Repository navigation
daemon answers the dashboard again (85 GB events, duplicate tails); click to copy errors (0.13.22) - #285
Merged
Conversation
…lick to copy errors (0.13.22) Anthony: "ban doesn't work anymore" from monitor --tui. On dev2 every IPC call, ban and blocklist included, timed out after 10s: the daemon was busy. - state.db was 85 GB. The events table was never pruned, and topSources / status scanned all of it synchronously (better-sqlite3) on every TUI poll, freezing the daemon for minutes. Counts and top sources now read the newest 200k events only; the total comes from sqlite_sequence. pruneEvents keeps [storage] event_retention (default 14d) and max_events (default 2M), in small batches every minute. - How it got there: the log watchers started a new read stream each poll and recorded the offset only when the stream closed. A read slower than the poll interval was started again from the same offset, so lines were processed (and stored) many times over, and every stream held a file descriptor (3,259 on syslog, 1,549 on deleted logs). LogTail reads synchronously, bounded and chunked, once per poll, and follows rotation by inode. Used by the log watcher, the DNS monitor and `monitor`. - TUI: errors stay 30s, a click on the status-bar message copies it (OSC 52, works over ssh and tmux), and `y` copies the last error after it fades. - `threatcrush servers` with no subcommand lists servers instead of "Unknown action: [object Object]". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| this.inode = st.ino; | ||
| const end = Math.min(st.size, this.pos + maxBytes); | ||
| if (end <= this.pos) return 0; | ||
| const buf = Buffer.allocUnsafe(Math.min(end - this.pos, 1 << 20)); |
ThreatCrush Security Scan18 finding(s) HIGH/CRITICAL: 1 | MEDIUM: 9 | LOW: 8
Snippets are redacted; ThreatCrush never prints matched credential material. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
daemon: answer the dashboard again (85 GB events, duplicate tails); click to copy errors (0.13.22)
Anthony: "ban doesn't work anymore" from monitor --tui. On dev2 every IPC
call, ban and blocklist included, timed out after 10s: the daemon was busy.
status scanned all of it synchronously (better-sqlite3) on every TUI poll,
freezing the daemon for minutes. Counts and top sources now read the newest
200k events only; the total comes from sqlite_sequence. pruneEvents keeps
[storage] event_retention (default 14d) and max_events (default 2M), in
small batches every minute.
recorded the offset only when the stream closed. A read slower than the
poll interval was started again from the same offset, so lines were
processed (and stored) many times over, and every stream held a file
descriptor (3,259 on syslog, 1,549 on deleted logs). LogTail reads
synchronously, bounded and chunked, once per poll, and follows rotation by
inode. Used by the log watcher, the DNS monitor and
monitor.works over ssh and tmux), and
ycopies the last error after it fades.threatcrush serverswith no subcommand lists servers instead of"Unknown action: [object Object]".
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com