Skip to content

A zone's log is bounded across launches, and by what is logged - #222

Merged
DevomB merged 1 commit into
mainfrom
zone-log-bound
Oct 5, 2026
Merged

DevomB merged 1 commit into
mainfrom
zone-log-bound

Conversation

@DevomB

@DevomB DevomB commented Oct 5, 2026

Copy link
Copy Markdown
Owner

A zone started through the launch service writes to a pipe, and its launcher relays that into /var/log/kryptik/zone-ZONE.log on the state partition. The relay bounds one launch. Nothing bounded the file: every launch appended to it, for as long as the installation lives.

What a zone could do with that:

  • The relay counted the bytes a zone wrote, not the bytes logged. Each line is logged with a mark (zone NAME| ) and a line end, so one megabyte of one-character lines became about nine in the log.
  • Launch after launch, a zone whose programs fill their allowance grew the log by that much each time. Nothing a zone does starts a launch, so the growth is at the pace the person starts programs, but it never ends, and the state partition holds their data.

The change:

  • serve.rs: at a launch, a log past 8 MiB becomes zone-ZONE.log.old, replacing the one before, and a new file starts. A zone keeps at most two files of that size plus one launch each. Under the bound the log is appended to as before, so a launch's diagnostics and the suites that read the log are unchanged.
  • spawn.rs: the relay counts each line's mark and end against the launch's megabyte.
  • The log is opened with O_NOFOLLOW, as last_log_line already reads it. /var/log/kryptik is root's alone, so this closes no hole today.

Not changed: the zone still never holds the log's descriptor (a pipe, read without blocking it), a write that fails on a full disk drops the line and the relay keeps reading, and a first launch on a full state partition is still refused when the log cannot be created. The net zone is run by its service, not the launch service: its output goes to the catch-all logger in /run, which s6-log rotates.

Tests: zone_log_starts_again_past_its_bound (append under the bound, rotation past it with the earlier .old replaced, a link at the name refused and nothing made through it) and the relay's flood test, which now measures logged bytes and adds the one-character-line case.

Conflicts to expect: #194 (comments in the same files), #221 and #214 (serve.rs, spawn.rs).

…t the next launch with one earlier file kept, the relay counts each line's mark and end against a launch's megabyte, and the log is never opened through a link
@DevomB
DevomB merged commit 92032f0 into main Oct 5, 2026
20 checks passed
@DevomB
DevomB deleted the zone-log-bound branch October 7, 2026 03:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant