All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Moore <paul@paul-moore.com>
To: "Christian Göttsche" <cgoettsche@seltendoof.de>
Cc: "Christian Göttsche" <cgzones@googlemail.com>,
	"Stephen Smalley" <stephen.smalley.work@gmail.com>,
	"Ondrej Mosnacek" <omosnace@redhat.com>,
	"Thiébaud Weksteen" <tweek@google.com>,
	"Bram Bonné" <brambonne@google.com>,
	"Casey Schaufler" <casey@schaufler-ca.com>,
	"GUO Zihua" <guozihua@huawei.com>,
	"Canfeng Guo" <guocanfeng@uniontech.com>,
	selinux@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH RFC 4/6] selinux: improve network lookup failure warnings
Date: Fri, 11 Apr 2025 16:29:36 -0400	[thread overview]
Message-ID: <7ed70f417b10ae1510dbbea501da892c@paul-moore.com> (raw)
In-Reply-To: <20250318083422.21489-3-cgoettsche@seltendoof.de>

On Mar 18, 2025 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
> 
> Rate limit the warnings and include additional available information.
> 
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> ---
>  security/selinux/netif.c   | 8 ++++----
>  security/selinux/netnode.c | 4 ++--
>  security/selinux/netport.c | 4 ++--
>  3 files changed, 8 insertions(+), 8 deletions(-)

How many of these messages were you seeing that rate limiting was a
concern?  Also, what were you doing that was causing this?

> diff --git a/security/selinux/netif.c b/security/selinux/netif.c
> index 43a0d3594b72..38fdba1e64bf 100644
> --- a/security/selinux/netif.c
> +++ b/security/selinux/netif.c
> @@ -141,8 +141,8 @@ static int sel_netif_sid_slow(struct net *ns, int ifindex, u32 *sid)
>  
>  	dev = dev_get_by_index(ns, ifindex);
>  	if (unlikely(dev == NULL)) {
> -		pr_warn("SELinux: failure in %s(), invalid network interface (%d)\n",
> -			__func__, ifindex);
> +		pr_warn_ratelimited("SELinux: failure in %s(), invalid network interface (%d)\n",
> +				    __func__, ifindex);
>  		return -ENOENT;
>  	}
>  
> @@ -169,8 +169,8 @@ static int sel_netif_sid_slow(struct net *ns, int ifindex, u32 *sid)
>  	spin_unlock_bh(&sel_netif_lock);
>  	dev_put(dev);
>  	if (unlikely(ret))
> -		pr_warn("SELinux: failure in %s(), unable to determine network interface label (%d)\n",
> -			__func__, ifindex);
> +		pr_warn_ratelimited("SELinux: failure in %s(), unable to determine network interface label (%d):  %d\n",
> +				    __func__, ifindex, ret);
>  	return ret;
>  }
>  
> diff --git a/security/selinux/netnode.c b/security/selinux/netnode.c
> index 8bb456d80dd5..76cf531af110 100644
> --- a/security/selinux/netnode.c
> +++ b/security/selinux/netnode.c
> @@ -228,8 +228,8 @@ static int sel_netnode_sid_slow(const void *addr, u16 family, u32 *sid)
>  
>  	spin_unlock_bh(&sel_netnode_lock);
>  	if (unlikely(ret))
> -		pr_warn("SELinux: failure in %s(), unable to determine network node label\n",
> -			__func__);
> +		pr_warn_ratelimited("SELinux: failure in %s(), unable to determine network node label (%d):  %d\n",
> +				    __func__, family, ret);
>  	return ret;
>  }
>  
> diff --git a/security/selinux/netport.c b/security/selinux/netport.c
> index 7d2207384d40..dadf14984fb4 100644
> --- a/security/selinux/netport.c
> +++ b/security/selinux/netport.c
> @@ -162,8 +162,8 @@ static int sel_netport_sid_slow(u8 protocol, u16 pnum, u32 *sid)
>  out:
>  	spin_unlock_bh(&sel_netport_lock);
>  	if (unlikely(ret))
> -		pr_warn("SELinux: failure in %s(), unable to determine network port label\n",
> -			__func__);
> +		pr_warn_ratelimited("SELinux: failure in %s(), unable to determine network port label (%d:%d):  %d\n",
> +				    __func__, protocol, pnum, ret);
>  	return ret;
>  }
>  
> -- 
> 2.49.0

--
paul-moore.com

  reply	other threads:[~2025-04-11 20:29 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-18  8:33 [RFC PATCH 2/6] selinux: contify network namespace pointer Christian Göttsche
2025-03-18  8:33 ` [RFC PATCH 3/6] selinux: add likely hints for fast paths Christian Göttsche
2025-04-11 20:29   ` [PATCH RFC " Paul Moore
2025-03-18  8:33 ` [RFC PATCH 4/6] selinux: improve network lookup failure warnings Christian Göttsche
2025-04-11 20:29   ` Paul Moore [this message]
2025-04-15 14:28     ` [PATCH RFC " Christian Göttsche
2025-05-20 21:09   ` Paul Moore
2025-03-18  8:33 ` [RFC PATCH 5/6] selinux: unify OOM handling in network hashtables Christian Göttsche
2025-04-11 20:29   ` [PATCH RFC " Paul Moore
2025-03-18  8:33 ` [RFC PATCH 6/6] selinux: add cache stats for network tables Christian Göttsche
2025-03-18  8:33 ` [RFC PATCH 1/6] selinux: constify network address pointer Christian Göttsche
2025-04-11 20:29   ` [PATCH RFC " Paul Moore
2025-04-11 20:29 ` [PATCH RFC 2/6] selinux: contify network namespace pointer Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7ed70f417b10ae1510dbbea501da892c@paul-moore.com \
    --to=paul@paul-moore.com \
    --cc=brambonne@google.com \
    --cc=casey@schaufler-ca.com \
    --cc=cgoettsche@seltendoof.de \
    --cc=cgzones@googlemail.com \
    --cc=guocanfeng@uniontech.com \
    --cc=guozihua@huawei.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=omosnace@redhat.com \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    --cc=tweek@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.