Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Phasers locked on target, Captain.


computers / alt.os.linux.mageia / shorewall dumping everything into dmesg

SubjectAuthor
* shorewall dumping everything into dmesgWilliam Unruh
`* Re: shorewall dumping everything into dmesgDavid W. Hodgins
 `* Re: shorewall dumping everything into dmesgWilliam Unruh
  `- Re: shorewall dumping everything into dmesgDavid W. Hodgins

1
shorewall dumping everything into dmesg

<uq1fr7$1q7lo$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5983&group=alt.os.linux.mageia#5983

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: unruh@invalid.ca (William Unruh)
Newsgroups: alt.os.linux.mageia
Subject: shorewall dumping everything into dmesg
Date: Thu, 8 Feb 2024 02:55:35 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 46
Message-ID: <uq1fr7$1q7lo$1@dont-email.me>
Injection-Date: Thu, 8 Feb 2024 02:55:35 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="344dec573c354355eccfdead0727f82b";
logging-data="1908408"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19Hyy3x2y5p5CrBYL8WD6Xe"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:UsQGNAAqOG3wlGzIvQck0rYzrc4=
 by: William Unruh - Thu, 8 Feb 2024 02:55 UTC

Shore wall is dumping its messages into dmesg, rather than say
/var/log/shorewall (which is empty) That rather fills dmesg with DROP
messages
[8024391.572953] Shorewall:sshd-fw:DROP:IN=eno1 OUT= MAC=4c:ed:fb:c2:2a:f3:a0:ab:1b:88:6e:58:08:00 SRC=185.196.8.151 DST=192.168.0.3 LEN=40 TOS=0x00 PREC=0xA0 TTL=250 ID=54321 PROTO=TCP SPT=40237 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0

What might I have misconfigured?
/etc/shorewall/shorewall.conf has

###############################################################################
# L O G G I N G
###############################################################################

BLACKLIST_LOG_LEVEL=info

INVALID_LOG_LEVEL=info

LOG_MARTIANS=Yes

LOG_VERBOSITY=2

#LOGALLNEW=yes

LOGFILE=/var/log/shorewall

LOGFORMAT="Shorewall:%s:%s:"

LOGTAGONLY=No

LOGLIMIT=

MACLIST_LOG_LEVEL=info

RELATED_LOG_LEVEL=

RPFILTER_LOG_LEVEL=info

SFILTER_LOG_LEVEL=info

SMURF_LOG_LEVEL=info

STARTUP_LOG=/var/log/shorewall-init.log

TCP_FLAGS_LOG_LEVEL=info

UNTRACKED_LOG_LEVEL=

Re: shorewall dumping everything into dmesg

<op.2iszwcrza3w0dxdave@hodgins.homeip.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=5984&group=alt.os.linux.mageia#5984

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux.mageia
Subject: Re: shorewall dumping everything into dmesg
Date: Wed, 07 Feb 2024 22:27:38 -0500
Organization: A noiseless patient Spider
Lines: 16
Message-ID: <op.2iszwcrza3w0dxdave@hodgins.homeip.net>
References: <uq1fr7$1q7lo$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="ba10507d462df0b1650804e99c04aa17";
logging-data="1923910"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+XJdOpJX+UoLyFfJqVJaQXCKHPtt7XaZc="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:o/AkjVIz3G2ZDX1UgLpRitSQK7E=
 by: David W. Hodgins - Thu, 8 Feb 2024 03:27 UTC

On Wed, 07 Feb 2024 21:55:35 -0500, William Unruh <unruh@invalid.ca> wrote:
> Shore wall is dumping its messages into dmesg, rather than say
> /var/log/shorewall (which is empty) That rather fills dmesg with DROP
> messages
> [8024391.572953] Shorewall:sshd-fw:DROP:IN=eno1 OUT= MAC=4c:ed:fb:c2:2a:f3:a0:ab:1b:88:6e:58:08:00 SRC=185.196.8.151 DST=192.168.0.3 LEN=40 TOS=0x00 PREC=0xA0 TTL=250 ID=54321 PROTO=TCP SPT=40237 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0

IIRC that's fixed by creating a file with one line such as
/etc/sysctl.d/kernel.msg.conf
kernel.printk=3 4 1 3

Then run as root "sysctl --system".

See https://linuxconfig.org/introduction-to-the-linux-kernel-log-levels
for details.

Regards, Dave Hodgins

Re: shorewall dumping everything into dmesg

<ur3d60$2ob56$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=6001&group=alt.os.linux.mageia#6001

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!news.nntp4.net!paganini.bofh.team!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: unruh@invalid.ca (William Unruh)
Newsgroups: alt.os.linux.mageia
Subject: Re: shorewall dumping everything into dmesg
Date: Tue, 20 Feb 2024 23:38:40 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 50
Message-ID: <ur3d60$2ob56$1@dont-email.me>
References: <uq1fr7$1q7lo$1@dont-email.me>
<op.2iszwcrza3w0dxdave@hodgins.homeip.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf8
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 20 Feb 2024 23:38:40 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="2e2b124d898a68bed9470a9df6514537";
logging-data="2895014"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/LXY7scG661e3AgKfjLZDd"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:O27kJ29ZlOPWqZdJGI5jfQuaY+o=
 by: William Unruh - Tue, 20 Feb 2024 23:38 UTC

On 2024-02-08, David W. Hodgins <dwhodgins@nomail.afraid.org> wrote:
> On Wed, 07 Feb 2024 21:55:35 -0500, William Unruh <unruh@invalid.ca> wrote:
>> Shore wall is dumping its messages into dmesg, rather than say
>> /var/log/shorewall (which is empty) That rather fills dmesg with DROP
>> messages
>> [8024391.572953] Shorewall:sshd-fw:DROP:IN=eno1 OUT= MAC=4c:ed:fb:c2:2a:f3:a0:ab:1b:88:6e:58:08:00 SRC=185.196.8.151 DST=192.168.0.3 LEN=40 TOS=0x00 PREC=0xA0 TTL=250 ID=54321 PROTO=TCP SPT=40237 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
>
> IIRC that's fixed by creating a file with one line such as
> /etc/sysctl.d/kernel.msg.conf
> kernel.printk=3 4 1 3
>
> Then run as root "sysctl --system".

That did not work.
The "explanation" in the article below is rather confusing

"starting from level 0 and decreasing in severity ’till level 7: the
lowest log level identifier, the most critical context." I have no idea
what that means. It seems to be saying that level 7 is the most
critical context. Is that right (Ie, this the opposite to the rsyslog
levels which have lower numbers more critical than high numbers).
"log level lower than it, (therefore messages with an higher severity)"
Whereas this sentence seems to say the opposite.
Or did the first quote mean to say "have lower numbers, the more
critical context.

But then I do not understand the log level of shorewall. Where are thos
DROP messages being sent to?

"The third value in the output reports the minimum_console_loglevel
status. It indicates the minimum loglevel which can be used for
console_loglevel. The level here used it’s 1, the highest."

7 is higher than 0. But that does not seem to be what they mean by
higher.

But my problem is with dmesg, not with the console. It is dmesg whic
his filling up with shorewall DROP messages, not the consooe. (Mind you
I told the sytem to stop drumping log stuff into the cosold anywahy
sicen it is really really really annoying to mafe the console filling
with garbage while one is deperately trying to fix so crucial error.

Ie, I have the printk file listing 3 4 1 3 as you suggested and dmesg is
still being innundated by DROP messages.

>
> See https://linuxconfig.org/introduction-to-the-linux-kernel-log-levels
> for details.
>
> Regards, Dave Hodgins

Re: shorewall dumping everything into dmesg

<op.2jgxqkxja3w0dxdave@hodgins.homeip.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=6002&group=alt.os.linux.mageia#6002

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!news.hispagatos.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux.mageia
Subject: Re: shorewall dumping everything into dmesg
Date: Tue, 20 Feb 2024 20:43:22 -0500
Organization: A noiseless patient Spider
Lines: 17
Message-ID: <op.2jgxqkxja3w0dxdave@hodgins.homeip.net>
References: <uq1fr7$1q7lo$1@dont-email.me>
<op.2iszwcrza3w0dxdave@hodgins.homeip.net> <ur3d60$2ob56$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="48cbaec1164e1ace196d6cc18693b411";
logging-data="2940495"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/vR0Ctodt3MmGxbxuWskHnI+3ElUmNZ4Q="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:Jjr/cLbTKmlQAIRGG09mZGUb+U4=
 by: David W. Hodgins - Wed, 21 Feb 2024 01:43 UTC

On Tue, 20 Feb 2024 18:38:40 -0500, William Unruh <unruh@invalid.ca> wrote:
> Ie, I have the printk file listing 3 4 1 3 as you suggested and dmesg is
> still being innundated by DROP messages.

Sorry, I thought your were referring to the messages showing up on a terminal,
such as when using alt+ctrl+f3, and then logging in in text mode.

The drop messages are generated by netfilter (part of the kernel), which uses
rules set by a firewall such as shorewall.

"man shorewall.conf" has some info on the log options, but I've never looked
into it in detail.

We used to have mandriva-save-dmesg.service saving a copy of the dmesg output
to /var/log/dmesg, but it seems it's been dropped.

Regards, Dave Hodgins

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor