[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v4 2/2] xen/console: add compile-time rate-limiting controls


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: dmukhin@xxxxxxxx
  • Date: Wed, 29 Jul 2026 00:25:20 -0700
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 148.163.138.245) smtp.rcpttodomain=lists.xenproject.org smtp.mailfrom=ford.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=ford.com; dkim=pass (signature was verified) header.d=saarlouis.ford.com; dkim=pass (signature was verified) header.d=ford.com; arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ahUdlfdxd+A3zLj5zNn6SxYqIoT62B9ILeo4nkM51SQ=; b=Bz/ZvkZmlHCoGGQpOuh4AmzRWS08tsIjqSzWwlzSzUKNVEU8EF2wnKOMwRUv/qP/QrlRttqA8tXyEUsfDZ1b5yHF5a9cXT4ZaimEXwcHqTpCXJ0pPvJOaQhm8wqAJ4C8Af8QN62Y7i0NaMekiaw05V6GBXGv+5LkjVEGGM7sw2pZWhCazlxpSst1tAZoAFJuLhQmnmKM1ClD6j5HX/Tvfg+XaRbCn7wumw511DqWrxUxpySj+cg1hDHXeY1nlHjsC79CmNQDDx+ALUcQhPtj0olXwI93VwG3v7ZYcymWLpysoOHUFy2O3m8jdHKlNHeNzBlfbZkC7I8BMdtLgIPT1Q==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MPtKAjI+GTs39DPbqlySzVR3iLANzx29XY6Ml+OIhNgL/cgtaRZDd3IkFqXDY8T/G1vksLWHQ+DHHcn9vmKJoWDRotanPDiYQlu3EK9n6Etxytxtpav8Kc0DPdOisHIx/xzX+Yc0dvSNWkMh+YxuKWNdN7xOrkKGtaVRvNkZ7HQ5QIsNhpd2G5i4YxnYIzTA8aq2OBFrWeCT73mmRm2/LyphRA3kVe/uhx/4NuZSpyrit0MW7bXLG0dNpizVNhLZQIQ5iGEtPF19QnzUnh+vSE4r9l2qB1vWPr1FIRIddZyCv49oS9hzM7TWYd903Y+zAxLGhneaLrZ1/CkAWVWYRA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=ppford header.d=ford.com header.i="@ford.com" header.h="Cc:Content-Transfer-Encoding:Content-Type:Date:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To"; dkim=pass header.s=selector2-azureford-onmicrosoft-com header.d=azureford.onmicrosoft.com header.i="@azureford.onmicrosoft.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"; dkim=pass header.s=ppserprodsaar header.d=saarlouis.ford.com header.i="@saarlouis.ford.com" header.h="Cc:Content-Transfer-Encoding:Date:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To"; dkim=pass header.s=ppfserpocford header.d=ford.com header.i="@ford.com" header.h="Cc:Content-Transfer-Encoding:Date:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To"
  • Cc: andrew.cooper3@xxxxxxxxxx, anthony.perard@xxxxxxxxxx, jbeulich@xxxxxxxx, julien@xxxxxxx, michal.orzel@xxxxxxx, roger.pau@xxxxxxxxxx, sstabellini@xxxxxxxxxx, dmukhin@xxxxxxxx
  • Delivery-date: Wed, 29 Jul 2026 07:25:41 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Pser-m365-app: SER-APP

From: Denis Mukhin <dmukhin@xxxxxxxx> 

Introduce CONFIG_PRINTK_RATELIMIT_MS and CONFIG_PRINTK_RATELIMIT_BURST
for configuring rate-limiting policy at the compile time.

Use symbols for global rate-limiting initialization in the console driver.

Signed-off-by: Denis Mukhin <dmukhin@xxxxxxxx>
---
Changes since v3:
- added note on security support for non-standard configurations
- gated menu with EXPERT

I kept both settings for now.
---
 xen/common/Kconfig         | 36 ++++++++++++++++++++++++++++++++++++
 xen/drivers/char/console.c |  6 ++++--
 2 files changed, 40 insertions(+), 2 deletions(-)

diff --git a/xen/common/Kconfig b/xen/common/Kconfig
index da80fdba8469..749d3bfb08e0 100644
--- a/xen/common/Kconfig
+++ b/xen/common/Kconfig
@@ -672,4 +672,40 @@ config PM_STATS
          Enable collection of performance management statistics to aid in
          analyzing and tuning power/performance characteristics of the system
 
+menu "Console rate-limiting"
+       visible if EXPERT
+
+config PRINTK_RATELIMIT_MS
+       int "printk rate-limiting time window (milliseconds)"
+       default 5000
+       help
+         Specifies the time window, in milliseconds, for rate-limited [*] 
printk
+         messages. No more than `CONFIG_PRINTK_RATELIMIT_BURST` messages will 
be
+         printed within this window.
+
+         Setting this value to 0 disables rate-limiting entirely.
+
+         Configurations using a value other than the default of 5000 are not
+         security supported.
+
+         [*] Rate-limited messages are those controlled by the `loglvl` and
+         `guest_loglvl` command-line parameters.
+
+config PRINTK_RATELIMIT_BURST
+       int "printk rate-limited message burst size"
+       default 10
+       help
+         Defines the maximum number of rate-limited [*] printk messages that 
may
+         be printed within each `CONFIG_PRINTK_RATELIMIT_MS` time window.
+
+         Setting this value to 0 disables rate-limiting entirely.
+
+         Configurations using a value other than the default of 10 are not
+         security supported.
+
+         [*] Rate-limited messages are those controlled by the `loglvl` and
+         `guest_loglvl` command-line parameters.
+
+endmenu
+
 endmenu
diff --git a/xen/drivers/char/console.c b/xen/drivers/char/console.c
index 76a1681670c1..2c7be1e61f3e 100644
--- a/xen/drivers/char/console.c
+++ b/xen/drivers/char/console.c
@@ -1353,10 +1353,12 @@ bool __printk_ratelimit(unsigned int ratelimit_ms,
 }
 
 /* Minimum time in ms between messages */
-static const unsigned int printk_ratelimit_ms = 5 * 1000;
+static const unsigned int printk_ratelimit_ms =
+    CONFIG_PRINTK_RATELIMIT_MS;
 
 /* Number of messages we send before ratelimiting */
-static const unsigned int printk_ratelimit_burst = 10;
+static const unsigned int printk_ratelimit_burst =
+    CONFIG_PRINTK_RATELIMIT_BURST;
 
 bool printk_ratelimit(void)
 {
-- 
2.54.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.