From owner-freebsd-current@FreeBSD.ORG Tue May 12 12:54:34 2009 Return-Path: Delivered-To: freebsd-current@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 43127106566B for ; Tue, 12 May 2009 12:54:34 +0000 (UTC) (envelope-from gavin@FreeBSD.org) Received: from mail-gw2.york.ac.uk (mail-gw2.york.ac.uk [144.32.128.247]) by mx1.freebsd.org (Postfix) with ESMTP id CD3EC8FC19 for ; Tue, 12 May 2009 12:54:33 +0000 (UTC) (envelope-from gavin@FreeBSD.org) Received: from mail-gw7.york.ac.uk (mail-gw7.york.ac.uk [144.32.129.30]) by mail-gw2.york.ac.uk (8.13.6/8.13.6) with ESMTP id n4CCsUse012357; Tue, 12 May 2009 13:54:30 +0100 (BST) Received: from buffy-128.york.ac.uk ([144.32.128.160] helo=buffy.york.ac.uk) by mail-gw7.york.ac.uk with esmtps (TLSv1:AES256-SHA:256) (Exim 4.68) (envelope-from ) id 1M3rV8-0007En-Sl; Tue, 12 May 2009 13:54:30 +0100 Received: from buffy.york.ac.uk (localhost [127.0.0.1]) by buffy.york.ac.uk (8.14.3/8.14.3) with ESMTP id n4CCsUhP007345; Tue, 12 May 2009 13:54:30 +0100 (BST) (envelope-from gavin@FreeBSD.org) Received: (from ga9@localhost) by buffy.york.ac.uk (8.14.3/8.14.3/Submit) id n4CCsUIY007344; Tue, 12 May 2009 13:54:30 +0100 (BST) (envelope-from gavin@FreeBSD.org) X-Authentication-Warning: buffy.york.ac.uk: ga9 set sender to gavin@FreeBSD.org using -f From: Gavin Atkinson To: Dmitry Morozovsky In-Reply-To: References: Content-Type: text/plain Content-Transfer-Encoding: 7bit Date: Tue, 12 May 2009 13:54:30 +0100 Message-Id: <1242132870.5455.9.camel@buffy.york.ac.uk> Mime-Version: 1.0 X-Mailer: Evolution 2.22.2 FreeBSD GNOME Team Port X-York-MailScanner: Found to be clean X-York-MailScanner-From: gavin@freebsd.org Cc: freebsd-current@FreeBSD.org, gad@FreeBSD.org Subject: Re: newsyslog(8) patch for both size and time checks X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 May 2009 12:54:34 -0000 On Tue, 2009-05-12 at 13:59 +0400, Dmitry Morozovsky wrote: > Dear colleagues, > > for now, if log is configured to be rotated in time manner, its size is not > checked, so /var/log may be DoSed by some service (in our case, it was mad DHCP > client which fills up our /var/log with dhcpd log; our newsyslog.conf line was > > /var/log/dhcpd 640 5 5000 @T00 JC > > The following simple patch should fix the problem. Any objection to commit > this? Short answer: I believe you will find this patch breaks some newsyslog functionality. I can't remember what the problems are, but that patch is pretty similar to my first attempt at fixing the problem too. The patch I ended up creating is at http://people.freebsd.org/~gavin/PRs/100018.diff (and a PR where somebody else requested this functionality is bin/100018). Gavin