Inspect and Dump a Devlink Dpipe Pipeline Safely
You will finish with a repeatable way to inspect a Linux device's devlink dataplane pipeline, dump a table, and enable or disable table counters when the driver supports them. The examples describe the devlink dpipe interface in iproute2 6.1.0, the version installed on this machine. Dpipe output is supplied by the hardware driver, so names and fields are device-specific.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell, the iproute2 package and a devlink device whose driver implements dpipe. The inspection commands are read-only. The table set example changes device state, may require elevated privileges, and can affect resource use. Do not run it on a production switch without checking the driver's documentation and maintenance impact.
1. Check the installed command
Start with ordinary, read-only checks. They need no sudo:
$ command -v devlink
/usr/sbin/devlink
$ devlink -V
devlink utility, iproute2-6.1.0
$ devlink dpipe help
Usage: devlink dpipe table show DEV [ name TABLE_NAME ]
devlink dpipe table set DEV name TABLE_NAME
[ counters_enabled { true | false } ]
devlink dpipe table dump DEV name TABLE_NAME
devlink dpipe header show DEV
The help output is a useful checkpoint. The command has four dpipe operations: show table attributes, set table attributes, dump table entries and show pipeline headers. The device argument is a devlink device identifier, not an ordinary network interface name in every case.
2. Find the devlink device identifier
List the devices before substituting a device into a dpipe command:
$ devlink dev show
On a host with a suitable driver, this prints device identifiers such as pci/0000:01:00.0. If it prints nothing, stop here: there is no device for this host and this workflow cannot produce table output. Do not invent a PCI address from a diagram or copy one from another machine.
Set a shell variable only after checking the list. Replace the value below with an identifier that actually appeared in your output:
DEV='pci/0000:01:00.0'
Checkpoint: run devlink dev show again and compare the exact spelling with $DEV. A typo gives a kernel error such as No such device; changing privilege will not create a missing device.
3. Show the pipeline headers
Ask the driver for the headers that describe its dataplane pipeline:
$ devlink dpipe header show "$DEV"
The output is driver-specific. It may include header names and fields used by the tables. Treat it as a description of the device's current dpipe model, not as a portable schema for another switch. The installed manual calls this operation header show; it takes the device but no table name.
If the command reports that the kernel does not support the operation, check the driver and kernel version before trying other syntax. The dpipe command cannot add dpipe support to a driver.
4. List the tables and inspect one
List every dpipe table exposed by the device:
$ devlink dpipe table show "$DEV"
Record one table name from that output. In the manual's example it is mlxsw_erif, but that name is not a default and will not be present on unrelated hardware. Put the real name in a variable:
TABLE='TABLE_NAME_FROM_DEVLINK_OUTPUT'
Now request just that table:
$ devlink dpipe table show "$DEV" name "$TABLE"
This is where the useful attributes normally appear, including the table's match fields and whether counters are enabled. The exact formatting and values belong to the driver. If the table name is rejected, copy it again from the unfiltered listing; do not assume a similar name is an alias.
5. Dump the table entries
Dump the entries for the table after you have identified it:
$ devlink dpipe table dump "$DEV" name "$TABLE"
The result is hardware state, not a fixed text format that this guide can reproduce. Save it for comparison if you are investigating forwarding behaviour:
$ devlink dpipe table dump "$DEV" name "$TABLE" > "${TABLE}.dpipe.txt"
$ test -s "${TABLE}.dpipe.txt" && printf '%s\n' 'dpipe dump captured'
The redirection creates or replaces the local file named after the table. Choose a new filename if an earlier capture matters. This does not change the device, but losing an old capture through shell redirection is irreversible unless you have another copy.
6. Change counters only when you mean to
The manual exposes one table attribute: counters_enabled. Enabling it may consume hardware resources or change what later dumps report. This is a state-changing operation, so take a capture first and check the maintenance procedure for the device:
$ sudo devlink dpipe table set "$DEV" name "$TABLE" counters_enabled true
Use elevated privileges only if the device policy requires them. If the unprivileged command is allowed, omit sudo. A successful command is normally quiet; verify the setting by showing the table again:
$ devlink dpipe table show "$DEV" name "$TABLE"
To undo this particular change, set the same attribute to false and verify again:
$ sudo devlink dpipe table set "$DEV" name "$TABLE" counters_enabled false
$ devlink dpipe table show "$DEV" name "$TABLE"
If the driver rejects the attribute, leave the device unchanged and use its documentation to determine whether counters are supported. Do not repeatedly toggle the setting as a diagnostic shortcut.
7. Separate syntax errors from device failures
Keep the operation shape in mind:
devlink dpipe table show DEVlists tables, while addingname TABLE_NAMEselects one.devlink dpipe table dump DEV name TABLE_NAMEreads entries; it does not enable counters.devlink dpipe header show DEVshows headers and does not select a table.devlink dpipe table set DEV name TABLE_NAME counters_enabled true|falsechanges an attribute and should be treated as privileged device administration.
For a failing command, rerun the read-only device and table listings first. Confirm that the device is present, the driver exposes dpipe, and the table name is exact. On this installation, querying a deliberately absent device returns a kernel No such device error and a non-zero status. That points to the identifier or hardware, not to a missing shell option.
Done means
devlink -Vreports the iproute2 version you expect.devlink dev showsupplied a real device identifier.header showand table listing completed, or the driver's lack of dpipe support is recorded.- You inspected a real table name before attempting a dump.
- Any counter change was deliberate, verified, and reverted with
falsewhen it was only a test.