View previous topic :: View next topic |
Author |
Message |
depontius Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
Joined: 05 May 2004 Posts: 3529
|
Posted: Fri Feb 28, 2025 6:30 pm Post subject: port with no proc id |
|
|
When I run "netstat -tupln" I get an open tcp port with a proc/PID of "-". After a bit of poking around I find that that happens when something in the kernel opens a port. I've also used "unhide" with a range of options, and nothing gets un-hidden, so I'm presuming it really is a kernel port.
Is there a way to find out what in the kernel is listening on that port?
I'd like to know what it is, so I can either rest easy or un-configure that option in my next kernel build. _________________ .sigs waste space and bandwidth |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
pietinger Moderator
data:image/s3,"s3://crabby-images/67fe7/67fe7022571da1b5ce850ed2a7afbd02b66f2b1d" alt="Moderator Moderator"
Joined: 17 Oct 2006 Posts: 5450 Location: Bavaria
|
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
zen_desu Tux's lil' helper
data:image/s3,"s3://crabby-images/bc27a/bc27a0391196ce67cfff4c0ec96ac0b8f77d0350" alt="Tux's lil' helper Tux's lil' helper"
Joined: 25 Oct 2024 Posts: 143
|
Posted: Fri Feb 28, 2025 8:53 pm Post subject: Re: port with no proc id |
|
|
depontius wrote: | When I run "netstat -tupln" I get an open tcp port with a proc/PID of "-". After a bit of poking around I find that that happens when something in the kernel opens a port. I've also used "unhide" with a range of options, and nothing gets un-hidden, so I'm presuming it really is a kernel port.
Is there a way to find out what in the kernel is listening on that port?
I'd like to know what it is, so I can either rest easy or un-configure that option in my next kernel build. |
This can happen with things like wireguard tunnels, I think it not having an associated PID implies it's from the kernel. _________________ µgRD dev
Wiki writer |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
depontius Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
Joined: 05 May 2004 Posts: 3529
|
Posted: Fri Feb 28, 2025 8:54 pm Post subject: |
|
|
It's a high port, somewhere in the 30k range, not 32. I have CONFIG_DNS_RESOLVER=m in my config, not sure why I have even that. I just did an lsmod and see that it's loaded and being used by nfsv4, which I am running. Not sure what's up with that, but I have a direction to look now, at least. Thanks. I sure wish there were a simpler way to draw the lines here. _________________ .sigs waste space and bandwidth |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
zen_desu Tux's lil' helper
data:image/s3,"s3://crabby-images/bc27a/bc27a0391196ce67cfff4c0ec96ac0b8f77d0350" alt="Tux's lil' helper Tux's lil' helper"
Joined: 25 Oct 2024 Posts: 143
|
Posted: Fri Feb 28, 2025 8:56 pm Post subject: |
|
|
depontius wrote: | It's a high port, somewhere in the 30k range, not 32. I have CONFIG_DNS_RESOLVER=m in my config, not sure why I have even that. I just did an lsmod and see that it's loaded and being used by nfsv4, which I am running. Not sure what's up with that, but I have a direction to look now, at least. Thanks. I sure wish there were a simpler way to draw the lines here. |
I think this is similar to wireguard, where the client, in kernel, binds to a certain port for that service. I think this is especially helpful for UDP, but can work for TCP too. _________________ µgRD dev
Wiki writer |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
depontius Advocate
data:image/s3,"s3://crabby-images/0ef21/0ef2195d2dcf511779850b5ca76ca86afef01f52" alt="Advocate Advocate"
Joined: 05 May 2004 Posts: 3529
|
Posted: Fri Feb 28, 2025 9:35 pm Post subject: |
|
|
Incidentally, I don't have wireguard on this machine. I was aware of that possibility, but knew it didn't apply. However I do have the kernel DNS resolver and the module is indeed loaded. I guess I don't have to worry, though I'd like to understand this better in order to fully ease my mind. As I said earlier, it would be really nice to see a straight line drawn between the open port and something, even if it doesn't have a proc/PID. _________________ .sigs waste space and bandwidth |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
zen_desu Tux's lil' helper
data:image/s3,"s3://crabby-images/bc27a/bc27a0391196ce67cfff4c0ec96ac0b8f77d0350" alt="Tux's lil' helper Tux's lil' helper"
Joined: 25 Oct 2024 Posts: 143
|
Posted: Fri Feb 28, 2025 9:50 pm Post subject: |
|
|
depontius wrote: | Incidentally, I don't have wireguard on this machine. I was aware of that possibility, but knew it didn't apply. However I do have the kernel DNS resolver and the module is indeed loaded. I guess I don't have to worry, though I'd like to understand this better in order to fully ease my mind. As I said earlier, it would be really nice to see a straight line drawn between the open port and something, even if it doesn't have a proc/PID. |
I agree, I always have to remind myself of this trait when I see stuff like this because it's not immediately obvious. _________________ µgRD dev
Wiki writer |
|
Back to top |
|
data:image/s3,"s3://crabby-images/3f3c1/3f3c163004cf5e6def6cb2e97158912573e3151e" alt="" |
|