From f97a25295ec71888a4e2cb07c922705f94063d2d Mon Sep 17 00:00:00 2001 From: David Cozens Date: Wed, 29 Jul 2026 11:11:56 +0100 Subject: [PATCH] feat: state the device's own address in origin.ip The ip PARAM, sourced from the same interface address HOSTNAME reports. A relay or NAT between device and collector rewrites what the collector observes; ip is what the device says about itself, which survives the hop. Flash +12,388 B (+408 on the previous stage) RAM +7,384 B (unchanged) Log stack +712 B (+8) Service +992 B (unchanged) ip is repeatable per RFC 5424 section 7.2, so the library asks for a count and then one value per index rather than taking a string. This device has one address and returns one, and none before the interface has an address. SyslogFields_IpAddress is now the single place that reads the address; HOSTNAME formats the same string through it. The record is 260 bytes, inside the 512-byte cap with room for both counters at full width. Co-Authored-By: Claude Opus 5 (1M context) --- README.md | 14 ++++++-------- app/syslog/Syslog.c | 29 +++++++++++++++++++++++++++-- app/syslog/SyslogFields.c | 19 +++++++++++++------ app/syslog/SyslogFields.h | 5 +++++ measurements/origin-ip.csv | 13 +++++++++++++ measurements/stages.tsv | 1 + run-report.md | 26 +++++++++++++------------- 7 files changed, 78 insertions(+), 29 deletions(-) create mode 100644 measurements/origin-ip.csv diff --git a/README.md b/README.md index ad6d82c..e0a66c3 100644 --- a/README.md +++ b/README.md @@ -10,18 +10,15 @@ It builds on a baseline that simulates the sort of device you might be adding th measures itself: see [docs/baseline.md](docs/baseline.md) for what the baseline is, how the figures are made, and how to run it. -## This stage — Smaller ring +## This stage — Origin address -The ring holds four records instead of eight. It is sized in records, so doubling the cap doubled -what it cost — and four is enough to absorb what gets logged while the service task is sending, -because the store rather than the ring is what holds a backlog. - -It gives back almost everything the cap rise took. Nothing else moves: the ring bounds how many -records can be in flight, not how large one may be. +`origin` gains the `ip` PARAM, read from the same interface address `HOSTNAME` reports. A relay or +NAT between the device and the collector rewrites what the collector observes; this is what the +device says about itself, and it survives the hop. -**Cost above baseline: Flash +11,980 B, RAM +7,384 B.** +**Cost above baseline: Flash +12,388 B, RAM +7,384 B.** @@ -49,6 +46,7 @@ committed as [`run-report.md`](run-report.md), and rewritten by every stage. | Origin | the device named in the record itself, not inferred from the source address | +11,972 | +7,136 | | Larger cap | headroom for the grown record, so full-width counters cannot push it into truncation | +11,980 | +9,440 | | Smaller ring | most of the cap rise given back, now the store rather than the ring holds a backlog | +11,980 | +7,384 | +| Origin address | the device's own address in the record, which a relay or NAT between it and the collector cannot rewrite | +12,388 | +7,384 | *Deltas are bytes above the baseline, which is itself Flash 350,308 B, RAM 111,192 B.* diff --git a/app/syslog/Syslog.c b/app/syslog/Syslog.c index 2149ee8..522148e 100644 --- a/app/syslog/Syslog.c +++ b/app/syslog/Syslog.c @@ -25,6 +25,7 @@ #include "SolidSyslogLwipRawTcpStream.h" #include "SolidSyslogMetaSd.h" #include "SolidSyslogOriginSd.h" +#include "SolidSyslogSdValue.h" #include "SolidSyslogStdAtomicCounter.h" #include "SolidSyslogStreamSender.h" #include "SolidSyslogTimeQuality.h" @@ -32,6 +33,7 @@ #include "SyslogEnterprise.h" #include "SyslogFields.h" +#include "lwip/ip4_addr.h" #include "lwip/tcpip.h" #include "FreeRTOS.h" @@ -74,6 +76,29 @@ static void SyslogTimeQuality(struct SolidSyslogTimeQuality* timeQuality) timeQuality->SyncAccuracyMicroseconds = SOLIDSYSLOG_SYNC_ACCURACY_OMIT; } +/* The device's own view of its address, which a relay or NAT between it and the + * collector would otherwise replace. */ +static size_t SyslogOriginIpCount(void* context) +{ + (void) context; + + char address[IP4ADDR_STRLEN_MAX] = {0}; + + SyslogFields_IpAddress(address, sizeof(address)); + return (address[0] != '\0') ? 1U : 0U; +} + +static void SyslogOriginIpAt(struct SolidSyslogSdValue* value, void* context, size_t index) +{ + (void) context; + (void) index; + + char address[IP4ADDR_STRLEN_MAX] = {0}; + + SyslogFields_IpAddress(address, sizeof(address)); + SolidSyslogSdValue_String(value, address); +} + /* Bounds the connect spin so it yields instead of busy-waiting. */ static void SyslogSleep(int milliseconds) { @@ -128,12 +153,12 @@ void Syslog_Start(void) s_sd[0] = SolidSyslogMetaSd_Create(&metaConfig); s_sd[1] = SolidSyslogTimeQualitySd_Create(SyslogTimeQuality); - /* No ip: the address the collector sees is the one that reached it, until a - * relay makes that untrue. */ struct SolidSyslogOriginSdConfig originConfig = { .Software = SYSLOG_SOFTWARE, .SwVersion = SYSLOG_SW_VERSION, .EnterpriseId = SYSLOG_ENTERPRISE_ID, + .GetIpCount = SyslogOriginIpCount, + .GetIpAt = SyslogOriginIpAt, }; s_sd[2] = SolidSyslogOriginSd_Create(&originConfig); diff --git a/app/syslog/SyslogFields.c b/app/syslog/SyslogFields.c index dd3b191..cf837c1 100644 --- a/app/syslog/SyslogFields.c +++ b/app/syslog/SyslogFields.c @@ -39,20 +39,27 @@ void SyslogFields_Clock(struct SolidSyslogTimestamp* timestamp) } } -void SyslogFields_Hostname(struct SolidSyslogHeaderField* field, void* context) +void SyslogFields_IpAddress(char* out, size_t size) { - (void) context; - - char address[IP4ADDR_STRLEN_MAX] = {0}; + out[0] = '\0'; /* netif state belongs to the lwIP core, so read and format under its lock. * ip4addr_ntoa_r, not ip4addr_ntoa: the latter shares one static buffer. */ LOCK_TCPIP_CORE(); - if (netif_default != NULL) + if ((netif_default != NULL) && !ip4_addr_isany_val(*netif_ip4_addr(netif_default))) { - (void) ip4addr_ntoa_r(netif_ip4_addr(netif_default), address, (int) sizeof(address)); + (void) ip4addr_ntoa_r(netif_ip4_addr(netif_default), out, (int) size); } UNLOCK_TCPIP_CORE(); +} + +void SyslogFields_Hostname(struct SolidSyslogHeaderField* field, void* context) +{ + (void) context; + + char address[IP4ADDR_STRLEN_MAX] = {0}; + + SyslogFields_IpAddress(address, sizeof(address)); if (address[0] != '\0') { diff --git a/app/syslog/SyslogFields.h b/app/syslog/SyslogFields.h index d329392..57e26b3 100644 --- a/app/syslog/SyslogFields.h +++ b/app/syslog/SyslogFields.h @@ -4,12 +4,17 @@ #ifndef SYSLOG_FIELDS_H #define SYSLOG_FIELDS_H +#include + struct SolidSyslogTimestamp; struct SolidSyslogHeaderField; /** SolidSyslogClockFunction. */ void SyslogFields_Clock(struct SolidSyslogTimestamp* timestamp); +/** The default interface's IPv4 address, or an empty string when unavailable. */ +void SyslogFields_IpAddress(char* out, size_t size); + /** HOSTNAME as the interface's IPv4 address — RFC 5424 section 6.2.4 allows an * address where a device has no resolvable name. */ void SyslogFields_Hostname(struct SolidSyslogHeaderField* field, void* context); diff --git a/measurements/origin-ip.csv b/measurements/origin-ip.csv new file mode 100644 index 0000000..a0a1fed --- /dev/null +++ b/measurements/origin-ip.csv @@ -0,0 +1,13 @@ +# origin-ip figures (bytes) — captured by scripts/run.sh (CAPTURE=1). +# The device reads measurements/Baseline.csv as its frozen baseline and reports current-minus-Baseline. +flash_text,362056 +flash_data,640 +static_bss,117936 +heap_used,4440 +mbedtls_peak,21280 +mbedtls_free,11488 +lwip_mem_free,7576 +lwip_pbufs_free,13 +stack_log,832 +stack_service,1044 +stack_harness,2848 diff --git a/measurements/stages.tsv b/measurements/stages.tsv index 2a21ae4..dcd00e2 100644 --- a/measurements/stages.tsv +++ b/measurements/stages.tsv @@ -24,3 +24,4 @@ file-store File store records that survive a failed send, spooled to disk with a origin Origin the device named in the record itself, not inferred from the source address cap-rise Larger cap headroom for the grown record, so full-width counters cannot push it into truncation buffer-halve Smaller ring most of the cap rise given back, now the store rather than the ring holds a backlog +origin-ip Origin address the device's own address in the record, which a relay or NAT between it and the collector cannot rewrite diff --git a/run-report.md b/run-report.md index 14d80e2..c894411 100644 --- a/run-report.md +++ b/run-report.md @@ -1,4 +1,4 @@ -# solid-syslog-example — run (buffer-halve) +# solid-syslog-example — run (origin-ip) ## Device (self-measured) @@ -10,15 +10,15 @@ [device] first record logged: yes [report] --- SolidSyslog cost above baseline (simulated existing application) --- [report] key,current,baseline,used_above_baseline -[report] flash_text,361648,349992,11656 +[report] flash_text,362056,349992,12064 [report] flash_data,640,316,324 [report] static_bss,117936,110876,7060 [report] heap_used,4440,4440,0 -[report] mbedtls_peak,21340,21332,8 -[report] mbedtls_free,11428,11436,-8 +[report] mbedtls_peak,21280,21332,-52 +[report] mbedtls_free,11488,11436,52 [report] lwip_mem_free,7576,7576,0 [report] lwip_pbufs_free,13,14,-1 -[report] stack_log,824,120,704 +[report] stack_log,832,120,712 [report] stack_service,1044,52,992 [report] stack_harness,2848,2840,8 [report] --- end --- @@ -29,7 +29,7 @@ ```text text data bss dec hex filename - 361640 648 117936 480224 753e0 /w/build/baseline-cross/baseline.elf + 362048 648 117936 480632 75578 /w/build/baseline-cross/baseline.elf ``` ## Listeners (proved before the device ran) @@ -47,22 +47,22 @@ ## Collector (syslog-ng) received ```text -wire <134>1 2026-07-29T08:29:37.410000Z 10.0.2.15 solid-syslog-example - BOOT [meta sequenceId="1" sysUpTime="241"][timeQuality tzKnown="1" isSynced="0"][origin software="solid-syslog-example" swVersion="0.1.0" enterpriseId="32473"] device started -parsed PRIORITY=134 TIMESTAMP=2026-07-29T08:29:37+00:00 HOSTNAME=10.0.2.15 APP_NAME=solid-syslog-example PROCID= MSGID=BOOT STRUCTURED_DATA=[meta sequenceId="1" sysUpTime="241"][timeQuality tzKnown="1" isSynced="0"][origin software="solid-syslog-example" swVersion="0.1.0" enterpriseId="32473"] MSG=device started +wire <134>1 2026-07-29T10:10:44.420000Z 10.0.2.15 solid-syslog-example - BOOT [meta sequenceId="1" sysUpTime="242"][timeQuality tzKnown="1" isSynced="0"][origin software="solid-syslog-example" swVersion="0.1.0" enterpriseId="32473" ip="10.0.2.15"] device started +parsed PRIORITY=134 TIMESTAMP=2026-07-29T10:10:44+00:00 HOSTNAME=10.0.2.15 APP_NAME=solid-syslog-example PROCID= MSGID=BOOT STRUCTURED_DATA=[meta sequenceId="1" sysUpTime="242"][timeQuality tzKnown="1" isSynced="0"][origin software="solid-syslog-example" swVersion="0.1.0" enterpriseId="32473" ip="10.0.2.15"] MSG=device started ``` -## Self-check (vs measurements/buffer-halve.csv) +## Self-check (vs measurements/origin-ip.csv) ```text - OK flash_text: 361648 (expected 361648, Δ0) + OK flash_text: 362056 (expected 362056, Δ0) OK flash_data: 640 (expected 640, Δ0) OK static_bss: 117936 (expected 117936, Δ0) OK heap_used: 4440 (expected 4440, Δ0) - OK mbedtls_peak: 21340 (expected 21340, Δ0) - OK mbedtls_free: 11428 (expected 11428, Δ0) + OK mbedtls_peak: 21280 (expected 21280, Δ0) + OK mbedtls_free: 11488 (expected 11488, Δ0) OK lwip_mem_free: 7576 (expected 7576, Δ0) OK lwip_pbufs_free: 13 (expected 13, Δ0) - OK stack_log: 824 (expected 824, Δ0) + OK stack_log: 832 (expected 832, Δ0) OK stack_service: 1044 (expected 1044, Δ0) OK stack_harness: 2848 (expected 2848, Δ0) ```