How to close a running process's socket
incoherency.co.uk
incoherency.co.uk
call creat("/path/to/where/you/want/log")
$1 = 3
call dup2(3,1)
$2 = 1
call close(3)
$3 = 0
Then start tailing /path/to/where/you/want/logWhat I found via SO [0] was in the context of routing things to dev/null instead of stdout, but you appear to be able to route to whatever you need to:
;; Setup: A bash scropt printed 'wat' every second,
;; redirected to /dev/null
;; Attach to the process in question using gdb:
gknoy$ sudo gdb 15488
;; Use '1' as the open flag, for write-only
(gdb) p dup2(open("/tmp/wat.log",1),1)
$1 = 1
(gdb) detach
Detaching from program: /bin/bash, process 15488
(gdb) quit
gknoy$ cat /tmp/wat.log
wat
wat
wat
0: http://stackoverflow.com/questions/593724/redirect-stderr-st...For those that don't know, linux behaves differently than other unix in that a thread blocked in recv() will remain blocked in recv if another thread closes the underlying socket.
AKA, the article works because GDB is interrupting the recv() call (or the socket was marked nonblocking), not because simply closing a socket wakes up a blocked recv() in linux.
Also useful would be a tool to close a TCP connection, regardless of the processes that have handles to it.
[EDIT]
These tools are a reasonable starting point.
http://linuxpoison.blogspot.co.uk/2008/10/tools-for-creating...
sudo tcpkill -9 -i eth0 host 1.2.3.4 and port 80
It is part of dsniff.http://killcx.sourceforge.net/
In particular, it sends a spoofed SYN packet to induce an ACK packet containing the sequence numbers necessary to send the RST. That means it doesn't rely on there being traffic already.
If a connection to httpd(8) is causing congestion on a network link, one
can drop the TCP session in charge:
# sockstat -c | grep httpd
www httpd 16525 3 tcp4 \
192.168.5.41:80 192.168.5.1:26747
The following command will drop the connection:
# tcpdrop 192.168.5.41 80 192.168.5.1 26747