Project

General

Profile

Bug #1101 » flow-dump-thread-4.txt

Thread that is processing the same flow - Duarte Silva, 02/07/2014 12:10 PM

 
(gdb) thread 4
[Switching to thread 4 (Thread 0x7ffff1d7a700 (LWP 9609))]#0 __lll_lock_wait () at ../nptl/sysdeps/unix/sysv/linux/x86_64/lowlevellock.S:136
136 2: movl %edx, %eax
(gdb) frame 3
#3 0x0000000000481964 in SigMatchSignatures (th_v=0x501e460, de_ctx=0x196ae10, det_ctx=0x7fffe40148e0, p=0x154f160) at detect.c:1584
1584 FLOWLOCK_WRLOCK(pflow);
(gdb) print *p
$4 = {src = {family = 2 '\002', address = {address_un_data32 = {511027392, 0, 0, 0}, address_un_data16 = {43200, 7797, 0, 0, 0, 0, 0, 0},
address_un_data8 = "\300\250u\036", '\000' <repeats 11 times>}}, dst = {family = 2 '\002', address = {address_un_data32 = {242815148, 0, 0, 0},
address_un_data16 = {4268, 3705, 0, 0, 0, 0, 0, 0}, address_un_data8 = "\254\020y\016", '\000' <repeats 11 times>}}, {sp = 61391, type = 207 '\317'},
{dp = 7091, code = 179 '\263'}, proto = 6 '\006', recursion_level = 0 '\000', vlan_id = {0, 0}, vlan_idx = 0 '\000', flowflags = 53 '5', flags = 65792,
flow = 0x7fffdc2bae00, ts = {tv_sec = 1391795473, tv_usec = 742539}, {afp_v = {relptr = 0x7fffc8e91290, copy_mode = 0, peer = 0x0,
mpeer = 0x7fffe4000b60}, pcap_v = {<No data fields>}}, ReleasePacket = 0x589b0d <AFPReleasePacket>, pktvar = 0x0, ethh = 0x7fffc8e912d2,
level3_comp_csum = -1, level4_comp_csum = 1878, ip4h = 0x7fffc8e912e0, ip6h = 0x0, {ip4vars = {comp_csum = 0, ip_src_u32 = 0, ip_dst_u32 = 0, ip_opts = {{
type = 148 '\224', len = 4 '\004', data = 0x7fffd39f5d36 "P\207N\003\355\251}KY?\020"}, {type = 0 '\000', len = 0 '\000',
data = 0x0} <repeats 39 times>}, ip_opt_cnt = 0 '\000', o_rr = 0x0, o_qs = 0x0, o_ts = 0x0, o_sec = 0x0, o_lsrr = 0x0, o_cipso = 0x0,
o_sid = 0x0, o_ssrr = 0x0, o_rtralt = 0x0}, {ip6vars = {ip_opts_len = 0 '\000', l4proto = 0 '\000'}, ip6eh = {ip6fh = 0x0, fh_offset = 1172,
ip6rh = 0x7fffd39f5d36, ip6ah = 0x0, ip6eh = 0x0, ip6dh1 = 0x0, ip6dh2 = 0x0, ip6hh = 0x0, ip6hh_opt_hao = {ip6hao_type = 0 '\000',
ip6hao_len = 0 '\000', ip6hao_hoa = {__in6_u = {__u6_addr8 = '\000' <repeats 15 times>, __u6_addr16 = {0, 0, 0, 0, 0, 0, 0, 0}, __u6_addr32 = {0,
0, 0, 0}}}}, ip6hh_opt_ra = {ip6ra_type = 0 '\000', ip6ra_len = 0 '\000', ip6ra_value = 0}, ip6hh_opt_jumbo = {ip6j_type = 0 '\000',
ip6j_len = 0 '\000', ip6j_payload_len = 0}, ip6dh1_opt_hao = {ip6hao_type = 0 '\000', ip6hao_len = 0 '\000', ip6hao_hoa = {__in6_u = {
__u6_addr8 = '\000' <repeats 15 times>, __u6_addr16 = {0, 0, 0, 0, 0, 0, 0, 0}, __u6_addr32 = {0, 0, 0, 0}}}}, ip6dh1_opt_ra = {
ip6ra_type = 0 '\000', ip6ra_len = 0 '\000', ip6ra_value = 0}, ip6dh1_opt_jumbo = {ip6j_type = 0 '\000', ip6j_len = 0 '\000',
ip6j_payload_len = 0}, ip6dh2_opt_hao = {ip6hao_type = 0 '\000', ip6hao_len = 0 '\000', ip6hao_hoa = {__in6_u = {
__u6_addr8 = '\000' <repeats 15 times>, __u6_addr16 = {0, 0, 0, 0, 0, 0, 0, 0}, __u6_addr32 = {0, 0, 0, 0}}}}, ip6dh2_opt_ra = {
ip6ra_type = 0 '\000', ip6ra_len = 0 '\000', ip6ra_value = 0}, ip6dh2_opt_jumbo = {ip6j_type = 0 '\000', ip6j_len = 0 '\000',
ip6j_payload_len = 0}, ip6_exthdrs = {{type = 0 '\000', next = 0 '\000', len = 0 '\000', data = 0x0} <repeats 40 times>},
ip6_exthdrs_cnt = 0 '\000'}}}, {tcpvars = {tcp_opt_cnt = 3 '\003', tcp_opts = {{type = 2 '\002', len = 4 '\004',
data = 0x7fffc8e9130a "\005\264\001\003\003"}, {type = 3 '\003', len = 3 '\003', data = 0x7fffc8e9130f ""}, {type = 4 '\004', len = 2 '\002',
data = 0x7fffc8e91312 ""}, {type = 3 '\003', len = 3 '\003',
data = 0x7fffc801d72b "\a\v)4:\022\067PGOU\033qt`8\200\001\327q\337\016\260\275\032JVQB\310c\276\026\v\v\233\225\235\267o\033C\016\030lC\357\062\b\b\326\345\257%\205\222\200\220V\026\324D^r\222", '"' <repeats 22 times>, "\020\016Es-%Jhj\245\207\356/6\363\034\307ĺi \v\225E\345Um%|\321\311N\354N\001\315y\261\002\300\367\272\375k\320觹\270", <incomplete sequence \304>}, {type = 0 '\000', len = 0 '\000', data = 0x0} <repeats 16 times>}, ts = 0x0,
sack = 0x0, sackok = 0x154f558, ws = 0x154f548, mss = 0x154f538}, udpvars = {<No data fields>}, icmpv4vars = {id = 3, seq = 0, mtu = 0,
error_ptr = 1026, emb_ipv4h = 0x7fffc8e9130a, emb_tcph = 0x303, emb_udph = 0x7fffc8e9130f, emb_icmpv4h = 0x204, emb_ip4_src = {s_addr = 3370717970},
emb_ip4_dst = {s_addr = 32767}, emb_ip4_hlen = 3 '\003', emb_ip4_proto = 3 '\003', emb_sport = 0, emb_dport = 0}, icmpv6vars = {id = 3, seq = 0,
mtu = 0, error_ptr = 1026, emb_ipv6h = 0x7fffc8e9130a, emb_tcph = 0x303, emb_udph = 0x7fffc8e9130f, emb_icmpv6h = 0x204, emb_ip6_src = {3370717970,
32767, 771, 0}, emb_ip6_dst = {3355563819, 32767, 0, 0}, emb_ip6_proto_next = 0 '\000', emb_sport = 0, emb_dport = 0}}, tcph = 0x7fffc8e912f4,
udph = 0x0, sctph = 0x0, icmpv4h = 0x0, icmpv6h = 0x0, ppph = 0x0, pppoesh = 0x0, pppoedh = 0x0, greh = 0x0, vlanh = {0x0, 0x0},
payload = 0x7fffc8e91314 " =\211\202\370#*\214:\032\071\004u\t\265\027\376\244\250\362mi=\004O\"\271 \305}G4\377\nL\"", payload_len = 0,
action = 0 '\000', pkt_src = 1 '\001', pktlen = 66, ext_pkt = 0x7fffc8e912d2 "", livedev = 0x3a85f80, alerts = {cnt = 0, alerts = {{num = 0,
order_id = 0, action = 0 '\000', flags = 0 '\000', s = 0x0, tx_id = 0} <repeats 15 times>}}, host_src = 0x0, host_dst = 0x0, pcap_cnt = 0,
events = {cnt = 0 '\000', events = "enu", '\000' <repeats 11 times>}, app_layer_events = 0x7fffdbec8160, next = 0x0, prev = 0x0, datalink = 1,
debuglog_flowbits_names_len = 0, debuglog_flowbits_names = 0x0, root = 0x0, tunnel_mutex = {__data = {__lock = 0, __count = 0, __owner = 0, __nusers = 0,
__kind = 0, __spins = 0, __list = {__prev = 0x0, __next = 0x0}}, __size = '\000' <repeats 39 times>, __align = 0}, tunnel_rtv_cnt = 0,
tunnel_tpr_cnt = 0}
(gdb) print *p->flow
$5 = {src = {address = {address_un_data32 = {511027392, 0, 0, 0}, address_un_data16 = {43200, 7797, 0, 0, 0, 0, 0, 0},
address_un_data8 = "\300\250u\036", '\000' <repeats 11 times>}}, dst = {address = {address_un_data32 = {242815148, 0, 0, 0}, address_un_data16 = {
4268, 3705, 0, 0, 0, 0, 0, 0}, address_un_data8 = "\254\020y\016", '\000' <repeats 11 times>}}, {sp = 61391, type = 207 '\317'}, {dp = 7091,
code = 179 '\263'}, proto = 6 '\006', recursion_level = 0 '\000', vlan_id = {0, 0}, use_cnt_sc_atomic__ = 2, autofp_tmqh_flow_qid_sc_atomic__ = -1,
probing_parser_toserver_alproto_masks = 0, probing_parser_toclient_alproto_masks = 0, flags = 4144044155, lastts_sec = 1391795473, m = {__data = {
__lock = 2, __count = 0, __owner = 9607, __nusers = 1, __kind = 0, __spins = 0, __list = {__prev = 0x0, __next = 0x0}},
__size = "\002\000\000\000\000\000\000\000\207%\000\000\001", '\000' <repeats 26 times>, __align = 2}, protoctx = 0x7fffb00900e0, protomap = 0 '\000',
pad0 = 0 '\000', alproto = 0, alproto_ts = 0, alproto_tc = 0, data_al_so_far = {0, 0}, de_ctx_id = 1, alparser = 0x0, alstate = 0x0, de_state = 0x0,
sgh_toclient = 0x5b4f140, sgh_toserver = 0x4fe1740, flowvar = 0x0, de_state_m = {__data = {__lock = 0, __count = 0, __owner = 0, __nusers = 0,
__kind = 0, __spins = 0, __list = {__prev = 0x0, __next = 0x0}}, __size = '\000' <repeats 39 times>, __align = 0}, hnext = 0x7fffdce8a070,
hprev = 0x0, fb = 0x7ffff3bbd750, lnext = 0x0, lprev = 0x0, startts = {tv_sec = 1391795459, tv_usec = 430152}}
(5-5/7)