Commit Graph

1 Commits

Author SHA1 Message Date
kaveh 5366eb0d29 Bound the panel syslog view with a journalctl timeout (#6689)
* Bound the syslog view with a journalctl timeout

* fix(syslog): bound the journal scan window and soften the timeout message

Limit journalctl to the last 30 days so a rare -p level cannot scan the whole
journal, and drop the guessed cause and the host-wide vacuum advice from the
timeout message.

* fix(syslog): drop --since from the journalctl call and test the timeout

On systemd 249/252 (Ubuntu 22.04, Debian 12) journalctl seeks to --since
and reads forward when both --since and -n are given, so the Syslog view
showed the oldest 200 lines of the 30-day window instead of the newest.
Reproduced in debian:12, ubuntu:22.04 and ubuntu:24.04 containers on a
synthetic journal; only 255 kept the newest lines. The window also bought
nothing: on a 340 MB journal every variant (with or without --since, rare
-p level or not) answered in ~10 ms on 252 and 255.

Keep the 15s deadline as the guard against a stalled journalctl and cover
it with a fake journalctl on PATH; the args test pinned the broken flag
and is removed.

---------

Co-authored-by: Sanaei <ho3ein.sanaei@gmail.com>
2026-10-03 01:21:25 +02:00