// the find
cilium/pwru
Packet, where are you? -- eBPF-based Linux kernel networking debugger
pwru is Cilium's eBPF packet tracer for the Linux kernel — it attaches kprobes across kernel functions and shows exactly which functions a given packet (or a filtered subset matching a pcap expression) passes through, including where it gets dropped. It's for people debugging kernel-level networking problems: mystery packet drops, iptables/nftables rule interactions, container/CNI connectivity issues.
It traces skbs across the actual call path rather than a fixed set of hook points, so you see real causality instead of guessing which subsystem touched the packet. --filter-track-skb and --filter-track-skb-by-stackid handle the genuinely hard problem of following a packet identity through NAT, tunnel decapsulation, or bridging, where a naive tracer loses the skb pointer. Filtering uses standard pcap-filter syntax, so anyone who knows tcpdump can use it immediately. It ships static binaries, a Docker image, and k8s examples, so getting it onto a node you don't want to build on is low friction.
It needs root/privileged access plus specific kernel config (CONFIG_DEBUG_INFO_BTF, kprobes, fprobe for kprobe-multi) and kernel >= 5.3, so it's unusable on hardened or older kernels without intervention. Tracing broadly (--all-kmods, no --filter-func) on a busy host produces enormous volumes of output and can add real overhead — the tool leaves it to you to scope filters tightly rather than guiding you there. There's still no distro packaging (issue #89 has been open a long time), so every install is a binary download or a Docker run. And the output is raw kernel function names and stacks — useful if you already know the networking stack's internals, but there's no higher-level narrative for someone who doesn't recognize tcp_v4_rcv from nf_hook_slow.