
|
|
groupid = 491
|
|
build_info = 0
|
|
delayed_detect = 0
|
|
log_dir = 0x7f8f06e6d3c0 "/var/log/suricata/"
|
|
buf = {st_dev = 64513, st_ino = 1061314, st_nlink = 2, st_mode = 16888, st_uid = 0, st_gid = 491, __pad0 = 0,
|
|
st_rdev = 0, st_size = 12288, st_blksize = 4096, st_blocks = 24, st_atim = {tv_sec = 1372897749,
|
|
tv_nsec = 605231249}, st_mtim = {tv_sec = 1372897748, tv_nsec = 936218909}, st_ctim = {tv_sec = 1372897748,
|
|
tv_nsec = 936218909}, __unused = {0, 0, 0}}
|
|
__FUNCTION__ = "main"
|
|
long_opts = {{name = 0x7f8f0600d469 "dump-config", has_arg = 0, flag = 0x7fff0e41b48c, val = 1}, {
|
|
name = 0x7f8f0600a7e8 "pfring", has_arg = 2, flag = 0x0, val = 0}, {name = 0x7f8f0600d475 "pfring-int",
|
|
has_arg = 1, flag = 0x0, val = 0}, {name = 0x7f8f0600d480 "pfring-cluster-id", has_arg = 1, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d492 "pfring-cluster-type", has_arg = 1, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f06009381 "af-packet", has_arg = 2, flag = 0x0, val = 0}, {name = 0x7f8f0600a162 "pcap", has_arg = 2,
|
|
flag = 0x0, val = 0}, {name = 0x7f8f0600d4a6 "unix-socket", has_arg = 2, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d4b2 "pcap-buffer-size", has_arg = 1, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d4c3 "unittest-filter", has_arg = 1, flag = 0x0, val = 85}, {
|
|
name = 0x7f8f0600d4d3 "list-app-layer-protos", has_arg = 0, flag = 0x7fff0e41b488, val = 1}, {
|
|
name = 0x7f8f0600d4e9 "list-unittests", has_arg = 0, flag = 0x7fff0e41b484, val = 1}, {
|
|
name = 0x7f8f0600d4f8 "list-cuda-cards", has_arg = 0, flag = 0x7fff0e41b480, val = 1}, {
|
|
name = 0x7f8f0600d508 "list-runmodes", has_arg = 0, flag = 0x7fff0e41b47c, val = 1}, {
|
|
name = 0x7f8f0600d516 "list-keywords", has_arg = 2, flag = 0x7fff0e41b478, val = 1}, {
|
|
name = 0x7f8f06009342 "runmode", has_arg = 1, flag = 0x0, val = 0}, {name = 0x7f8f05ffbf6b "engine-analysis",
|
|
has_arg = 0, flag = 0x7f8f06267998, val = 1}, {name = 0x7f8f0600d524 "pidfile", has_arg = 1, flag = 0x0, val = 0},
|
|
{name = 0x7f8f0600d52c "init-errors-fatal", has_arg = 0, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d53e "fatal-unittests", has_arg = 0, flag = 0x0, val = 0}, {name = 0x7f8f0600d6a4 "user",
|
|
has_arg = 1, flag = 0x0, val = 0}, {name = 0x7f8f060183d5 "group", has_arg = 1, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d54e "erf-in", has_arg = 1, flag = 0x0, val = 0}, {name = 0x7f8f0600d555 "dag", has_arg = 1,
|
|
flag = 0x0, val = 0}, {name = 0x7f8f0600d559 "napatech", has_arg = 0, flag = 0x0, val = 0}, {
|
|
name = 0x7f8f0600d562 "build-info", has_arg = 0, flag = 0x7fff0e41b46c, val = 1}, {name = 0x0, has_arg = 0,
|
|
flag = 0x0, val = 0}}
|
|
option_index = 21
|
|
short_opts = "c:TDhi:l:q:d:r:us:S:U:VF:"
|
|
temp_default_packet_size = 0x7f8f04d6d1d0 ""
|
|
c = <value optimized out>
|
|
de_ctx = 0x7f8f07efd2b0
|
|
start_time = {tv_sec = 1372944291, tv_usec = 395384}
|
|
end_time = {tv_sec = 140252256026584, tv_usec = 140733432578152}
|
|
milliseconds = <value optimized out>
|
|
global_de_ctx = <value optimized out>
|
|
__PRETTY_FUNCTION__ = "main"
|