* [PATCH] fwd: Don't log warnings when failing to bind "weak" ports, just debug messages
@ 2026-07-27 6:18 Stefano Brivio
2026-07-27 7:05 ` David Gibson
0 siblings, 1 reply; 2+ messages in thread
From: Stefano Brivio @ 2026-07-27 6:18 UTC (permalink / raw)
To: passt-dev; +Cc: David Gibson, frajo
When ports are forwarded by exclusion, we might fail to bind all
privileged ports (typically lower than 1024), but that's actually
expected, and we shouldn't log warnings just because of that.
Now, if those ports are automatically forwarded, and we have a
container binding some low ports, we'll log those warnings messages
every second, which is just unnecessary noise in the system log or
in log files.
Use LOG_DEBUG as severity for those messages, instead of LOG_WARNING,
so that they are only printed when --debug is given: that should be
convenient enough to investigate things, while avoiding excess noise
during regular operations.
There might be more sophisticated ways to limit this noise, but this
might be a significant regression in some setups, introduced by recent
changes in port forwarding handling, so I'm going for a somewhat
minimal fix for the moment, which can be improved later on if needed.
Reported-by: frajo <frajo@frajo.fi>
Link: https://bugs.passt.top/show_bug.cgi?id=213
Fixes: b223bec48213 ("fwd, tcp, udp: Set up listening sockets based on forward table")
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
---
fwd.c | 21 +++++++++++++--------
1 file changed, 13 insertions(+), 8 deletions(-)
diff --git a/fwd.c b/fwd.c
index 4ba0af3..5679a3d 100644
--- a/fwd.c
+++ b/fwd.c
@@ -392,17 +392,22 @@ static int fwd_sync_one(const struct ctx *c, uint8_t pif, unsigned idx,
fd = pif_listen(c, rule->proto, pif, addr, ifname, port, idx);
if (fd < 0) {
char astr[INANY_ADDRSTRLEN];
+ int pri = LOG_WARNING;
- warn("Listen failed for %s %s port %s%s%s/%u: %s",
- pif_name(pif), ipproto_name(rule->proto),
- inany_ntop(addr, astr, sizeof(astr)),
- ifname ? "%" : "", ifname ? ifname : "",
- port, strerror_(-fd));
+ if (rule->flags & FWD_WEAK)
+ pri = LOG_DEBUG;
- if (!(rule->flags & FWD_WEAK))
- return -1;
+ logmsg(true, false, pri,
+ "Listen failed for %s %s port %s%s%s/%u: %s",
+ pif_name(pif), ipproto_name(rule->proto),
+ inany_ntop(addr, astr, sizeof(astr)),
+ ifname ? "%" : "", ifname ? ifname : "",
+ port, strerror_(-fd));
- continue;
+ if (rule->flags & FWD_WEAK)
+ continue;
+
+ return -1;
}
socks[port - rule->first] = fd;
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] fwd: Don't log warnings when failing to bind "weak" ports, just debug messages
2026-07-27 6:18 [PATCH] fwd: Don't log warnings when failing to bind "weak" ports, just debug messages Stefano Brivio
@ 2026-07-27 7:05 ` David Gibson
0 siblings, 0 replies; 2+ messages in thread
From: David Gibson @ 2026-07-27 7:05 UTC (permalink / raw)
To: Stefano Brivio; +Cc: passt-dev, frajo
[-- Attachment #1: Type: text/plain, Size: 2819 bytes --]
On Mon, Jul 27, 2026 at 08:18:40AM +0200, Stefano Brivio wrote:
> When ports are forwarded by exclusion, we might fail to bind all
> privileged ports (typically lower than 1024), but that's actually
> expected, and we shouldn't log warnings just because of that.
>
> Now, if those ports are automatically forwarded, and we have a
> container binding some low ports, we'll log those warnings messages
> every second, which is just unnecessary noise in the system log or
> in log files.
>
> Use LOG_DEBUG as severity for those messages, instead of LOG_WARNING,
> so that they are only printed when --debug is given: that should be
> convenient enough to investigate things, while avoiding excess noise
> during regular operations.
>
> There might be more sophisticated ways to limit this noise, but this
> might be a significant regression in some setups, introduced by recent
> changes in port forwarding handling, so I'm going for a somewhat
> minimal fix for the moment, which can be improved later on if needed.
>
> Reported-by: frajo <frajo@frajo.fi>
> Link: https://bugs.passt.top/show_bug.cgi?id=213
> Fixes: b223bec48213 ("fwd, tcp, udp: Set up listening sockets based on forward table")
> Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Reviewed-by: David Gibson <david@gibson.dropbear.id.au>
> ---
> fwd.c | 21 +++++++++++++--------
> 1 file changed, 13 insertions(+), 8 deletions(-)
>
> diff --git a/fwd.c b/fwd.c
> index 4ba0af3..5679a3d 100644
> --- a/fwd.c
> +++ b/fwd.c
> @@ -392,17 +392,22 @@ static int fwd_sync_one(const struct ctx *c, uint8_t pif, unsigned idx,
> fd = pif_listen(c, rule->proto, pif, addr, ifname, port, idx);
> if (fd < 0) {
> char astr[INANY_ADDRSTRLEN];
> + int pri = LOG_WARNING;
>
> - warn("Listen failed for %s %s port %s%s%s/%u: %s",
> - pif_name(pif), ipproto_name(rule->proto),
> - inany_ntop(addr, astr, sizeof(astr)),
> - ifname ? "%" : "", ifname ? ifname : "",
> - port, strerror_(-fd));
> + if (rule->flags & FWD_WEAK)
> + pri = LOG_DEBUG;
>
> - if (!(rule->flags & FWD_WEAK))
> - return -1;
> + logmsg(true, false, pri,
> + "Listen failed for %s %s port %s%s%s/%u: %s",
> + pif_name(pif), ipproto_name(rule->proto),
> + inany_ntop(addr, astr, sizeof(astr)),
> + ifname ? "%" : "", ifname ? ifname : "",
> + port, strerror_(-fd));
>
> - continue;
> + if (rule->flags & FWD_WEAK)
> + continue;
> +
> + return -1;
> }
>
> socks[port - rule->first] = fd;
> --
> 2.43.0
>
--
David Gibson (he or they) | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you, not the other way
| around.
http://www.ozlabs.org/~dgibson
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-27 7:06 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-27 6:18 [PATCH] fwd: Don't log warnings when failing to bind "weak" ports, just debug messages Stefano Brivio
2026-07-27 7:05 ` David Gibson
Code repositories for project(s) associated with this public inbox
https://passt.top/passt
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).