From patchwork Fri Dec 12 16:38:11 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 9366 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (verified OK)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4dVK3q1P8Rz3wbF for ; Mon, 15 Dec 2025 12:23:51 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "E8" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4dSZrn3JBhz446 for ; Fri, 12 Dec 2025 16:38:17 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4dSZrn2Xrkz2xnx for ; Fri, 12 Dec 2025 16:38:17 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R12" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4dSZrk42HFz2xWj for ; Fri, 12 Dec 2025 16:38:14 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4dSZrj4JR5z1N3; Fri, 12 Dec 2025 16:38:13 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1765557493; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=ZAba6MQq4STpGi76LFc5PUYydi3yTfCGY57VDRhgESo=; b=pKcnNcvcjFEb9ZBqBgOygMCONu3Axby8rUjjs+gybKG/x6F0e5r4MqwEy+PGpdj6YI7Qrx /Ukz1KuWp1n6ncDg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1765557493; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=ZAba6MQq4STpGi76LFc5PUYydi3yTfCGY57VDRhgESo=; b=jgDwZ3veyhllmXzu/arFgKrEomtopODDxAT6LufKPZzZftg+nKhPlkVVZ6g3Dy5sz+h6iD NCuOA7xhyAANUKuu7IdOEnOxZN9kf3BxNOoBmSEUxZqfMZCLL+dQhGl9uHOYFPIeme/oUd HSz5LYw07NfYrNz3phCHgxKrfKZHt0vDi4VzzFlbQyKQbJnpg1Y8MDdp1ocWdAIINZlNkD wrUmDRFFY9ilm2IgbtuSEPTQVUzBCNYJsDn5sLwPZLpTkaAxR1G7xXu7Dvo8omC9aTxyJQ 9AU6mVHBXCOtG+maxNJhHBd148dfdJj8PV/438yAWi8P6KGcKlGCskpy+PR4Qg== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] exclude: Add the suricata sgh cache directory to the list Date: Fri, 12 Dec 2025 17:38:11 +0100 Message-ID: <20251212163811.3547417-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Depending on the number of suricata rulesets that users have got enabled the suricata cache in /var/cache/suricata/sgh/ gets currently backed up in the ipfire .ipf file and some users are ending up with backup files that used to be 190MB and are now greater than 700MB, some even over 800MB. - This change excludes the cache from the backup as it seems that a restore with a cache from an earlier time does not make sense. Signed-off-by: Adolf Belka --- config/backup/exclude | 1 + 1 file changed, 1 insertion(+) diff --git a/config/backup/exclude b/config/backup/exclude index a69eed767..0719b471f 100644 --- a/config/backup/exclude +++ b/config/backup/exclude @@ -1,6 +1,7 @@ etc/sysconfig/lm_sensors etc/unbound/unbound.conf *.tmp +var/cache/suricata/sgh/* var/ipfire/ethernet/settings var/ipfire/firewall/bin/* var/ipfire/ovpn/openssl/*