Rate-limit log sites with LOGLIMIT #33
Reference in New Issue
Block a user
Delete Branch "benvin/loglimit"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Log sites have no rate limit, so a flood of dropped or logged traffic floods the journal. Shorewall caps this with LOGLIMIT, which migrate ignored.
log_limitsetting (rate/unit[:burst]); unset keeps logging every hits:/d:formsmark/ratelimitandloglogs every matching packet regardless of mark/user/time, and alogaction with extras leaves an unlogged no-op rule → copy the extras (everything between the log and the verdict) into the log rule too, or run limitLogs before applyRuleExtras and have the extras applied to both halves; drop ratelimit/connlimit/setmark from the log half (limiter/side-effect must not run twice); add a test with Mark + RateLimit + Log.[s:|d:][name:]rate/unit[:burst]); onlys:/d:is stripped, soname:1/sec:5(ors:name:...) is written to config and then rejected by thelogLimitRecheck at config/config.go:128, so migrate emits a config that fails to load → strip an optional leadingname:too (same as parseRateLimit does), or fall back with the same warning, and add a convert test for it.No findings.