From mboxrd@z Thu Jan 1 00:00:00 1970 Received: by passt.top (Postfix, from userid 1000) id DB4495A026D; Mon, 27 Jul 2026 08:18:40 +0200 (CEST) From: Stefano Brivio To: passt-dev@passt.top Subject: [PATCH] fwd: Don't log warnings when failing to bind "weak" ports, just debug messages Date: Mon, 27 Jul 2026 08:18:40 +0200 Message-ID: <20260727061840.1840487-1-sbrivio@redhat.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID-Hash: 4FZ3YHTODDLYDUIFG5C2MNDIOZLMNHWO X-Message-ID-Hash: 4FZ3YHTODDLYDUIFG5C2MNDIOZLMNHWO X-MailFrom: sbrivio@passt.top X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: David Gibson , frajo@frajo.fi X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: When ports are forwarded by exclusion, we might fail to bind all privileged ports (typically lower than 1024), but that's actually expected, and we shouldn't log warnings just because of that. Now, if those ports are automatically forwarded, and we have a container binding some low ports, we'll log those warnings messages every second, which is just unnecessary noise in the system log or in log files. Use LOG_DEBUG as severity for those messages, instead of LOG_WARNING, so that they are only printed when --debug is given: that should be convenient enough to investigate things, while avoiding excess noise during regular operations. There might be more sophisticated ways to limit this noise, but this might be a significant regression in some setups, introduced by recent changes in port forwarding handling, so I'm going for a somewhat minimal fix for the moment, which can be improved later on if needed. Reported-by: frajo Link: https://bugs.passt.top/show_bug.cgi?id=213 Fixes: b223bec48213 ("fwd, tcp, udp: Set up listening sockets based on forward table") Signed-off-by: Stefano Brivio --- fwd.c | 21 +++++++++++++-------- 1 file changed, 13 insertions(+), 8 deletions(-) diff --git a/fwd.c b/fwd.c index 4ba0af3..5679a3d 100644 --- a/fwd.c +++ b/fwd.c @@ -392,17 +392,22 @@ static int fwd_sync_one(const struct ctx *c, uint8_t pif, unsigned idx, fd = pif_listen(c, rule->proto, pif, addr, ifname, port, idx); if (fd < 0) { char astr[INANY_ADDRSTRLEN]; + int pri = LOG_WARNING; - warn("Listen failed for %s %s port %s%s%s/%u: %s", - pif_name(pif), ipproto_name(rule->proto), - inany_ntop(addr, astr, sizeof(astr)), - ifname ? "%" : "", ifname ? ifname : "", - port, strerror_(-fd)); + if (rule->flags & FWD_WEAK) + pri = LOG_DEBUG; - if (!(rule->flags & FWD_WEAK)) - return -1; + logmsg(true, false, pri, + "Listen failed for %s %s port %s%s%s/%u: %s", + pif_name(pif), ipproto_name(rule->proto), + inany_ntop(addr, astr, sizeof(astr)), + ifname ? "%" : "", ifname ? ifname : "", + port, strerror_(-fd)); - continue; + if (rule->flags & FWD_WEAK) + continue; + + return -1; } socks[port - rule->first] = fd; -- 2.43.0