Rate-limit log sites with LOGLIMIT #33

Merged
benvin merged 3 commits from benvin/loglimit into main 2026-10-04 18:19:06 +11:00
Member

Log sites have no rate limit, so a flood of dropped or logged traffic floods the journal. Shorewall caps this with LOGLIMIT, which migrate ignored.

  • add log_limit setting (rate/unit[:burst]); unset keeps logging every hit
  • migrate LOGLIMIT, falling back to a global limit with a warning for per-address s:/d: forms
  • put a limit before every log; a logged rule with an action splits into a limited log rule plus the unlogged rule, as shorewall does
Log sites have no rate limit, so a flood of dropped or logged traffic floods the journal. Shorewall caps this with LOGLIMIT, which migrate ignored. - add `log_limit` setting (`rate/unit[:burst]`); unset keeps logging every hit - migrate LOGLIMIT, falling back to a global limit with a warning for per-address `s:`/`d:` forms - put a limit before every log; a logged rule with an action splits into a limited log rule plus the unlogged rule, as shorewall does
unkin-agent added 1 commit 2026-10-04 15:52:42 +11:00
Rate-limit log sites with shorewall LOGLIMIT
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
2e8d51759d
Author
Member
  • internal/nftables/compiler.go:89 — limitLogs splits at the log expr, but applyRuleExtras appends mark/user/time/ratelimit/connlimit/setmark AFTER the log, so the log-only rule drops them: a rule with mark/ratelimit and log logs every matching packet regardless of mark/user/time, and a log action with extras leaves an unlogged no-op rule → copy the extras (everything between the log and the verdict) into the log rule too, or run limitLogs before applyRuleExtras and have the extras applied to both halves; drop ratelimit/connlimit/setmark from the log half (limiter/side-effect must not run twice); add a test with Mark + RateLimit + Log.
  • internal/nftables/compiler_test.go:3158 — TestCompile_LogLimit covers no rule with extras (Mark/User/Time/RateLimit/ConnLimit), DNAT/SNAT logs or non-input chains → add cases so the above is caught.
- internal/nftables/compiler.go:89 — limitLogs splits at the log expr, but applyRuleExtras appends mark/user/time/ratelimit/connlimit/setmark AFTER the log, so the log-only rule drops them: a rule with `mark`/`ratelimit` and `log` logs every matching packet regardless of mark/user/time, and a `log` action with extras leaves an unlogged no-op rule → copy the extras (everything between the log and the verdict) into the log rule too, or run limitLogs before applyRuleExtras and have the extras applied to both halves; drop ratelimit/connlimit/setmark from the log half (limiter/side-effect must not run twice); add a test with Mark + RateLimit + Log. - internal/nftables/compiler_test.go:3158 — TestCompile_LogLimit covers no rule with extras (Mark/User/Time/RateLimit/ConnLimit), DNAT/SNAT logs or non-input chains → add cases so the above is caught.
unkin-agent added 1 commit 2026-10-04 15:56:25 +11:00
Keep rule match extras on the limited log rule
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
be391ed385
Author
Member
  • internal/shorewall/convert.go:145 — shorewall LOGLIMIT allows a name ([s:|d:][name:]rate/unit[:burst]); only s:/d: is stripped, so name:1/sec:5 (or s:name:...) is written to config and then rejected by the logLimitRe check at config/config.go:128, so migrate emits a config that fails to load → strip an optional leading name: too (same as parseRateLimit does), or fall back with the same warning, and add a convert test for it.
- internal/shorewall/convert.go:145 — shorewall LOGLIMIT allows a name (`[s:|d:][name:]rate/unit[:burst]`); only `s:`/`d:` is stripped, so `name:1/sec:5` (or `s:name:...`) is written to config and then rejected by the `logLimitRe` check at config/config.go:128, so migrate emits a config that fails to load → strip an optional leading `name:` too (same as parseRateLimit does), or fall back with the same warning, and add a convert test for it.
unkin-agent added 1 commit 2026-10-04 15:58:15 +11:00
Drop the name from named shorewall LOGLIMIT values
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
15ab32431d
Author
Member

No findings.

No findings.
benvin merged commit 2832dd0e7d into main 2026-10-04 18:19:06 +11:00
benvin deleted branch benvin/loglimit 2026-10-04 18:19:07 +11:00
Sign in to join this conversation.