Skip to content

daemon answers the dashboard again (85 GB events, duplicate tails); click to copy errors (0.13.22) - #285

Merged
ralyodio merged 1 commit into
masterfrom
fix/daemon-starved-ipc
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/daemon-starved-ipc

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

daemon: answer the dashboard again (85 GB events, duplicate tails); click to copy errors (0.13.22)

Anthony: "ban doesn't work anymore" from monitor --tui. On dev2 every IPC
call, ban and blocklist included, timed out after 10s: the daemon was busy.

  • state.db was 85 GB. The events table was never pruned, and topSources /
    status scanned all of it synchronously (better-sqlite3) on every TUI poll,
    freezing the daemon for minutes. Counts and top sources now read the newest
    200k events only; the total comes from sqlite_sequence. pruneEvents keeps
    [storage] event_retention (default 14d) and max_events (default 2M), in
    small batches every minute.
  • How it got there: the log watchers started a new read stream each poll and
    recorded the offset only when the stream closed. A read slower than the
    poll interval was started again from the same offset, so lines were
    processed (and stored) many times over, and every stream held a file
    descriptor (3,259 on syslog, 1,549 on deleted logs). LogTail reads
    synchronously, bounded and chunked, once per poll, and follows rotation by
    inode. Used by the log watcher, the DNS monitor and monitor.
  • TUI: errors stay 30s, a click on the status-bar message copies it (OSC 52,
    works over ssh and tmux), and y copies the last error after it fades.
  • threatcrush servers with no subcommand lists servers instead of
    "Unknown action: [object Object]".

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com

…lick to copy errors (0.13.22)

Anthony: "ban doesn't work anymore" from monitor --tui. On dev2 every IPC
call, ban and blocklist included, timed out after 10s: the daemon was busy.

- state.db was 85 GB. The events table was never pruned, and topSources /
  status scanned all of it synchronously (better-sqlite3) on every TUI poll,
  freezing the daemon for minutes. Counts and top sources now read the newest
  200k events only; the total comes from sqlite_sequence. pruneEvents keeps
  [storage] event_retention (default 14d) and max_events (default 2M), in
  small batches every minute.
- How it got there: the log watchers started a new read stream each poll and
  recorded the offset only when the stream closed. A read slower than the
  poll interval was started again from the same offset, so lines were
  processed (and stored) many times over, and every stream held a file
  descriptor (3,259 on syslog, 1,549 on deleted logs). LogTail reads
  synchronously, bounded and chunked, once per poll, and follows rotation by
  inode. Used by the log watcher, the DNS monitor and `monitor`.
- TUI: errors stay 30s, a click on the status-bar message copies it (OSC 52,
  works over ssh and tmux), and `y` copies the last error after it fades.
- `threatcrush servers` with no subcommand lists servers instead of
  "Unknown action: [object Object]".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
this.inode = st.ino;
const end = Math.min(st.size, this.pos + maxBytes);
if (end <= this.pos) return 0;
const buf = Buffer.allocUnsafe(Math.min(end - this.pos, 1 << 20));
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

18 finding(s)

HIGH/CRITICAL: 1 | MEDIUM: 9 | LOW: 8

Severity Rule Location
HIGH secret-aws-access-key prd/0003-detect-hardcoded-secrets-before-they-are-committed-or-served.md:126
MEDIUM sql-string-concatenation .github/workflows/migrate-dev2.yml:128
MEDIUM js-uninitialized-buffer apps/cli/src/core/log-tail.ts:58
MEDIUM js-open-redirect apps/web/src/app/auth/login/page.tsx:67
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:104
MEDIUM js-unescaped-html-sink apps/web/src/app/hire/page.tsx:108
MEDIUM js-open-redirect apps/web/src/app/invite/[token]/invite-client.tsx:55
MEDIUM js-open-redirect apps/web/src/components/funding/FundingClient.tsx:97
MEDIUM js-unescaped-html-sink apps/web/src/components/GuideReader.tsx:265
MEDIUM js-uninitialized-buffer packages/scan/src/node-rules.ts:456
LOW secret-generic-credential apps/web/src/app/api/auth/refresh/route.ts:17
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:26
LOW secret-generic-credential apps/web/src/app/api/auth/reset-password/route.ts:27
LOW secret-generic-credential PRD.md:269
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:121
LOW tls-verification-disabled prd/0004-find-dangerous-code-patterns-without-pretending-to-be-a-compiler.md:122
LOW sh-remote-script-execution scripts/smoke-test.sh:72
LOW secret-aws-access-key scripts/smoke-test.sh:150

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit d4e6cf6 into master Oct 6, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants