Repository navigation
A zone's log is bounded across launches, and by what is logged - #222
Merged
Merged
Conversation
…t the next launch with one earlier file kept, the relay counts each line's mark and end against a launch's megabyte, and the log is never opened through a link
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A zone started through the launch service writes to a pipe, and its launcher relays that into
/var/log/kryptik/zone-ZONE.logon the state partition. The relay bounds one launch. Nothing bounded the file: every launch appended to it, for as long as the installation lives.What a zone could do with that:
zone NAME|) and a line end, so one megabyte of one-character lines became about nine in the log.The change:
serve.rs: at a launch, a log past 8 MiB becomeszone-ZONE.log.old, replacing the one before, and a new file starts. A zone keeps at most two files of that size plus one launch each. Under the bound the log is appended to as before, so a launch's diagnostics and the suites that read the log are unchanged.spawn.rs: the relay counts each line's mark and end against the launch's megabyte.O_NOFOLLOW, aslast_log_linealready reads it./var/log/kryptikis root's alone, so this closes no hole today.Not changed: the zone still never holds the log's descriptor (a pipe, read without blocking it), a write that fails on a full disk drops the line and the relay keeps reading, and a first launch on a full state partition is still refused when the log cannot be created. The net zone is run by its service, not the launch service: its output goes to the catch-all logger in
/run, whichs6-logrotates.Tests:
zone_log_starts_again_past_its_bound(append under the bound, rotation past it with the earlier.oldreplaced, a link at the name refused and nothing made through it) and the relay's flood test, which now measures logged bytes and adds the one-character-line case.Conflicts to expect: #194 (comments in the same files), #221 and #214 (
serve.rs,spawn.rs).