Logo

The Linux Kernel

7.3.0-rc5

Quick search

Contents

Working with the development community

  • Development process
  • Submitting patches
  • Code of conduct
  • Maintainer handbook
  • All development-process docs

Internal API manuals

  • Core API
  • Driver APIs
  • Subsystems
    • Core subsystems
    • Human interfaces
    • Networking interfaces
      • Networking
      • NetLabel
      • InfiniBand
      • MHI
    • Storage interfaces
    • Other subsystems
  • Locking

Development tools and processes

  • Licensing rules
  • Writing documentation
  • Development tools
  • Testing guide
  • Hacking guide
  • Tracing
  • Fault injection
  • Livepatching
  • Rust

User-oriented documentation

  • Administration
  • Build system
  • Reporting issues
  • Userspace tools
  • Userspace API

Firmware-related documentation

  • Firmware
  • Firmware and Devicetree

Architecture-specific documentation

  • CPU architectures

Other documentation

  • Unsorted documentation

Translations

  • Translations

This Page

  • Show Source

Family conntrack netlink specificationΒΆ

Contents

  • Family conntrack netlink specification

    • Summary

    • Operations

      • get

      • get-stats

    • Definitions

      • nfgenmsg

      • nf-ct-tcp-flags-mask

      • nf-ct-tcp-flags

      • nf-ct-tcp-state

      • nf-ct-sctp-state

      • nf-ct-status

    • Attribute sets

      • counter-attrs

      • tuple-proto-attrs

      • tuple-ip-attrs

      • tuple-attrs

      • protoinfo-tcp-attrs

      • protoinfo-dccp-attrs

      • protoinfo-sctp-attrs

      • protoinfo-attrs

      • help-attrs

      • nat-proto-attrs

      • nat-attrs

      • seqadj-attrs

      • secctx-attrs

      • synproxy-attrs

      • filter-attrs

      • conntrack-attrs

      • conntrack-stats-attrs

SummaryΒΆ

Netfilter connection tracking subsystem over nfnetlink

OperationsΒΆ

getΒΆ

get / dump entries

attribute-set:

conntrack-attrs

fixed-header:

nfgenmsg

do:
request
attributes:

[tuple-orig, tuple-reply, zone]

reply
attributes:

[tuple-orig, tuple-reply, status, protoinfo, help, nat-src, nat-dst, timeout, mark, counters-orig, counters-reply, use, id, nat-dst, tuple-master, seq-adj-orig, seq-adj-reply, zone, secctx, labels, synproxy]

dump:
request
attributes:

[tuple-orig, tuple-reply, status, mark, zone, mark-mask, filter, status-mask]

reply
attributes:

[tuple-orig, tuple-reply, status, protoinfo, help, nat-src, nat-dst, timeout, mark, counters-orig, counters-reply, use, id, nat-dst, tuple-master, seq-adj-orig, seq-adj-reply, zone, secctx, labels, synproxy]

get-statsΒΆ

dump pcpu conntrack stats

attribute-set:

conntrack-stats-attrs

fixed-header:

nfgenmsg

dump:

request

reply
attributes:

[searched, found, insert, insert-failed, drop, early-drop, error, search-restart, clash-resolve, chain-toolong]

DefinitionsΒΆ

nfgenmsgΒΆ

type:

struct

members:
nfgen-family (u8):

version (u8):

res-id (u16):

nf-ct-tcp-flags-maskΒΆ

type:

struct

members:
flags (u8):

mask (u8):

nf-ct-tcp-flagsΒΆ

type:

flags

entries:
  • window-scale

  • sack-perm

  • close-init

  • be-liberal

  • unacked

  • maxack

  • challenge-ack

  • simultaneous-open

nf-ct-tcp-stateΒΆ

type:

enum

entries:
  • none

  • syn-sent

  • syn-recv

  • established

  • fin-wait

  • close-wait

  • last-ack

  • time-wait

  • close

  • syn-sent2

  • max

  • ignore

  • retrans

  • unack

  • timeout-max

nf-ct-sctp-stateΒΆ

type:

enum

entries:
  • none

  • cloned

  • cookie-wait

  • cookie-echoed

  • established

  • shutdown-sent

  • shutdown-received

  • shutdown-ack-sent

  • shutdown-heartbeat-sent

nf-ct-statusΒΆ

type:

flags

entries:
  • expected

  • seen-reply

  • assured

  • confirmed

  • src-nat

  • dst-nat

  • seq-adj

  • src-nat-done

  • dst-nat-done

  • dying

  • fixed-timeout

  • template

  • nat-clash

  • helper

  • offload

  • hw-offload

Attribute setsΒΆ

counter-attrsΒΆ

packets (u64)ΒΆ

byte-order:

big-endian

bytes (u64)ΒΆ

byte-order:

big-endian

packets-old (u32)ΒΆ

bytes-old (u32)ΒΆ

pad (pad)ΒΆ

tuple-proto-attrsΒΆ

proto-num (u8)ΒΆ

doc:

l4 protocol number

proto-src-port (u16)ΒΆ

byte-order:

big-endian

doc:

l4 source port

proto-dst-port (u16)ΒΆ

byte-order:

big-endian

doc:

l4 source port

proto-icmp-id (u16)ΒΆ

byte-order:

big-endian

doc:

l4 icmp id

proto-icmp-type (u8)ΒΆ

proto-icmp-code (u8)ΒΆ

proto-icmpv6-id (u16)ΒΆ

byte-order:

big-endian

doc:

l4 icmp id

proto-icmpv6-type (u8)ΒΆ

proto-icmpv6-code (u8)ΒΆ

tuple-ip-attrsΒΆ

ip-v4-src (u32)ΒΆ

byte-order:

big-endian

display-hint:

ipv4

doc:

ipv4 source address

ip-v4-dst (u32)ΒΆ

byte-order:

big-endian

display-hint:

ipv4

doc:

ipv4 destination address

ip-v6-src (binary)ΒΆ

byte-order:

big-endian

display-hint:

ipv6

doc:

ipv6 source address

ip-v6-dst (binary)ΒΆ

byte-order:

big-endian

display-hint:

ipv6

doc:

ipv6 destination address

tuple-attrsΒΆ

tuple-ip (nest)ΒΆ

nested-attributes:

tuple-ip-attrs

doc:

conntrack l3 information

tuple-proto (nest)ΒΆ

nested-attributes:

tuple-proto-attrs

doc:

conntrack l4 information

tuple-zone (u16)ΒΆ

byte-order:

big-endian

doc:

conntrack zone id

protoinfo-tcp-attrsΒΆ

tcp-state (u8)ΒΆ

enum:

nf-ct-tcp-state

doc:

tcp connection state

tcp-wscale-original (u8)ΒΆ

doc:

window scaling factor in original direction

tcp-wscale-reply (u8)ΒΆ

doc:

window scaling factor in reply direction

tcp-flags-original (binary)ΒΆ

struct:

nf-ct-tcp-flags-mask

tcp-flags-reply (binary)ΒΆ

struct:

nf-ct-tcp-flags-mask

protoinfo-dccp-attrsΒΆ

dccp-state (u8)ΒΆ

doc:

dccp connection state

dccp-role (u8)ΒΆ

dccp-handshake-seq (u64)ΒΆ

byte-order:

big-endian

dccp-pad (pad)ΒΆ

protoinfo-sctp-attrsΒΆ

sctp-state (u8)ΒΆ

doc:

sctp connection state

enum:

nf-ct-sctp-state

vtag-original (u32)ΒΆ

byte-order:

big-endian

vtag-reply (u32)ΒΆ

byte-order:

big-endian

protoinfo-attrsΒΆ

protoinfo-tcp (nest)ΒΆ

nested-attributes:

protoinfo-tcp-attrs

doc:

conntrack tcp state information

protoinfo-dccp (nest)ΒΆ

nested-attributes:

protoinfo-dccp-attrs

doc:

conntrack dccp state information

protoinfo-sctp (nest)ΒΆ

nested-attributes:

protoinfo-sctp-attrs

doc:

conntrack sctp state information

help-attrsΒΆ

help-name (string)ΒΆ

doc:

helper name

nat-proto-attrsΒΆ

nat-port-min (u16)ΒΆ

byte-order:

big-endian

nat-port-max (u16)ΒΆ

byte-order:

big-endian

nat-attrsΒΆ

nat-v4-minip (u32)ΒΆ

byte-order:

big-endian

nat-v4-maxip (u32)ΒΆ

byte-order:

big-endian

nat-v6-minip (binary)ΒΆ

nat-v6-maxip (binary)ΒΆ

nat-proto (nest)ΒΆ

nested-attributes:

nat-proto-attrs

seqadj-attrsΒΆ

correction-pos (u32)ΒΆ

byte-order:

big-endian

offset-before (u32)ΒΆ

byte-order:

big-endian

offset-after (u32)ΒΆ

byte-order:

big-endian

secctx-attrsΒΆ

secctx-name (string)ΒΆ

synproxy-attrsΒΆ

isn (u32)ΒΆ

byte-order:

big-endian

its (u32)ΒΆ

byte-order:

big-endian

tsoff (u32)ΒΆ

byte-order:

big-endian

filter-attrsΒΆ

orig-flags (u32)ΒΆ

doc:

bitmask of tuple fields to filter on, original direction

reply-flags (u32)ΒΆ

doc:

bitmask of tuple fields to filter on, reply direction

conntrack-attrsΒΆ

tuple-orig (nest)ΒΆ

nested-attributes:

tuple-attrs

doc:

conntrack l3+l4 protocol information, original direction

tuple-reply (nest)ΒΆ

nested-attributes:

tuple-attrs

doc:

conntrack l3+l4 protocol information, reply direction

status (u32)ΒΆ

byte-order:

big-endian

enum:

nf-ct-status

enum-as-flags:

True

doc:

conntrack flag bits

protoinfo (nest)ΒΆ

nested-attributes:

protoinfo-attrs

help (nest)ΒΆ

nested-attributes:

help-attrs

nat-src (nest)ΒΆ

nested-attributes:

nat-attrs

timeout (u32)ΒΆ

byte-order:

big-endian

mark (u32)ΒΆ

byte-order:

big-endian

counters-orig (nest)ΒΆ

nested-attributes:

counter-attrs

counters-reply (nest)ΒΆ

nested-attributes:

counter-attrs

use (u32)ΒΆ

byte-order:

big-endian

id (u32)ΒΆ

byte-order:

big-endian

nat-dst (nest)ΒΆ

nested-attributes:

nat-attrs

tuple-master (nest)ΒΆ

nested-attributes:

tuple-attrs

seq-adj-orig (nest)ΒΆ

nested-attributes:

seqadj-attrs

seq-adj-reply (nest)ΒΆ

nested-attributes:

seqadj-attrs

secmark (binary)ΒΆ

doc:

obsolete

zone (u16)ΒΆ

byte-order:

big-endian

doc:

conntrack zone id

secctx (nest)ΒΆ

nested-attributes:

secctx-attrs

timestamp (u64)ΒΆ

byte-order:

big-endian

mark-mask (u32)ΒΆ

byte-order:

big-endian

labels (binary)ΒΆ

labels-mask (binary)ΒΆ

synproxy (nest)ΒΆ

nested-attributes:

synproxy-attrs

filter (nest)ΒΆ

nested-attributes:

filter-attrs

status-mask (u32)ΒΆ

byte-order:

big-endian

enum:

nf-ct-status

enum-as-flags:

True

doc:

conntrack flag bits to change

timestamp-event (u64)ΒΆ

byte-order:

big-endian

conntrack-stats-attrsΒΆ

searched (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

found (u32)ΒΆ

byte-order:

big-endian

new (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

invalid (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

ignore (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

delete (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

delete-list (u32)ΒΆ

byte-order:

big-endian

doc:

obsolete

insert (u32)ΒΆ

byte-order:

big-endian

insert-failed (u32)ΒΆ

byte-order:

big-endian

drop (u32)ΒΆ

byte-order:

big-endian

early-drop (u32)ΒΆ

byte-order:

big-endian

error (u32)ΒΆ

byte-order:

big-endian

search-restart (u32)ΒΆ

byte-order:

big-endian

clash-resolve (u32)ΒΆ

byte-order:

big-endian

chain-toolong (u32)ΒΆ

byte-order:

big-endian

©The kernel development community. | Powered by Sphinx 5.3.0 & Alabaster 0.7.16 | Page source