From: Denis Mukhin <[email protected]> 

Introduce CONFIG_PRINTK_RATELIMIT_MS and CONFIG_PRINTK_RATELIMIT_BURST
for configuring rate-limiting policy at the compile time.

Use symbols for global rate-limiting initialization in the console driver.

Signed-off-by: Denis Mukhin <[email protected]>
---
Changes since v3:
- added note on security support for non-standard configurations
- gated menu with EXPERT

I kept both settings for now.
---
 xen/common/Kconfig         | 36 ++++++++++++++++++++++++++++++++++++
 xen/drivers/char/console.c |  6 ++++--
 2 files changed, 40 insertions(+), 2 deletions(-)

diff --git a/xen/common/Kconfig b/xen/common/Kconfig
index da80fdba8469..749d3bfb08e0 100644
--- a/xen/common/Kconfig
+++ b/xen/common/Kconfig
@@ -672,4 +672,40 @@ config PM_STATS
          Enable collection of performance management statistics to aid in
          analyzing and tuning power/performance characteristics of the system
 
+menu "Console rate-limiting"
+       visible if EXPERT
+
+config PRINTK_RATELIMIT_MS
+       int "printk rate-limiting time window (milliseconds)"
+       default 5000
+       help
+         Specifies the time window, in milliseconds, for rate-limited [*] 
printk
+         messages. No more than `CONFIG_PRINTK_RATELIMIT_BURST` messages will 
be
+         printed within this window.
+
+         Setting this value to 0 disables rate-limiting entirely.
+
+         Configurations using a value other than the default of 5000 are not
+         security supported.
+
+         [*] Rate-limited messages are those controlled by the `loglvl` and
+         `guest_loglvl` command-line parameters.
+
+config PRINTK_RATELIMIT_BURST
+       int "printk rate-limited message burst size"
+       default 10
+       help
+         Defines the maximum number of rate-limited [*] printk messages that 
may
+         be printed within each `CONFIG_PRINTK_RATELIMIT_MS` time window.
+
+         Setting this value to 0 disables rate-limiting entirely.
+
+         Configurations using a value other than the default of 10 are not
+         security supported.
+
+         [*] Rate-limited messages are those controlled by the `loglvl` and
+         `guest_loglvl` command-line parameters.
+
+endmenu
+
 endmenu
diff --git a/xen/drivers/char/console.c b/xen/drivers/char/console.c
index 76a1681670c1..2c7be1e61f3e 100644
--- a/xen/drivers/char/console.c
+++ b/xen/drivers/char/console.c
@@ -1353,10 +1353,12 @@ bool __printk_ratelimit(unsigned int ratelimit_ms,
 }
 
 /* Minimum time in ms between messages */
-static const unsigned int printk_ratelimit_ms = 5 * 1000;
+static const unsigned int printk_ratelimit_ms =
+    CONFIG_PRINTK_RATELIMIT_MS;
 
 /* Number of messages we send before ratelimiting */
-static const unsigned int printk_ratelimit_burst = 10;
+static const unsigned int printk_ratelimit_burst =
+    CONFIG_PRINTK_RATELIMIT_BURST;
 
 bool printk_ratelimit(void)
 {
-- 
2.54.0


Reply via email to