diff --git a/internal/shorewall/convert.go b/internal/shorewall/convert.go index 4144de7..e9bc9ea 100644 --- a/internal/shorewall/convert.go +++ b/internal/shorewall/convert.go @@ -147,6 +147,10 @@ func convertConf(dir string, cfg *config.Config, params map[string]string, ipv6 slog.Warn("shorewall: per-address LOGLIMIT is not supported, limiting each log site globally", "loglimit", v) v = v[2:] } + if name, rest, ok := strings.Cut(v, ":"); ok && !strings.Contains(name, "/") { + slog.Warn("shorewall: named LOGLIMIT is not supported, dropping the name", "loglimit", conf["LOGLIMIT"]) + v = rest + } cfg.Settings.LogLimit = v } if v, ok := conf["IP_FORWARDING"]; ok { diff --git a/internal/shorewall/convert_test.go b/internal/shorewall/convert_test.go index fb447d6..5431b5a 100644 --- a/internal/shorewall/convert_test.go +++ b/internal/shorewall/convert_test.go @@ -759,9 +759,11 @@ func TestConvert_Dispositions(t *testing.T) { func TestConvert_LogLimit(t *testing.T) { for in, want := range map[string]string{ - `LOGLIMIT="s:1/sec:10"`: "1/sec:10", - `LOGLIMIT=2/min`: "2/min", - `LOGLIMIT=`: "", + `LOGLIMIT="s:1/sec:10"`: "1/sec:10", + `LOGLIMIT=2/min`: "2/min", + `LOGLIMIT=name:1/sec:5`: "1/sec:5", + `LOGLIMIT=s:name:1/sec:5`: "1/sec:5", + `LOGLIMIT=`: "", } { dir := minimalShorewallDir(t) writeFile(t, dir, "shorewall.conf", "LOG_LEVEL=info\n"+in+"\n")