netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH net-next] tcp: rate limit synflood warnings further
@ 2018-09-09 23:12 Willem de Bruijn
  2018-09-10  7:52 ` Eric Dumazet
  2018-09-12  6:35 ` David Miller
  0 siblings, 2 replies; 4+ messages in thread
From: Willem de Bruijn @ 2018-09-09 23:12 UTC (permalink / raw)
  To: netdev; +Cc: davem, eric.dumazet, Willem de Bruijn

From: Willem de Bruijn <willemb@google.com>

Convert pr_info to net_info_ratelimited to limit the total number of
synflood warnings.

Commit 946cedccbd73 ("tcp: Change possible SYN flooding messages")
rate limits synflood warnings to one per listener.

Workloads that open many listener sockets can still see a high rate of
log messages. Syzkaller is one frequent example.

Signed-off-by: Willem de Bruijn <willemb@google.com>
---
 net/ipv4/tcp_input.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c
index 62508a2f9b21..d9034073138c 100644
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -6380,8 +6380,8 @@ static bool tcp_syn_flood_action(const struct sock *sk,
 	if (!queue->synflood_warned &&
 	    net->ipv4.sysctl_tcp_syncookies != 2 &&
 	    xchg(&queue->synflood_warned, 1) == 0)
-		pr_info("%s: Possible SYN flooding on port %d. %s.  Check SNMP counters.\n",
-			proto, ntohs(tcp_hdr(skb)->dest), msg);
+		net_info_ratelimited("%s: Possible SYN flooding on port %d. %s.  Check SNMP counters.\n",
+				     proto, ntohs(tcp_hdr(skb)->dest), msg);
 
 	return want_cookie;
 }
-- 
2.19.0.rc2.392.g5ba43deb5a-goog

^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] tcp: rate limit synflood warnings further
  2018-09-09 23:12 [PATCH net-next] tcp: rate limit synflood warnings further Willem de Bruijn
@ 2018-09-10  7:52 ` Eric Dumazet
  2018-09-12  6:35 ` David Miller
  1 sibling, 0 replies; 4+ messages in thread
From: Eric Dumazet @ 2018-09-10  7:52 UTC (permalink / raw)
  To: Willem de Bruijn, netdev; +Cc: davem, eric.dumazet, Willem de Bruijn



On 09/09/2018 04:12 PM, Willem de Bruijn wrote:
> From: Willem de Bruijn <willemb@google.com>
> 
> Convert pr_info to net_info_ratelimited to limit the total number of
> synflood warnings.
> 
> Commit 946cedccbd73 ("tcp: Change possible SYN flooding messages")
> rate limits synflood warnings to one per listener.
> 
> Workloads that open many listener sockets can still see a high rate of
> log messages. Syzkaller is one frequent example.
> 
> Signed-off-by: Willem de Bruijn <willemb@google.com>

Thanks Willem

Signed-off-by: Eric Dumazet <edumazet@google.com>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] tcp: rate limit synflood warnings further
  2018-09-09 23:12 [PATCH net-next] tcp: rate limit synflood warnings further Willem de Bruijn
  2018-09-10  7:52 ` Eric Dumazet
@ 2018-09-12  6:35 ` David Miller
  2018-09-12 13:39   ` Willem de Bruijn
  1 sibling, 1 reply; 4+ messages in thread
From: David Miller @ 2018-09-12  6:35 UTC (permalink / raw)
  To: willemdebruijn.kernel; +Cc: netdev, eric.dumazet, willemb

From: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
Date: Sun,  9 Sep 2018 19:12:12 -0400

> From: Willem de Bruijn <willemb@google.com>
> 
> Convert pr_info to net_info_ratelimited to limit the total number of
> synflood warnings.
> 
> Commit 946cedccbd73 ("tcp: Change possible SYN flooding messages")
> rate limits synflood warnings to one per listener.
> 
> Workloads that open many listener sockets can still see a high rate of
> log messages. Syzkaller is one frequent example.
> 
> Signed-off-by: Willem de Bruijn <willemb@google.com>

Applied, thanks Willem.

Is this stable material?

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] tcp: rate limit synflood warnings further
  2018-09-12  6:35 ` David Miller
@ 2018-09-12 13:39   ` Willem de Bruijn
  0 siblings, 0 replies; 4+ messages in thread
From: Willem de Bruijn @ 2018-09-12 13:39 UTC (permalink / raw)
  To: David Miller; +Cc: Network Development, Eric Dumazet, Willem de Bruijn

On Wed, Sep 12, 2018 at 2:35 AM David Miller <davem@davemloft.net> wrote:
>
> From: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
> Date: Sun,  9 Sep 2018 19:12:12 -0400
>
> > From: Willem de Bruijn <willemb@google.com>
> >
> > Convert pr_info to net_info_ratelimited to limit the total number of
> > synflood warnings.
> >
> > Commit 946cedccbd73 ("tcp: Change possible SYN flooding messages")
> > rate limits synflood warnings to one per listener.
> >
> > Workloads that open many listener sockets can still see a high rate of
> > log messages. Syzkaller is one frequent example.
> >
> > Signed-off-by: Willem de Bruijn <willemb@google.com>
>
> Applied, thanks Willem.
>
> Is this stable material?

Thanks. Probably not. A process has to keep opening new listeners
at high rate while under load. I've only seen syzkaller do that.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-09-12 18:44 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-09-09 23:12 [PATCH net-next] tcp: rate limit synflood warnings further Willem de Bruijn
2018-09-10  7:52 ` Eric Dumazet
2018-09-12  6:35 ` David Miller
2018-09-12 13:39   ` Willem de Bruijn

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).