From nobody Mon Nov 20 14:43:38 2023 X-Original-To: freebsd-hackers@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4SYqyR0Prsz51Nxs for ; Mon, 20 Nov 2023 14:43:59 +0000 (UTC) (envelope-from zarychtam@plan-b.pwste.edu.pl) Received: from plan-b.pwste.edu.pl (plan-b.pwste.edu.pl [IPv6:2001:678:618::40]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "plan-b.pwste.edu.pl", Issuer "GEANT OV RSA CA 4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4SYqyQ49KTz4LgB for ; Mon, 20 Nov 2023 14:43:58 +0000 (UTC) (envelope-from zarychtam@plan-b.pwste.edu.pl) Authentication-Results: mx1.freebsd.org; none Received: from [IPV6:2a02:22e0:cf00:1ff:86f5:5b17:8cd7:ba0b] (mzar@[IPv6:2a02:22e0:cf00:1ff:86f5:5b17:8cd7:ba0b]) (authenticated bits=0) by plan-b.pwste.edu.pl (8.17.2/8.17.2) with ESMTPSA id 3AKEhdrG070077 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NO); Mon, 20 Nov 2023 15:43:39 +0100 (CET) (envelope-from zarychtam@plan-b.pwste.edu.pl) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=plan-b.pwste.edu.pl; s=plan-b-mailer; t=1700491421; bh=Y4QVyTHlSm2i2awiuMXyqul0qU2Z1wdtk2hioFz5K+Y=; h=Date:Subject:To:References:From:Cc:In-Reply-To; b=vf+LIFRJfIsLVAM75Jc0VzaGTIsr9ys8e1ZMh/KiRL8tvnuW5h2YaoUngLeBsWrZS qjRJa05kcQoXiN1qXANYW9nDEB8YC9S06wl5iKcS3IcIvopWUaB30ex54BUuQwspDf GUFEWvVS9zw0gcrRS/LGHlNG/csRRvBeFluH+8Rnf3TUEdRRjBIxv3osVEV7cSuja8 rdEFyB/krapANrK1lu9ehTTQUGgN8vDUibjLU3LQm9R6qoNis6jWeA4YSdFYmdi5Eg L//8c2l+bDKEmoRli78JCiu2k6taNMFESx+pCaG97WP/hXaKcyvb2JhK1zThkEh0/F v8nadeo8EtLJg== Message-ID: Date: Mon, 20 Nov 2023 15:43:38 +0100 List-Id: Technical discussions relating to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-hackers List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-hackers@freebsd.org MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: the RATELIMIT kernel option Content-Language: en-US To: void@f-m.fm References: From: Marek Zarychta Autocrypt: addr=zarychtam@plan-b.pwste.edu.pl; keydata= xsBNBFfi3cMBCADLecMTFXad4uDXqv3eRuB4qJJ8G9tzzFezeRnnwxOsPdytW5ES2z1ibSrR IsiImx6+PTqrAmXpTInxAi7yiZGdSiONRI4CCxKY9d1YFiNYT/2WyNXCekm9x29YeIU7x0JB Llbz0f/9HC+styBIu2H+PY/X98Clzm110CS+n/b9l1AtiGxTiVFj7/uavYAKxH6LNWnbkuc5 v8EVNc7NkEcl5h7Z9X5NEtzDxTOiBIFQ/kOT7LAtkYUPo1lqLeOM2DtWSXTXQgXl0zJI4iP1 OAu4qQYm2nXwq4b2AH9peknelvnt1mpfgDCGSKnhc26q6ibTfMwydp+tvUtQIQYpA6b9ABEB AAHNN01hcmVrIFphcnljaHRhIChQbGFuLWIpIDx6YXJ5Y2h0YW1AcGxhbi1iLnB3c3RlLmVk dS5wbD7CwHcEEwEIACEFAlfi4LkCGwMFCwkIBwIGFQgJCgsCBBYCAwECHgECF4AACgkQHZW8 vIFppoJXdgf8D9X3VRFSNaR9lthSx/+uqas17J3FJKBo1xMQsC2a+44vzNvYJSuPGLLJ+LW2 HPVazjP/BWZJbxOYpliY4zxNRU0YCp0BLIVLibc//yax+mE42FND/+NiIZhqJscl6MLPrSwo sIwXec4XYkldkyqW/xBbBYXoIkBqdKB9j5j42Npy1IV/RizOSdmvTWY27ir8e/yGMR1RLr4F 8P5K3OWTdlGy2H2F/3J8bIPBLG6FpaIyLQw4dHSx8V02PYqDxK1cNo2kAOnU8PnZL/AGuMOH iv3MN1VYL8ehcmpBBsrZGebQJxrjY2/5IaTSgp9xHYT70kshuU6Qb97vk1mOjNZxgc7ATQRX 4t3DAQgA10h6RCXuBLMHxq5B8X/ZIlj9sgLoeyfRdDZEc9rT2KUeUJVHDsbvOFf4/7F1ovWY hJbA6GK/LUZeHHTjnbZcH1uDYQeHly4UOLxeEvhGoz4JhS2C7JzN/uRnwbdOAUbJr8rUj/IY a7gk906rktsc/Ldrxrxh7O6WO0JCh2XO/p4pDfEwwB37g4xHprSab28ECYJ9JMbtA8Sy4M55 g3+GQ28FvSlGnx48OoGXU2BZdc1vZKSQmNOlikB+9/hDX8zdYWVfDaX1TLQ8Ib4+xTUmapza mV/bxIsaZRBw+jFjLQHhTbIMfPEU+4mxFDvTdbKPruKPqVf1ydgMnPZWngowdwARAQABwsBf BBgBCAAJBQJX4t3DAhsMAAoJEB2VvLyBaaaC6qkIAJs9sDPqrqW0bYoRfzY6XjDWQ59p9tJi v8aogxacQNCfAu+WkJ8PNVUtC1dlVcG5NnZ80gXzd1rc8ueIvXlvdanUt/jZd8jbb3gaDbK3 wh1yMCGBl/1fOJTyEGYv1CRojv97KK89KP5+r8x1P1iHcSrunlDNqGxTMydNCwBH23QcOM+m u4spKnJ/s0VRBkw3xoKBZfZza6fTQ4gTpAipjyk7ldOGBV+PvkKATdhK2yLwuWXhKbg/GRlD 1r5P0gxzSqfV4My+KJuc2EDcrqp1y0wOpE1m9iZqCcd0fup5f7HDsYlLWshr7NQl28f6+fQb sylq/j672BHXsdeqf/Ip9V4= Cc: FreeBSD Hackers In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Spamd-Bar: ---- X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; ASN(0.00)[asn:206006, ipnet:2001:678:618::/48, country:PL] X-Rspamd-Queue-Id: 4SYqyQ49KTz4LgB Hello void W dniu 20.11.2023 o 14:46, void pisze: > Hello hackers@, > > I've been looking at adding the RACK tcp kernel option, and reading > the instructions on > https://klarasystems.com/articles/using-the-freebsd-rack-tcp-stack/ > > They mention the RATELIMIT option for some network cards but I can find > no option of that name in LINT/NOTES so am not sure if it works with > just some or all network interfaces or what the tradeoffs are. Can > anyone here clarify please? or just point me to whatever I need to > look at, thanks I am not a hacker, but I have also sought a couple of times what FreeBSD hackers have done with the code. There are a few or even a bunch of undocumented options. Number one for me is still "options RSS". From my experience, the best way to read about them is by digging FreeBSD mailing lists[1], searching on FreeBSD's Phabricator[2] and ... using grep inside /usr/src. If you want to build stabe/1{3,4} with TCP RACK stack then mentioned article published on Klara Systems website provides still right guidance, then both: options         TCPHPTS options         RATELIMIT are required. 1. https://lists.freebsd.org/ 2. https://reviews.freebsd.org/ Cheers -- Marek Zarychta