Skip to main content

Netlink Tracer

Netlink is a socket-based interface used for communication between the Linux kernel and userspace applications.

tracenl is a proof-of-concept tool for monitoring and decoding Netlink messages at a process level. It is implemented as a thin wrapper around python-ptrace and pyroute2.

Installation

Install with pip:

$ pip install tracenl

Usage

Typical usage:

$ tracenl -- iw dev

[4292] sendmsg(fd=3, msg=0x00007ffcc5215100, flags=0x0000000000000000) = 32 (0x0000000000000020)
  {'attrs': [('NL80211_ATTR_WIPHY_NAME', 'nl80211')],
   'cmd': 3,
   'header': {'flags': 5,
              'length': 32,
              'pid': 1786777796,
              'sequence_number': 1589321889,
              'type': 16},
   'reserved': 0,
   'version': 1}

[4292] recvmsg(fd=3, msg=0x00007ffcc5215090, flags=0x0000000000000022) = 2316 (0x000000000000090c)
  {'attrs': [('NL80211_ATTR_WIPHY_NAME', 'nl80211'),
             ('NL80211_ATTR_WIPHY', 29),
             ('NL80211_ATTR_IFINDEX', 1),
             ('NL80211_ATTR_IFNAME', ''),
             ('NL80211_ATTR_IFTYPE', 278),
             ('NL80211_ATTR_MAC', '14:00:01:00:08:00'),
             ('NL80211_ATTR_KEY_DATA', '....')],
...

Limitations

In its current state, tracenl has significant limitations:

  • Only decodes nl80211 messages.
  • No support for attaching to running processes.
  • Unattractive console output

Metadata

Release files for tracenl 0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tracenl 0.1
File Size Uploaded
tracenl-0.1.tar.gz 3.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tracenl 0.1
File Interpreter ABI Platform
tracenl-0.1-py3-none-any.whl Python 3 none any Details

Total release size: 9.4 kB

Release files / tracenl-0.1.tar.gz

Download URL tracenl-0.1.tar.gz
Size 3.8 kB
Tags Source
SHA-256 checksum
How to use checksums
faccb74dbed468084843d85b7d506030e4b7054ebc0d371085637f648f624ab9
BLAKE2b-256 checksum
How to use checksums
d09ac3f7cd67e91c31ad232184e181e47483877ec0a1341a77a2bc80608a6ac0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.20.1 setuptools/41.4.0 requests-toolbelt/0.9.1 tqdm/4.40.2 CPython/3.6.9

Release files / tracenl-0.1-py3-none-any.whl

Download URL tracenl-0.1-py3-none-any.whl
Size 5.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f48f20204965d40df3b269d6f340da8c1834f296f6fe8f46daf0d908a7cd1cb8
BLAKE2b-256 checksum
How to use checksums
d2efe08871f58e28ea09c6b4aadd2a00a3ed37a2f8bc5608e3938452b79ab052
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/3.1.1 pkginfo/1.5.0.1 requests/2.20.1 setuptools/41.4.0 requests-toolbelt/0.9.1 tqdm/4.40.2 CPython/3.6.9

Release history Release notifications | RSS feed

This release

0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page