On Mon, Jul 27, 2026 at 08:18:40AM +0200, Stefano Brivio wrote: > When ports are forwarded by exclusion, we might fail to bind all > privileged ports (typically lower than 1024), but that's actually > expected, and we shouldn't log warnings just because of that. > > Now, if those ports are automatically forwarded, and we have a > container binding some low ports, we'll log those warnings messages > every second, which is just unnecessary noise in the system log or > in log files. > > Use LOG_DEBUG as severity for those messages, instead of LOG_WARNING, > so that they are only printed when --debug is given: that should be > convenient enough to investigate things, while avoiding excess noise > during regular operations. > > There might be more sophisticated ways to limit this noise, but this > might be a significant regression in some setups, introduced by recent > changes in port forwarding handling, so I'm going for a somewhat > minimal fix for the moment, which can be improved later on if needed. > > Reported-by: frajo > Link: https://bugs.passt.top/show_bug.cgi?id=213 > Fixes: b223bec48213 ("fwd, tcp, udp: Set up listening sockets based on forward table") > Signed-off-by: Stefano Brivio Reviewed-by: David Gibson > --- > fwd.c | 21 +++++++++++++-------- > 1 file changed, 13 insertions(+), 8 deletions(-) > > diff --git a/fwd.c b/fwd.c > index 4ba0af3..5679a3d 100644 > --- a/fwd.c > +++ b/fwd.c > @@ -392,17 +392,22 @@ static int fwd_sync_one(const struct ctx *c, uint8_t pif, unsigned idx, > fd = pif_listen(c, rule->proto, pif, addr, ifname, port, idx); > if (fd < 0) { > char astr[INANY_ADDRSTRLEN]; > + int pri = LOG_WARNING; > > - warn("Listen failed for %s %s port %s%s%s/%u: %s", > - pif_name(pif), ipproto_name(rule->proto), > - inany_ntop(addr, astr, sizeof(astr)), > - ifname ? "%" : "", ifname ? ifname : "", > - port, strerror_(-fd)); > + if (rule->flags & FWD_WEAK) > + pri = LOG_DEBUG; > > - if (!(rule->flags & FWD_WEAK)) > - return -1; > + logmsg(true, false, pri, > + "Listen failed for %s %s port %s%s%s/%u: %s", > + pif_name(pif), ipproto_name(rule->proto), > + inany_ntop(addr, astr, sizeof(astr)), > + ifname ? "%" : "", ifname ? ifname : "", > + port, strerror_(-fd)); > > - continue; > + if (rule->flags & FWD_WEAK) > + continue; > + > + return -1; > } > > socks[port - rule->first] = fd; > -- > 2.43.0 > -- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson