Index | Thread | Search

From:
Claudio Jeker <cjeker@diehard.n-r-g.com>
Subject:
Re: [patch] wireguard floods dmesg
To:
Jay <mysidia@gmail.com>
Cc:
Lloyd <ng2d68@proton.me>, "tech@openbsd.org" <tech@openbsd.org>
Date:
Thu, 12 Dec 2024 21:11:20 +0100

Download raw body.

Thread
  • Claudio Jeker:

    [patch] wireguard floods dmesg

  • Stuart Henderson:

    [patch] wireguard floods dmesg

  • On Thu, Dec 12, 2024 at 12:50:30PM -0600, Jay wrote:
    > On Wed, Dec 11, 2024 at 9:55 PM Lloyd <ng2d68@proton.me> wrote:
    > 
    > > This didn't make sense, so I looked at the Linux implementation of Wireguard. Under Linux, the debugging messages contain more information such as IP addresses of the remote endpoint that triggered the error. It appears when Wireguard was ported to OpenBSD, these were intentionally removed.
    > >..
    > > Should this functionality be added/restored?
    > 
    > I would suggest that information be restored to the log messages.   It
    > seems to be an important feature that got lost (log message content
    > that could be analyzed for debugging or security monitoring purposes).
    > 
    > And also that there be global options rather than a per-link flag
    > establishing  a maximum count on identical log messages within a short
    > period of time.
    > 
    > More than a couple of this message per 30 seconds or so is not going
    > to be useful for a conceivable purpose,  especially without more
    > information, since the meaning/intent of what is being logged is too
    > vague/non-specific.
    > 
    > A simple flag on each link rather than an integer threshold does not
    > seem very suitable for choosing a verbosity level.   Ideally you would
    > go to syslog with a more detailed category and more detailed priority
    > for each log message,   and the user would decide through their syslog
    > filtering more precisely what verbosity they would like saved  or
    > printed to their console, or not displayed.
    > 
    
    The OpenBSD motto is shut up and hack. This is not complex work and people
    interested in this can provide diffs. Keep it small, keep it simple and it
    will get committed.
    
    -- 
    :wq Claudio
    
    
    
  • Claudio Jeker:

    [patch] wireguard floods dmesg

  • Stuart Henderson:

    [patch] wireguard floods dmesg