From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f42.google.com (mail-qv1-f42.google.com [209.85.219.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E5855299944 for ; Thu, 20 Nov 2025 09:26:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.42 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763630811; cv=none; b=LZ7Trpz8XrBtZ5QU+p/DOI+fgzDkC8sFB1Gs/YHUaOMg+wDILnMUAlkrzFzhh9hXIOWq3fvgGhAS2X51c9W70FccPyx0Eyit1fbPvxukpS0YdbyFK3S93M9tiM+3vIxvcevxUPPafgik/FfvdsZyWmmj6/uXMJclO6WHC5Cau/E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1763630811; c=relaxed/simple; bh=FGbe2QJ35IWC87sUETNWg6RlVC1TZZq96naSHX+aXm0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=rT7iQvW9ofIhB8vAztReYpRP9l2dWl4+9uFlsIzwXO0zNSrSjDAB3yYZ8VBz0kZl2uf9mK7glS/JpQgYxwTsC08OBrKJkMl+4hT0Fdz0T3AUIqz7hVUr+fqfMzOeU7qFrtTJGQi89RDc7cb+8dIWAQDLKCHkNEGkF5tWWFYocl0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nqvvyLJD; arc=none smtp.client-ip=209.85.219.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nqvvyLJD" Received: by mail-qv1-f42.google.com with SMTP id 6a1803df08f44-8804f1bd6a7so5754816d6.2 for ; Thu, 20 Nov 2025 01:26:49 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1763630809; x=1764235609; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=5rNfEEw4vHnSGPrrOqGBlUEcYjNEIn+vm1yCxi49VeY=; b=nqvvyLJDLW0qQ5AVPBd5aPNl6w+dvbzoam2rRdhW/5YMaM30PkjHOn3r46xXjXcnDn TXdNSiEIANVJhEuwCHEee2VNw77kTiSy7snpP3paqh+acUZga0ZHr5ZpJcB9Xc4l1+ef I5b38RJjxb1giKsZvCcUB2qXeT78Zq+EqvU1RUuzam7x30BjDY0eGp/o9QADxqYSZ5lQ BZEGaVNCxu6Rz5IOe1FQW4vRFMNIYsy32rynCsjfo5QVziAn86sltsVEzYJq4XnDGRN3 MWGu5k3lYJeJ97jmW99MPQQl8tPOeDCLGRMSvUgnBLixhBlJVx8cUlkK46YXXHpDr3y6 4dhQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1763630809; x=1764235609; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=5rNfEEw4vHnSGPrrOqGBlUEcYjNEIn+vm1yCxi49VeY=; b=hMYF9yajhq6k+QT1mbjriR9RaQiR4KzepQuFkOwv8xg1VWVs9eyMFBX9j7slNKgSyE EGN7oH/PW3IxL3s0+8hrwuHsdelLDFu9FF5uDpBRtekPVhMl3Stt3HzGWWIUEHkY0q3t oLT8s2JyfFByfPAPN4O+tpnOZmpLtyqvmoixYNkvIIozbqCRYxKqfSh8YjDRU0exNAUM QlzAOHD4tlJZhyxelmD5+3mxI3FL46szasnh5jTs0tG1i3MKdI7j0Ijc3wu4oDh5MNo2 sK+mayTRs7q84dhVkwtErQUO9EhvYgoOuJUnnGFHHvsaiMYVw5YxIi1sOURmrpPpiK6h 6Rog== X-Forwarded-Encrypted: i=1; AJvYcCXkKUU8xUdAbQ85avW+Lorr9in9vVPs8MM2dCY5ih5yqb0Z8HaS2bc6lsHADb/18zzO4W+Ho88pk4APlyk=@vger.kernel.org X-Gm-Message-State: AOJu0YySOGHwkH3Mbp+um7/MVjAdlJC9Cw8/0z9eLn+kyPWaSA5J9Ltm wYyacBP/+FebgC8B+VxZTYxnRunVbtyMsFD4GJPx4sqfGVlIGgqMUgzc X-Gm-Gg: ASbGncsz6Tv5fNFJZx/QX0zATaQx/D+Nc0EcUbFwHdENFYEFFcogK5XBzUwBiEuKDzD i6WL5o+UyKc8LhUFmV++vDLt9ZN0apHHeo2bgAukpy+ocgHUeQzqU9ZqWJtUFkOFm1USbF+mkOF 06b9ZAaH/u6MHqEBFYkGAeJFDut2J1z/RbPwa1ZjYf2yOQpkD3fWDpDktgLjeaWYI85anBRPs6U y/N/j23S99xOv/kcqlkclvZEGtcF1+HndlDYJjeZ9F57yJgLIiMkPsfEAjr04c9GIR2pUY26JaV n93VyrbuMTy39prNqGJZcg1MgOcMOZehRP12y/v9SANQLt2uyJcysACp0Oa8ao1db4qVIEeKe1f gq0fEMHLarWBSrKaVliOBGvDTOPz1bYpKKD9G4W157bH0+C7wkiF1ekVtvomnOEBZfhIq7k6hq+ yZtbh4lvT5qEtIMQf+EVOhPEByFKPSQSTPFUXmeZD2qA== X-Google-Smtp-Source: AGHT+IErijzjvVB6QHM2SddkkZKIVjIoxlhrkbOqhzMQX/h3ZCJn9AHYFiv/1s4Xuegx61VoNALOKw== X-Received: by 2002:a05:6214:4903:b0:880:5279:98e9 with SMTP id 6a1803df08f44-8846e131c85mr33483786d6.40.1763630808772; Thu, 20 Nov 2025 01:26:48 -0800 (PST) Received: from daniel-desktop3.localnet ([204.48.92.24]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-8846e54c9b9sm13611896d6.28.2025.11.20.01.26.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Nov 2025 01:26:48 -0800 (PST) From: Daniel Tang To: Nicolas Bouchinet , Xiu Jianfeng , Paul Moore , Xiujianfeng Cc: linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, Nathan Lynch , Matthew Garrett , Kees Cook , David Howells , James Morris Subject: Re: [PATCH v2] lockdown: Only log restrictions once Date: Thu, 20 Nov 2025 04:26:45 -0500 Message-ID: <7645139.4DdEvYhyI6@daniel-desktop3> In-Reply-To: <2f4a1af8-adc6-4cbc-813f-4cc8e9bc75ae@huaweicloud.com> References: <3641397.L58v44csPz@daniel-desktop3> <1961790.USuA9gRusQ@daniel-desktop3> <2f4a1af8-adc6-4cbc-813f-4cc8e9bc75ae@huaweicloud.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On Thursday, 20 November 2025, 02:37:56 EST Xiujianfeng wrote: > Is it possible to adjust the printk_ratelimit & printk_ratelimit_burst > in /proc/sys/kernel/ to reduce the logs in your scenario? It's not working. Watching the console after setting the sysctl and repeatedly clicking org.freedesktop.login1.Manager.CanSuspend in qdbusviewer (simulating what the lockscreen does), I see: ```console root@daniel-desktop3:~# uname -a Linux daniel-desktop3 6.17.0-6-generic #6-Ubuntu SMP PREEMPT_DYNAMIC Tue Oc= t 7 13:34:17 UTC 2025 x86_64 GNU/Linux root@daniel-desktop3:~# sysctl kernel.printk_ratelimit_burst=3D1 kernel.printk_ratelimit_burst =3D 1 root@daniel-desktop3:~# sysctl kernel.printk_ratelimit=3D999999 kernel.printk_ratelimit =3D 999999 root@daniel-desktop3:~# dmesg -W [14385.334698] lockdown_is_locked_down: 3 callbacks suppressed [14385.334701] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14385.614738] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14385.878857] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14386.166744] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14386.454771] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14386.750900] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14387.038795] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14387.334770] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14387.622696] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14387.926763] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14390.366582] lockdown_is_locked_down: 7 callbacks suppressed [14390.366585] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14390.798744] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14391.118802] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14391.422728] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14391.742754] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14392.046735] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14392.350745] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14392.654992] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14392.974797] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 [14393.270741] Lockdown: systemd-logind: hibernation is restricted; see man= kernel_lockdown.7 ``` At my desk, I lock my screen every 5 hours. In public, I might lock my screen every 1 minute, 5 minute, or 15 *minutes*. printk_ratelimit seems to be targeted towards things that happen every N *seconds*. > logs here serve a purpose similar to auditing. Based on this, I think > this change will meaningfully degrade the quality of the logs, making it > hard for users to find out what happens when lockdown is active=EF=BC=8C > especially after a long time running. =46or v3 in December, I'm thinking of adding a code path to special-case *reads* from /sys/power/state. What do you think?