From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=WhMRaUUt; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 959C05A0265 for ; Thu, 02 Apr 2026 17:10:18 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1775142617; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:autocrypt:autocrypt; bh=idOpZIHaMuq6Hg4Dj3wSoLqdJx32EwZYj8gcJJh7IBU=; b=WhMRaUUtv6s41QpGSP7oMTt8U+VA+PV2740AwWJSqG5Wt4rEs/ZJ+/NJQN1CYGCsLGUTiz M4zsO/UEW5n96MqCIMXN/AlSN6BjOjnxl5a7pG7+J7XZ3ZAaUEmZfGj4z8x6GVsOKi2rCt iUZNEBqQJFBrlY9dbm+MVgIbE4uKW+w= Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-222-mNB99IuBOnyooD9bg9pWYg-1; Thu, 02 Apr 2026 11:10:16 -0400 X-MC-Unique: mNB99IuBOnyooD9bg9pWYg-1 X-Mimecast-MFC-AGG-ID: mNB99IuBOnyooD9bg9pWYg_1775142615 Received: by mail-wr1-f71.google.com with SMTP id ffacd0b85a97d-43d15f2e0f4so939161f8f.0 for ; Thu, 02 Apr 2026 08:10:16 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775142615; x=1775747415; h=content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=idOpZIHaMuq6Hg4Dj3wSoLqdJx32EwZYj8gcJJh7IBU=; b=pYkUJAshVfDI9XwgTNzxIu4WtVvrb6QWk/QvO9vbm/n/Kj5+BGvSkBJWJdyXfX883Q 2hrlEh0pCV8RMZDK6bl4DfdxmTn1Nv9NjS5/ue8aMEZvg0flvZdjZXvjiLuG+uUrHRsh 0L8oBEYzFr2M0YsJvIr2TyWWTgyXjde8VubYJwvdp022TZ5aXnXL3/eLcpe/+cQuIPKl Kl/YyHvY0U4i4BGnbCPY+y+P/gzYW5BIK85H6z8yntuWxrgUwBOEH/lhdzTMvOyxCpTX WXUd/x4pJCesvlWYrQhVg/nswkSJP9Tkr92wLhIk6M1mE83DQDqD+0xVHM7Gca9EWnx6 aQmg== X-Forwarded-Encrypted: i=1; AJvYcCVcTG8LV9bKNF0bc02MCMilUzG1ObWoVtVEM87ujeRlHMgekqBURyxZ+U8yEnjHcZPmE3T6eb4auEs=@passt.top X-Gm-Message-State: AOJu0YxDFoRsiRhLU8kPvbeGu+RHiBsGaAQTZVfaMjxHCNW5GkM4fhji X4LilS36vNjSJjLLIuY9CRVXVAq8WyyO5ASexU0e6lJSSiXxc0MYEc110SKoStwNatRJ3Rr2OcJ BnykyGf9ey35k4qkNwx5tYmCxMb5Fl120sIK5lz2hvjGDwKJuqxSWZg== X-Gm-Gg: AeBDiesMCiR6m1oPUf8PgPSxffRejlhyg68lJ9pRgmH1d8za2cQDWvm05MTu1cIdwtW d7AQJYwoaiaSmkEBpU53XEX5JMwJyGzfwQvmjQyaHKwwsBLcjdor09iCtohmfp4nQ5URB2bTClb ZdvgIOR7Jy+5m0OLKOLut1SjlnSe8xg/qsQyAqz6ejiSo7PP60QUkkPSE1qs7wTuSMNDcr8Umfv tVjtUil/J8GCgU5Juy9sEgtAnJvAdhqDtgCYITRLW8JAq20LC2mTOKYxQfLoztBbeftTEOQ+GW/ Skptw8w7A6TmbGlb9o3RSZLhmM3EAZpBF7xiAPgrkmt6cMfbdWP4uaMUVKSGxUigLsfecod1C65 hgU6tkhFGHM1OSs2VnRrLfhgBlMixEvayT5rwmKijfIY/BoEpBthQ1LQ= X-Received: by 2002:a05:6000:268a:b0:439:b3ff:9ab9 with SMTP id ffacd0b85a97d-43d150f756cmr15220783f8f.48.1775142614873; Thu, 02 Apr 2026 08:10:14 -0700 (PDT) X-Received: by 2002:a05:6000:268a:b0:439:b3ff:9ab9 with SMTP id ffacd0b85a97d-43d150f756cmr15220688f8f.48.1775142614253; Thu, 02 Apr 2026 08:10:14 -0700 (PDT) Received: from [192.168.100.100] (82-64-211-94.subs.proxad.net. [82.64.211.94]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43d1e4d2738sm8471263f8f.24.2026.04.02.08.10.13 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 02 Apr 2026 08:10:13 -0700 (PDT) Message-ID: Date: Thu, 2 Apr 2026 17:10:12 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v1 2/2] tap, tcp, udp: Use rate-limited logging To: Anshu Kumari , sbrivio@redhat.com, passt-dev@passt.top References: <20260401182910.669164-1-anskuma@redhat.com> From: Laurent Vivier Autocrypt: addr=lvivier@redhat.com; keydata= xsFNBFYFJhkBEAC2me7w2+RizYOKZM+vZCx69GTewOwqzHrrHSG07MUAxJ6AY29/+HYf6EY2 WoeuLWDmXE7A3oJoIsRecD6BXHTb0OYS20lS608anr3B0xn5g0BX7es9Mw+hV/pL+63EOCVm SUVTEQwbGQN62guOKnJJJfphbbv82glIC/Ei4Ky8BwZkUuXd7d5NFJKC9/GDrbWdj75cDNQx UZ9XXbXEKY9MHX83Uy7JFoiFDMOVHn55HnncflUncO0zDzY7CxFeQFwYRbsCXOUL9yBtqLer Ky8/yjBskIlNrp0uQSt9LMoMsdSjYLYhvk1StsNPg74+s4u0Q6z45+l8RAsgLw5OLtTa+ePM JyS7OIGNYxAX6eZk1+91a6tnqfyPcMbduxyBaYXn94HUG162BeuyBkbNoIDkB7pCByed1A7q q9/FbuTDwgVGVLYthYSfTtN0Y60OgNkWCMtFwKxRaXt1WFA5ceqinN/XkgA+vf2Ch72zBkJL RBIhfOPFv5f2Hkkj0MvsUXpOWaOjatiu0fpPo6Hw14UEpywke1zN4NKubApQOlNKZZC4hu6/ 8pv2t4HRi7s0K88jQYBRPObjrN5+owtI51xMaYzvPitHQ2053LmgsOdN9EKOqZeHAYG2SmRW LOxYWKX14YkZI5j/TXfKlTpwSMvXho+efN4kgFvFmP6WT+tPnwARAQABzSNMYXVyZW50IFZp dmllciA8bHZpdmllckByZWRoYXQuY29tPsLBeAQTAQIAIgUCVgVQgAIbAwYLCQgHAwIGFQgC CQoLBBYCAwECHgECF4AACgkQ8ww4vT8vvjwpgg//fSGy0Rs/t8cPFuzoY1cex4limJQfReLr SJXCANg9NOWy/bFK5wunj+h/RCFxIFhZcyXveurkBwYikDPUrBoBRoOJY/BHK0iZo7/WQkur 6H5losVZtrotmKOGnP/lJYZ3H6OWvXzdz8LL5hb3TvGOP68K8Bn8UsIaZJoeiKhaNR0sOJyI YYbgFQPWMHfVwHD/U+/gqRhD7apVysxv5by/pKDln1I5v0cRRH6hd8M8oXgKhF2+rAOL7gvh jEHSSWKUlMjC7YwwjSZmUkL+TQyE18e2XBk85X8Da3FznrLiHZFHQ/NzETYxRjnOzD7/kOVy gKD/o7asyWQVU65mh/ECrtjfhtCBSYmIIVkopoLaVJ/kEbVJQegT2P6NgERC/31kmTF69vn8 uQyW11Hk8tyubicByL3/XVBrq4jZdJW3cePNJbTNaT0d/bjMg5zCWHbMErUib2Nellnbg6bc 2HLDe0NLVPuRZhHUHM9hO/JNnHfvgiRQDh6loNOUnm9Iw2YiVgZNnT4soUehMZ7au8PwSl4I KYE4ulJ8RRiydN7fES3IZWmOPlyskp1QMQBD/w16o+lEtY6HSFEzsK3o0vuBRBVp2WKnssVH qeeV01ZHw0bvWKjxVNOksP98eJfWLfV9l9e7s6TaAeySKRRubtJ+21PRuYAxKsaueBfUE7ZT 7zfOwU0EVgUmGQEQALxSQRbl/QOnmssVDxWhHM5TGxl7oLNJms2zmBpcmlrIsn8nNz0rRyxT 460k2niaTwowSRK8KWVDeAW6ZAaWiYjLlTunoKwvF8vP3JyWpBz0diTxL5o+xpvy/Q6YU3BN efdq8Vy3rFsxgW7mMSrI/CxJ667y8ot5DVugeS2NyHfmZlPGE0Nsy7hlebS4liisXOrN3jFz asKyUws3VXek4V65lHwB23BVzsnFMn/bw/rPliqXGcwl8CoJu8dSyrCcd1Ibs0/Inq9S9+t0 VmWiQWfQkz4rvEeTQkp/VfgZ6z98JRW7S6l6eophoWs0/ZyRfOm+QVSqRfFZdxdP2PlGeIFM C3fXJgygXJkFPyWkVElr76JTbtSHsGWbt6xUlYHKXWo+xf9WgtLeby3cfSkEchACrxDrQpj+ Jt/JFP+q997dybkyZ5IoHWuPkn7uZGBrKIHmBunTco1+cKSuRiSCYpBIXZMHCzPgVDjk4viP brV9NwRkmaOxVvye0vctJeWvJ6KA7NoAURplIGCqkCRwg0MmLrfoZnK/gRqVJ/f6adhU1oo6 z4p2/z3PemA0C0ANatgHgBb90cd16AUxpdEQmOCmdNnNJF/3Zt3inzF+NFzHoM5Vwq6rc1JP jfC3oqRLJzqAEHBDjQFlqNR3IFCIAo4SYQRBdAHBCzkM4rWyRhuVABEBAAHCwV8EGAECAAkF AlYFJhkCGwwACgkQ8ww4vT8vvjwg9w//VQrcnVg3TsjEybxDEUBm8dBmnKqcnTBFmxN5FFtI WlEuY8+YMiWRykd8Ln9RJ/98/ghABHz9TN8TRo2b6WimV64FmlVn17Ri6FgFU3xNt9TTEChq AcNg88eYryKsYpFwegGpwUlaUaaGh1m9OrTzcQy+klVfZWaVJ9Nw0keoGRGb8j4XjVpL8+2x OhXKrM1fzzb8JtAuSbuzZSQPDwQEI5CKKxp7zf76J21YeRrEW4WDznPyVcDTa+tz++q2S/Bp P4W98bXCBIuQgs2m+OflERv5c3Ojldp04/S4NEjXEYRWdiCxN7ca5iPml5gLtuvhJMSy36gl U6IW9kn30IWuSoBpTkgV7rLUEhh9Ms82VWW/h2TxL8enfx40PrfbDtWwqRID3WY8jLrjKfTd R3LW8BnUDNkG+c4FzvvGUs8AvuqxxyHbXAfDx9o/jXfPHVRmJVhSmd+hC3mcQ+4iX5bBPBPM oDqSoLt5w9GoQQ6gDVP2ZjTWqwSRMLzNr37rJjZ1pt0DCMMTbiYIUcrhX8eveCJtY7NGWNyx FCRkhxRuGcpwPmRVDwOl39MB3iTsRighiMnijkbLXiKoJ5CDVvX5yicNqYJPKh5MFXN1bvsB kmYiStMRbrD0HoY1kx5/VozBtc70OU0EB8Wrv9hZD+Ofp0T3KOr1RUHvCZoLURfFhSQ= In-Reply-To: <20260401182910.669164-1-anskuma@redhat.com> X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: o1P-J_w8kATYdBDiHrtO9T24KKttx7JRby1Uh01fa8Y_1775142615 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Message-ID-Hash: UGQKZAAIOPOTLXC6FHJAMKGHW4M4C4DC X-Message-ID-Hash: UGQKZAAIOPOTLXC6FHJAMKGHW4M4C4DC X-MailFrom: lvivier@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: david@gibson.dropbear.id.au X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On 4/1/26 20:29, Anshu Kumari wrote: > Now that rate-limited logging macros are available, promote several > debug messages to higher severity levels. These messages were > previously kept at debug to prevent guests from flooding host > logs, but with rate limiting they can safely be made visible in > normal operation. > > In tap.c, refactor tap4_is_fragment() to use warn_ratelimit() instead > of its ad-hoc rate limiting, and promote the guest MAC address change > message to info level. > > In tcp.c, promote the invalid TCP SYN endpoint message to warn level. > > In udp.c and udp_flow.c, promote flow allocation failures and dropped > datagram messages to warn level, and rate-limit the unrecoverable > socket error message. > > Link: https://bugs.passt.top/show_bug.cgi?id=134 > Signed-off-by: Anshu Kumari As the patch 1/2 is already merged, you don't need to number this one 2/2. > --- > > - Inside udp.c > - David: should this be changed to warn_ratelimit? I am not sure about it > debug("%s error on UDP socket %i: %s", > str_ee_origin(ee), s, strerror_(ee->ee_errno)); > > --- > tap.c | 14 ++++---------- > tcp.c | 2 +- > udp.c | 6 +++--- > udp_flow.c | 4 ++-- > 4 files changed, 10 insertions(+), 16 deletions(-) > > diff --git a/tap.c b/tap.c > index 1049e02..f569b61 100644 > --- a/tap.c > +++ b/tap.c > @@ -686,17 +686,11 @@ static bool tap4_is_fragment(const struct iphdr *iph, > const struct timespec *now) > { > if (ntohs(iph->frag_off) & ~IP_DF) { > - /* Ratelimit messages */ > - static time_t last_message; > static unsigned num_dropped; > > num_dropped++; > - if (now->tv_sec - last_message > FRAGMENT_MSG_RATE) { the #define FRAGMENT_MSG_RATE can be removed from the file as it is unused now. > - warn("Can't process IPv4 fragments (%u dropped)", > - num_dropped); > - last_message = now->tv_sec; > - num_dropped = 0; > - } > + warn_ratelimit(now, "Can't process IPv4 fragments (%u dropped)", > + num_dropped); I don't think we should keep the num_dropped value here as it is never reset, the "suppressed %u similar messages" will give the information. > return true; > } > return false; > @@ -1115,8 +1109,8 @@ void tap_add_packet(struct ctx *c, struct iov_tail *data, > char bufmac[ETH_ADDRSTRLEN]; > > memcpy(c->guest_mac, eh->h_source, ETH_ALEN); > - debug("New guest MAC address observed: %s", > - eth_ntop(c->guest_mac, bufmac, sizeof(bufmac))); > + info_ratelimit(now, "New guest MAC address observed: %s", > + eth_ntop(c->guest_mac, bufmac, sizeof(bufmac))); > proto_update_l2_buf(c->guest_mac); > } > > diff --git a/tcp.c b/tcp.c > index 8ea9be8..3d3b80d 100644 > --- a/tcp.c > +++ b/tcp.c > @@ -1688,7 +1688,7 @@ static void tcp_conn_from_tap(const struct ctx *c, sa_family_t af, > !inany_is_unicast(&ini->oaddr) || ini->oport == 0) { > char sstr[INANY_ADDRSTRLEN], dstr[INANY_ADDRSTRLEN]; > > - debug("Invalid endpoint in TCP SYN: %s:%hu -> %s:%hu", > + warn_ratelimit(now, "Invalid endpoint in TCP SYN: %s:%hu -> %s:%hu", > inany_ntop(&ini->eaddr, sstr, sizeof(sstr)), ini->eport, > inany_ntop(&ini->oaddr, dstr, sizeof(dstr)), ini->oport); You must align 'inany..." with the new place of '(' of warn_ratelimit > goto cancel; > diff --git a/udp.c b/udp.c > index 1fc5a42..1ef5e7a 100644 > --- a/udp.c > +++ b/udp.c > @@ -871,7 +871,7 @@ void udp_sock_fwd(const struct ctx *c, int s, int rule_hint, > /* Clear errors & carry on */ > if (udp_sock_errs(c, s, FLOW_SIDX_NONE, > frompif, port) < 0) { > - err( > + err_ratelimit(now, > "UDP: Unrecoverable error on listening socket: (%s port %hu)", > pif_name(frompif), port); > /* FIXME: what now? close/re-open socket? */ > @@ -898,7 +898,7 @@ void udp_sock_fwd(const struct ctx *c, int s, int rule_hint, > pif_name(frompif), pif_name(topif)); > discard = true; > } else { > - debug("Discarding datagram without flow"); > + warn_ratelimit(now, "Discarding datagram without flow"); > discard = true; > } > > @@ -1042,7 +1042,7 @@ int udp_tap_handler(const struct ctx *c, uint8_t pif, > if (!(uflow = udp_at_sidx(tosidx))) { > char sstr[INET6_ADDRSTRLEN], dstr[INET6_ADDRSTRLEN]; > > - debug("Dropping datagram with no flow %s %s:%hu -> %s:%hu", > + warn_ratelimit(now, "Dropping datagram with no flow %s %s:%hu -> %s:%hu", > pif_name(pif), > inet_ntop(af, saddr, sstr, sizeof(sstr)), src, > inet_ntop(af, daddr, dstr, sizeof(dstr)), dst); > diff --git a/udp_flow.c b/udp_flow.c > index 7e2453e..9343b4b 100644 > --- a/udp_flow.c > +++ b/udp_flow.c > @@ -235,7 +235,7 @@ flow_sidx_t udp_flow_from_sock(const struct ctx *c, uint8_t pif, > if (!(flow = flow_alloc())) { > char sastr[SOCKADDR_STRLEN]; > > - debug("Couldn't allocate flow for UDP datagram from %s %s", > + warn_ratelimit(now, "Couldn't allocate flow for UDP datagram from %s %s", > pif_name(pif), sockaddr_ntop(s_in, sastr, sizeof(sastr))); > return FLOW_SIDX_NONE; > } > @@ -292,7 +292,7 @@ flow_sidx_t udp_flow_from_tap(const struct ctx *c, > if (!(flow = flow_alloc())) { > char sstr[INET6_ADDRSTRLEN], dstr[INET6_ADDRSTRLEN]; > > - debug("Couldn't allocate flow for UDP datagram from %s %s:%hu -> %s:%hu", > + warn_ratelimit(now, "Couldn't allocate flow for UDP datagram from %s %s:%hu -> %s:%hu", > pif_name(pif), > inet_ntop(af, saddr, sstr, sizeof(sstr)), srcport, > inet_ntop(af, daddr, dstr, sizeof(dstr)), dstport); Thanks, Laurent