Re: [PATCH] tcp provider: support tcp:::accept-established in absence of skb

Alan Maguire <[email protected]>
Newsgroups dev.linux.lists.dtrace
Message-ID <[email protected]>
On 26/08/2025 23:23, Eugene Loh wrote:
> I might be doing something wrong, but the tests in question still fail
> for me -- largely unchanged -- even with the patch.
> 5.4.17-2136.346.6.el8uek.x86_64
> 5.4.17-2136.346.6.el8uek.aarch64
>

Hmm, did you have both

https://lore.kernel.org/dtrace/[email protected]/T/#t

"[PATCH] cg: fix offset for > 8 bit bitfields in dt_cg_ctf_offsetof()"

and

https://lore.kernel.org/dtrace/[email protected]/T/#t

"[PATCH] tcp provider: use __ip_queue_xmit() as it is non-static on 5.4"

...applied? The cg patch doesn't mention tcp in the title but it is
needed as it fixes the offset from where we look up the sk->sk_protocol;
without that state-change probes won't fire.

Thanks for testing!

Alan

> On 8/26/25 09:12, Alan Maguire wrote:
>> On a 5.4 kernel, the function we instrument for tcp:::accept-established
>> (tcp_init_transfer()) does not have a struct sk_buff * as argument;
>> that does not appear until 5.10.  As a result we need to fake up
>> the IP and TCP headers from the TCP socket.  We can reuse existing
>> code (ensuring to mark accept-established correctly as an _INBOUND
>> probe) once we fix up references in ip.d to be arg6 and not arg7 (this
>> parameter is used to mark a probe point as inbound, outbound or as a
>> state change).  We need to ensure that args[2] is translated from
>> a __dtrace_tcp_void_ip_t * to get this to work for the IP header.
>>
>> For the TCP header we need a similar solution; add a
>> __dtrace_tcp_void_tcp_t type and translate from either the tcp heade
>> passed in (if non-null) or use arg3 (the socket) to fill out the TCP
>> header info.  We can get the ports, seq/ack and because we know that
>> only accept-established is used we know the flags will just be an
>> ACK.
>>
>> With this in place (along with previous fixes for the TCP provider)
>> the TCP state-related tests finally pass on a 5.4 kernel.
>>
>> Reported-by: Eugene Loh <[email protected]>
>> Signed-off-by: Alan Maguire <[email protected]>
>> ---
>>   dlibs/aarch64/5.11/ip.d  | 12 +++---
>>   dlibs/aarch64/5.11/tcp.d | 34 +++++++++++++++-
>>   dlibs/aarch64/5.12/ip.d  | 12 +++---
>>   dlibs/aarch64/5.12/tcp.d | 34 +++++++++++++++-
>>   dlibs/aarch64/5.14/ip.d  | 12 +++---
>>   dlibs/aarch64/5.14/tcp.d | 34 +++++++++++++++-
>>   dlibs/aarch64/5.16/ip.d  | 12 +++---
>>   dlibs/aarch64/5.16/tcp.d | 34 +++++++++++++++-
>>   dlibs/aarch64/5.2/ip.d   | 12 +++---
>>   dlibs/aarch64/5.2/tcp.d  | 34 +++++++++++++++-
>>   dlibs/aarch64/5.6/ip.d   | 12 +++---
>>   dlibs/aarch64/5.6/tcp.d  | 34 +++++++++++++++-
>>   dlibs/aarch64/6.1/ip.d   | 12 +++---
>>   dlibs/aarch64/6.1/tcp.d  | 34 +++++++++++++++-
>>   dlibs/aarch64/6.10/ip.d  | 12 +++---
>>   dlibs/aarch64/6.10/tcp.d | 34 +++++++++++++++-
>>   dlibs/x86_64/5.11/ip.d   | 12 +++---
>>   dlibs/x86_64/5.11/tcp.d  | 34 +++++++++++++++-
>>   dlibs/x86_64/5.12/ip.d   | 12 +++---
>>   dlibs/x86_64/5.12/tcp.d  | 34 +++++++++++++++-
>>   dlibs/x86_64/5.14/ip.d   | 12 +++---
>>   dlibs/x86_64/5.14/tcp.d  | 34 +++++++++++++++-
>>   dlibs/x86_64/5.16/ip.d   | 12 +++---
>>   dlibs/x86_64/5.16/tcp.d  | 34 +++++++++++++++-
>>   dlibs/x86_64/5.2/ip.d    | 12 +++---
>>   dlibs/x86_64/5.2/tcp.d   | 34 +++++++++++++++-
>>   dlibs/x86_64/5.6/ip.d    | 12 +++---
>>   dlibs/x86_64/5.6/tcp.d   | 34 +++++++++++++++-
>>   dlibs/x86_64/6.1/ip.d    | 12 +++---
>>   dlibs/x86_64/6.1/tcp.d   | 34 +++++++++++++++-
>>   dlibs/x86_64/6.10/ip.d   | 12 +++---
>>   dlibs/x86_64/6.10/tcp.d  | 34 +++++++++++++++-
>>   libdtrace/dt_prov_tcp.c  | 85 ++++++++++++++++++++++++----------------
>>   libdtrace/ip.d           | 12 +++---
>>   libdtrace/tcp.d          | 34 +++++++++++++++-
>>   35 files changed, 698 insertions(+), 169 deletions(-)
>>
>> diff --git a/dlibs/aarch64/5.11/ip.d b/dlibs/aarch64/5.11/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.11/ip.d
>> +++ b/dlibs/aarch64/5.11/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.11/tcp.d b/dlibs/aarch64/5.11/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.11/tcp.d
>> +++ b/dlibs/aarch64/5.11/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/5.12/ip.d b/dlibs/aarch64/5.12/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.12/ip.d
>> +++ b/dlibs/aarch64/5.12/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.12/tcp.d b/dlibs/aarch64/5.12/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.12/tcp.d
>> +++ b/dlibs/aarch64/5.12/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/5.14/ip.d b/dlibs/aarch64/5.14/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.14/ip.d
>> +++ b/dlibs/aarch64/5.14/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.14/tcp.d b/dlibs/aarch64/5.14/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.14/tcp.d
>> +++ b/dlibs/aarch64/5.14/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/5.16/ip.d b/dlibs/aarch64/5.16/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.16/ip.d
>> +++ b/dlibs/aarch64/5.16/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.16/tcp.d b/dlibs/aarch64/5.16/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.16/tcp.d
>> +++ b/dlibs/aarch64/5.16/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/5.2/ip.d b/dlibs/aarch64/5.2/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.2/ip.d
>> +++ b/dlibs/aarch64/5.2/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.2/tcp.d b/dlibs/aarch64/5.2/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.2/tcp.d
>> +++ b/dlibs/aarch64/5.2/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/5.6/ip.d b/dlibs/aarch64/5.6/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/5.6/ip.d
>> +++ b/dlibs/aarch64/5.6/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/5.6/tcp.d b/dlibs/aarch64/5.6/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/5.6/tcp.d
>> +++ b/dlibs/aarch64/5.6/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/6.1/ip.d b/dlibs/aarch64/6.1/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/6.1/ip.d
>> +++ b/dlibs/aarch64/6.1/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/6.1/tcp.d b/dlibs/aarch64/6.1/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/6.1/tcp.d
>> +++ b/dlibs/aarch64/6.1/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/aarch64/6.10/ip.d b/dlibs/aarch64/6.10/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/aarch64/6.10/ip.d
>> +++ b/dlibs/aarch64/6.10/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/aarch64/6.10/tcp.d b/dlibs/aarch64/6.10/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/aarch64/6.10/tcp.d
>> +++ b/dlibs/aarch64/6.10/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.11/ip.d b/dlibs/x86_64/5.11/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.11/ip.d
>> +++ b/dlibs/x86_64/5.11/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.11/tcp.d b/dlibs/x86_64/5.11/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.11/tcp.d
>> +++ b/dlibs/x86_64/5.11/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.12/ip.d b/dlibs/x86_64/5.12/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.12/ip.d
>> +++ b/dlibs/x86_64/5.12/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.12/tcp.d b/dlibs/x86_64/5.12/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.12/tcp.d
>> +++ b/dlibs/x86_64/5.12/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.14/ip.d b/dlibs/x86_64/5.14/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.14/ip.d
>> +++ b/dlibs/x86_64/5.14/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.14/tcp.d b/dlibs/x86_64/5.14/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.14/tcp.d
>> +++ b/dlibs/x86_64/5.14/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.16/ip.d b/dlibs/x86_64/5.16/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.16/ip.d
>> +++ b/dlibs/x86_64/5.16/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.16/tcp.d b/dlibs/x86_64/5.16/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.16/tcp.d
>> +++ b/dlibs/x86_64/5.16/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.2/ip.d b/dlibs/x86_64/5.2/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.2/ip.d
>> +++ b/dlibs/x86_64/5.2/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.2/tcp.d b/dlibs/x86_64/5.2/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.2/tcp.d
>> +++ b/dlibs/x86_64/5.2/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/5.6/ip.d b/dlibs/x86_64/5.6/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/5.6/ip.d
>> +++ b/dlibs/x86_64/5.6/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/5.6/tcp.d b/dlibs/x86_64/5.6/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/5.6/tcp.d
>> +++ b/dlibs/x86_64/5.6/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/6.1/ip.d b/dlibs/x86_64/6.1/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/6.1/ip.d
>> +++ b/dlibs/x86_64/6.1/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/6.1/tcp.d b/dlibs/x86_64/6.1/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/6.1/tcp.d
>> +++ b/dlibs/x86_64/6.1/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/dlibs/x86_64/6.10/ip.d b/dlibs/x86_64/6.10/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/dlibs/x86_64/6.10/ip.d
>> +++ b/dlibs/x86_64/6.10/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/dlibs/x86_64/6.10/tcp.d b/dlibs/x86_64/6.10/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/dlibs/x86_64/6.10/tcp.d
>> +++ b/dlibs/x86_64/6.10/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
>> diff --git a/libdtrace/dt_prov_tcp.c b/libdtrace/dt_prov_tcp.c
>> index a191efe1..44ed2bc9 100644
>> --- a/libdtrace/dt_prov_tcp.c
>> +++ b/libdtrace/dt_prov_tcp.c
>> @@ -72,9 +72,9 @@ static probe_dep_t    probes[] = {
>>   static probe_arg_t probe_args[] = {
>>       { "accept-established", 0, { 0, 0, "struct sk_buff *",
>> "pktinfo_t *" } },
>>       { "accept-established", 1, { 1, 0, "struct sock *", "csinfo_t
>> *" } },
>> -    { "accept-established", 2, { 2, 0, "void_ip_t *", "ipinfo_t *" } },
>> +    { "accept-established", 2, { 2, 0, "__dtrace_tcp_void_ip_t *",
>> "ipinfo_t *" } },
>>       { "accept-established", 3, { 3, 0, "struct tcp_sock *",
>> "tcpsinfo_t *" } },
>> -    { "accept-established", 4, { 4, 0, "struct tcphdr *", "tcpinfo_t
>> *" } },
>> +    { "accept-established", 4, { 4, 0, "__dtrace_tcp_void_tcp_t *",
>> "tcpinfo_t *" } },
>>       { "accept-established", 5, { 5, 0, "void", "void" } },
>>         { "accept-refused", 0, { 0, 0, "struct sk_buff *", "pktinfo_t
>> *" } },
>> @@ -166,8 +166,11 @@ static int trampoline(dt_pcb_t *pcb, uint_t exitlbl)
>>       dt_probe_t    *uprp = pcb->pcb_parent_probe;
>>       int        direction, have_iphdr;
>>       int        skarg = 0, skbarg = 1, tcparg = 0;
>> -    int        skarg_maybe_null;
>> +    int        skarg_maybe_null, have_skb = 1;
>>       int        skstate = 0;
>> +    dtrace_typeinfo_t sym;
>> +    ctf_funcinfo_t    fi;
>> +    int        rc;
>>         /*
>>        * We construct the tcp::: probe arguments as follows:
>> @@ -258,11 +261,24 @@ static int trampoline(dt_pcb_t *pcb, uint_t
>> exitlbl)
>>       }
>>         if (strcmp(prp->desc->prb, "accept-established") == 0) {
>> -        direction = NET_PROBE_OUTBOUND;
>> +        direction = NET_PROBE_INBOUND;
>>           have_iphdr = 1;
>> -        /* skb in arg2 not arg1 */
>> -        skbarg = 2;
>> -        skarg_maybe_null = 0;
>> +        /* on older (5.4) kernels, tcp_init_transfer() only has 2
>> +         * args, i.e. no struct skb * third argument.
>> +          */
>> +        rc = dtrace_lookup_by_type(dtp, DTRACE_OBJ_EVERY,
>> +                       uprp->desc->fun, &sym);
>> +        if (rc == 0 &&
>> +            ctf_type_kind(sym.dtt_ctfp, sym.dtt_type) ==
>> CTF_K_FUNCTION &&
>> +            ctf_func_type_info(sym.dtt_ctfp, sym.dtt_type, &fi) == 0 &&
>> +            fi.ctc_argc > 2) {
>> +            /* skb in arg2 not arg1 */
>> +            skbarg = 2;
>> +            skarg_maybe_null = 0;
>> +        } else {
>> +            have_skb = 0;
>> +            have_iphdr = 0;
>> +        }
>>           /* ensure arg1 is BPF_SOCK_OPS_PASSIVE_ESTABLISHED_CB */
>>           emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(1)));
>>           emit(dlp, BPF_BRANCH_IMM(BPF_JNE, BPF_REG_6,
>> @@ -289,10 +305,6 @@ static int trampoline(dt_pcb_t *pcb, uint_t exitlbl)
>>       } else {
>>           direction = NET_PROBE_OUTBOUND;
>>           if (strcmp(uprp->desc->fun, "ip_send_unicast_reply") == 0) {
>> -            dtrace_typeinfo_t    sym;
>> -            ctf_funcinfo_t        fi;
>> -            int rc;
>> -
>>               /* Newer kernels pass the original socket as second
>>                * arg to ip_send_unicast_reply(); if that function
>>                * has an extra (> 9) argument we know we have to
>> @@ -344,10 +356,14 @@ static int trampoline(dt_pcb_t *pcb, uint_t
>> exitlbl)
>>           emit(dlp, BPF_BRANCH_IMM(BPF_JEQ, BPF_REG_6, 0, exitlbl));
>>       emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(3), BPF_REG_6));
>>   -    /* then save skb to args[0] */
>> -    emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(skbarg)));
>> -    emit(dlp, BPF_BRANCH_IMM(BPF_JEQ, BPF_REG_6, 0, exitlbl));
>> -    emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(0), BPF_REG_6));
>> +    if (have_skb) {
>> +        /* then save skb to args[0] */
>> +        emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7,
>> DMST_ARG(skbarg)));
>> +        emit(dlp, BPF_BRANCH_IMM(BPF_JEQ, BPF_REG_6, 0, exitlbl));
>> +        emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(0), BPF_REG_6));
>> +    } else {
>> +        emit(dlp, BPF_STORE_IMM(BPF_DW, BPF_REG_7, DMST_ARG(0), 0));
>> +    }
>>         /* next save sk to args[1] now that we have skb in args[0] */
>>       emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(3)));
>> @@ -358,34 +374,37 @@ static int trampoline(dt_pcb_t *pcb, uint_t
>> exitlbl)
>>        *    skb_network_header(skb)    =    (include/linux/ip.h)
>>        *    skb->head + skb->network_header    (include/linux/skbuff.h)
>>        */
>> -    emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(0)));
>> -    dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6, "head");
>> -    if (have_iphdr)
>> +    if (have_skb && have_iphdr) {
>> +        emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(0)));
>> +        dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> "head");
>>           emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(2),
>> BPF_REG_0));
>> -    else
>> -        emit(dlp, BPF_STORE_IMM(BPF_DW, BPF_REG_7, DMST_ARG(2), 0));
>> -
>> -    if (have_iphdr) {
>>           dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> -                 "network_header");
>> +                       "network_header");
>>           emit(dlp, BPF_XADD_REG(BPF_DW, BPF_REG_7, DMST_ARG(2),
>> BPF_REG_0));
>> +    } else {
>> +        emit(dlp, BPF_STORE_IMM(BPF_DW, BPF_REG_7, DMST_ARG(2), 0));
>>       }
>> +
>>       /*
>>        * tcp_hdr(skb) =
>>        *    skb_transport_header(skb) =        (include/linux/ip.h)
>>        *    skb->head + skb->transport_header    (include/linux/skbuff.h)
>>        */
>> -    emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7, DMST_ARG(tcparg)));
>> -    if (tcparg) {
>> -        /* struct ip_reply_arg * has a kvec containing the tcp header */
>> -        dt_cg_tramp_get_member(pcb, "struct kvec", BPF_REG_6,
>> "iov_base");
>> -        emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(4), BPF_REG_0));
>> +    if (have_skb) {
>> +        emit(dlp, BPF_LOAD(BPF_DW, BPF_REG_6, BPF_REG_7,
>> DMST_ARG(tcparg)));
>> +        if (tcparg) {
>> +            /* struct ip_reply_arg * has a kvec containing the tcp
>> header */
>> +            dt_cg_tramp_get_member(pcb, "struct kvec", BPF_REG_6,
>> "iov_base");
>> +            emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(4),
>> BPF_REG_0));
>> +        } else {
>> +            dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> "head");
>> +            emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(4),
>> BPF_REG_0));
>> +            dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> +                     "transport_header");
>> +            emit(dlp, BPF_XADD_REG(BPF_DW, BPF_REG_7, DMST_ARG(4),
>> BPF_REG_0));
>> +        }
>>       } else {
>> -        dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> "head");
>> -        emit(dlp, BPF_STORE(BPF_DW, BPF_REG_7, DMST_ARG(4), BPF_REG_0));
>> -        dt_cg_tramp_get_member(pcb, "struct sk_buff", BPF_REG_6,
>> -                 "transport_header");
>> -        emit(dlp, BPF_XADD_REG(BPF_DW, BPF_REG_7, DMST_ARG(4),
>> BPF_REG_0));
>> +        emit(dlp, BPF_STORE_IMM(BPF_DW, BPF_REG_7, DMST_ARG(4), 0));
>>       }
>>         if (!skarg_maybe_null) {
>> diff --git a/libdtrace/ip.d b/libdtrace/ip.d
>> index 493b75a0..95520b4a 100644
>> --- a/libdtrace/ip.d
>> +++ b/libdtrace/ip.d
>> @@ -170,8 +170,8 @@ translator ipinfo_t < void_ip_t *I > {
>>    * In some cases where the ipinfo_t * is NULL we wish to construct
>> IP info
>>    * using the struct tcp_sock * (arg3).  In order to map local IP to
>> source
>>    * or destination IP address appropriately we need to check if the
>> associated
>> - * data is inbound (NET_PROBE_INBOUND in arg7) or outbound
>> (NET_PROBE_OUTBOUND);
>> - * the value is stored in arg7.  If inbound, we map the local IP
>> address to
>> + * data is inbound (NET_PROBE_INBOUND in arg6) or outbound
>> (NET_PROBE_OUTBOUND);
>> + * the value is stored in arg6.  If inbound, we map the local IP
>> address to
>>    * ip_daddr (destination), and if outbound it is mapped to ip_saddr.
>>    */
>>   #pragma D binding "1.5" translator
>> @@ -214,12 +214,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family == AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr) :
>>           "<unknown>";
>> @@ -229,12 +229,12 @@ translator ipinfo_t < __dtrace_tcp_void_ip_t *I > {
>>           inet_ntoa6(&((struct ipv6hdr *)I)->daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET ?
>> -        inet_ntoa(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_daddr) :
>>           arg3 != NULL &&
>>           ((struct sock *)arg3)->__sk_common.skc_family== AF_INET6 ?
>> -        inet_ntoa6(arg7 == NET_PROBE_INBOUND ?
>> +        inet_ntoa6(arg6 == NET_PROBE_INBOUND ?
>>           &((struct sock *)arg3)->__sk_common.skc_v6_rcv_saddr :
>>           &((struct sock *)arg3)->__sk_common.skc_v6_daddr) :
>>           "<unknown>";
>> diff --git a/libdtrace/tcp.d b/libdtrace/tcp.d
>> index 48d9adb4..8f87aa57 100644
>> --- a/libdtrace/tcp.d
>> +++ b/libdtrace/tcp.d
>> @@ -172,14 +172,14 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>           (T && ((struct inet_sock *)T)->inet_sport == 0) ?
>>           ((struct sock *)T)->__sk_common.skc_num :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->dest :
>>             ((struct tcphdr *)arg4)->source) :
>>           0;
>>       tcps_rport = T && ((struct sock *)T)->__sk_common.skc_dport != 0 ?
>>           ntohs(((struct sock *)T)->__sk_common.skc_dport) :
>>           arg4 != NULL ?
>> -        ntohs(arg7 == NET_PROBE_INBOUND ?
>> +        ntohs(arg6 == NET_PROBE_INBOUND ?
>>             ((struct tcphdr *)arg4)->source :
>>             ((struct tcphdr *)arg4)->dest) :
>>           0;
>> @@ -242,3 +242,33 @@ translator tcpsinfo_t < struct tcp_sock *T > {
>>   translator tcplsinfo_t < int I > {
>>       tcps_state = arg3 ? ((struct sock *)arg3)-
>> >__sk_common.skc_state : 0;
>>   };
>> +
>> +/* Use struct tcp_sock * to fill out tcp header info where we do not
>> have
>> + * an sk_buff with struct tcphdr * available; currently only used for
>> + * the tcp:::accept-established case where the struct sk_buff * is not
>> + * available on < 5.10 kernels.
>> + */
>> +typedef void * __dtrace_tcp_void_tcp_t;
>> +
>> +#pragma D binding "1.6.3" translator
>> +translator tcpinfo_t < __dtrace_tcp_void_tcp_t *T > {
>> +    tcp_sport = T ? ntohs(((struct tcphdr *)T)->source) :
>> +            arg3 ? ((struct sock *)arg3)->__sk_common.skc_dport :
>> +            0;
>> +    tcp_dport = T ? ntohs(((struct tcphdr *)T)->dest) :
>> +            arg3 ? ntohs(((struct inet_sock *)arg3)->inet_sport) :
>> +            0;
>> +    tcp_seq = T ? ntohl(((struct tcphdr *)T)->seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->rcv_nxt :
>> +          0;
>> +    tcp_ack = T ? ntohl(((struct tcphdr *)T)->ack_seq) :
>> +          arg3 ? ((struct tcp_sock *)arg3)->snd_nxt :
>> +          0;
>> +    tcp_offset = T ? (*(uint8_t *)(T + 12) & 0xf0) >> 2 : 0;
>> +    tcp_flags = T ? *((uint8_t *)T + 13) : TH_ACK;
>> +    tcp_window = T ? ntohs(((struct tcphdr *)T)->window) :
>> +             arg3 ? ((struct tcp_sock *)arg3)->rcv_wnd :
>> +             0;
>> +    tcp_checksum = T ? ntohs(((struct tcphdr *)T)->check) : 0;
>> +    tcp_hdr = (uintptr_t)T;
>> +};
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.