Describe the per-target token bucket and the two configfs files that drive it: ratelimit_interval_ms and ratelimit_burst.
Spell out the two properties that are not obvious from the file names. The limit is accounted per message rather than per packet, so a message split into several ncfrag packets is never truncated by the bucket running dry halfway through. Note in the message ID section that a message the bucket discards never reaches the counter, so those drops leave no gap in the IDs. Signed-off-by: Breno Leitao <[email protected]> --- Documentation/networking/netconsole.rst | 38 +++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/Documentation/networking/netconsole.rst b/Documentation/networking/netconsole.rst index 4ab5d7b05cf102..a9ccf798346562 100644 --- a/Documentation/networking/netconsole.rst +++ b/Documentation/networking/netconsole.rst @@ -177,6 +177,41 @@ You can modify these targets in runtime by creating the following targets:: cat cmdline1/remote_ip 10.0.0.3 +Rate limiting +------------- + +Netconsole hands every console message to every enabled target, so a host that +logs continuously can saturate the receiving agent. Each target carries a token +bucket that drops messages once the configured rate is exceeded, controlled by +two files in the target directory: + + ===================== ================================================ + ratelimit_interval_ms Length of the accounting interval, in + milliseconds. Zero, the default, sends + everything. + ratelimit_burst Messages allowed per interval. Defaults to + 10; zero drops every message once an + interval is set. + ===================== ================================================ + +Unlike most target parameters, both knobs can be written while the target is +enabled, which is when a flooding target most likely needs them. + +The limit is applied per message, not per packet, so a message big enough to be +split into several `ncfrag` packets is either sent whole or not at all. + +Crash output bypasses the bucket. While an oops, BUG() or panic() is in +progress every message is sent, whatever the limit says, so a small burst +cannot cost you part of a crash dump. + +A drop leaves nothing on the wire. On an extended target it shows up as a gap +in the sequence number the header carries; a basic target has no such marker. + +Capping a target at 500 messages a minute:: + + echo 60000 > ratelimit_interval_ms + echo 500 > ratelimit_burst + Append User Data ---------------- @@ -359,6 +394,9 @@ indicate that a message was dropped during transmission, as it may never have been sent via netconsole. The message ID, on the other hand, is only assigned to messages that are actually transmitted via netconsole. +A message the target's rate limit discards is dropped before the ID is +assigned, so those drops leave no gap in the sequence of IDs either. + Example:: echo "This is message #1" > /dev/kmsg -- 2.53.0-Meta

