#libbpf #ebpf #networking #cgroup-skb

cgroup_traffic

A simple bpf program to monitor process traffic by cgroup_skb/egress and cgroup_skb/ingress

14 releases

0.2.2 Oct 23, 2024
0.2.1 Oct 15, 2024
0.1.10 Oct 2, 2024
0.1.8 Sep 29, 2024

#541 in Unix APIs

Download history 524/week @ 2024-09-25 231/week @ 2024-10-02 244/week @ 2024-10-09 150/week @ 2024-10-16 200/week @ 2024-10-23 4/week @ 2024-10-30 7/week @ 2024-11-06 1/week @ 2024-11-13 1/week @ 2024-11-20 6/week @ 2024-11-27 13/week @ 2024-12-04 9/week @ 2024-12-11 144/week @ 2025-01-01

154 downloads per month

LGPL-2.1-only OR BSD-2-Clause

605KB
254 lines

cgroup_traffic is a library to monitor the network traffic of a cgroup. By passing a pid to this library, it will attach to the cgroup of the pid and monitor the network traffic of the cgroup.

It use ebpf program BPF_PROG_TYPE_CGROUP_SKB to monitor the network traffic. Now it's only tested for Cgroup V2. It doesn't support Cgroup V1, because it cannot parse the path of cgroup V1.

Examples

#![deny(warnings)]
use std::mem::MaybeUninit;

use log::info;

pub fn main() -> Result<(), Box<dyn std::error::Error>> {
    let _ = env_logger::builder()
        .filter_level(log::LevelFilter::Info)
        .try_init();

    let mut open_object = MaybeUninit::uninit(); // make the ebpf prog lives as long as the process.
    let (cgroup_transmit_counter, _links) = cgroup_traffic::init_cgroup_skb_for_process_name(
        &mut open_object,
        "^rust-analyzer$|ssh|rust_http_proxy",
    )?; // _links cannot be replaced by _, because it holds the life of bpf prog.
    loop {
        info!(
            "current bytes: {} {}",
            cgroup_transmit_counter.get_egress(),
            cgroup_transmit_counter.get_ingress()
        );
        std::thread::sleep(std::time::Duration::from_secs(1));
    }
}

Refer to cgroup_traffic::init_cgroup_skb_monitor if you want to attach to a specific cgroup path.

Limitations

  • Support for Cgroup V1 is NOT tested.

Dependencies

~11MB
~242K SLoC