Re: tmpfs

Andrew <[email protected]> Fri, 22 Nov 2024 10:42:30 +0200
Newsgroups gmane.linux.leaf.user
Message-ID <[email protected]>
I thin trouble was caused by hostapd logs; ntpd looks like having 
self-rotated logs or something like that.


On 11/21/24 23:57, Boris via leaf-user wrote:
> Am 21.11.24 um 09:11 schrieb Andrew:
>> hi.
>>
>> did you try to check which deleted logfiles are still opened by 
>> running processes? try to run 'lsof /var/log' to see which files are 
>> currently opened; deleted ones are marked as (deleted) - they aren't 
>> displayed, but are still allocated on FS (until file is closed).
>>
>
> Hej Andrew,
>
> thanks for your statement!
>
> Assuming your hint is 'lsof | grep /var/log', here is the output 
> before and after restarting ntp(d) and hostapd:
>
> # lsof | grep /var/log
> 3250    /usr/sbin/hostapd    3    /var/log/hostapd.log (deleted)
> 3260    /usr/sbin/openvpn    1    /var/log/openvpn.log
> 3260    /usr/sbin/openvpn    2    /var/log/openvpn.log
> 3260    /usr/sbin/openvpn    3    /var/log/openvpn-status.log
> 3278    /usr/sbin/ntpd    4    /var/log/ntpd
> 3278    /usr/sbin/ntpd    7 /var/log/ntpstats/peerstats.20241121 
> (deleted)
> 3278    /usr/sbin/ntpd    8 /var/log/ntpstats/loopstats.20241121 
> (deleted)
> 22077    /usr/sbin/ulogd    4    /var/log/ulogd.log
> 22077    /usr/sbin/ulogd    7    /var/log/shorewall.log
> 22077    /usr/sbin/ulogd    11    /var/log/shorewall6.log
> 22893    /usr/sbin/lighttpd    5    /var/log/lighttpd/error.log
> 22893    /usr/sbin/lighttpd    7    /var/log/lighttpd/access.log
> 22963    /usr/sbin/rsyslogd    2    /var/log/syslog
> 22963    /usr/sbin/rsyslogd    5    /var/log/syslog
> 22963    /usr/sbin/rsyslogd    6    /var/log/auth.log
> 22963    /usr/sbin/rsyslogd    7    /var/log/daemon.log
> 22963    /usr/sbin/rsyslogd    8    /var/log/kern.log
> # /etc/init.d/ntp restart
> Restarting NTP server: ntpd... done.
> # /etc/init.d/hostapd  restart
> Stopping advanced IEEE 802.11 management: hostapd.
> Starting advanced IEEE 802.11 management: hostapd.
> # lsof | grep /var/log
> 3260    /usr/sbin/openvpn    1    /var/log/openvpn.log
> 3260    /usr/sbin/openvpn    2    /var/log/openvpn.log
> 3260    /usr/sbin/openvpn    3    /var/log/openvpn-status.log
> 22077    /usr/sbin/ulogd    4    /var/log/ulogd.log
> 22077    /usr/sbin/ulogd    7    /var/log/shorewall.log
> 22077    /usr/sbin/ulogd    11    /var/log/shorewall6.log
> 22893    /usr/sbin/lighttpd    5    /var/log/lighttpd/error.log
> 22893    /usr/sbin/lighttpd    7    /var/log/lighttpd/access.log
> 22963    /usr/sbin/rsyslogd    2    /var/log/syslog
> 22963    /usr/sbin/rsyslogd    5    /var/log/syslog
> 22963    /usr/sbin/rsyslogd    6    /var/log/auth.log
> 22963    /usr/sbin/rsyslogd    7    /var/log/daemon.log
> 22963    /usr/sbin/rsyslogd    8    /var/log/kern.log
> 28492    /usr/sbin/ntpd    4    /var/log/ntpd
> 28492    /usr/sbin/ntpd    7 /var/log/ntpstats/peerstats.20241121
> 28492    /usr/sbin/ntpd    8 /var/log/ntpstats/loopstats.20241121
> 28507    /usr/sbin/hostapd    3    /var/log/hostapd.log
>
> And yeah, fantastic:
>
> # du -h /var/log
> 176.0K    ./ntpstats
> 4.0K    ./lighttpd
> 11.4M    .
>
> # df -h
> Filesystem                Size      Used Available Use% Mounted on
> tmpfs                   150.0M      4.0K    150.0M   0% /tmp
> tmpfs                   800.0M     11.4M    788.6M   1% /var/log
> root                     64.0M     42.6M     21.4M  67% /
>
> Seems that's the clue!
>
> Now what's the consequence? Restarting those daemons (and withit 
> closing those files) after rotating logs?
> Use perhaps POSTROTATE_EXEC from /usr/bin/logratate for this?
>
> Thanks and regards,
>
>
> Boris
>
>
>
> ------------------------------------------------------------------------
> leaf-user mailing list: [email protected]
> https://lists.sourceforge.net/lists/listinfo/leaf-user
> Support Request -- http://leaf-project.org/




------------------------------------------------------------------------
leaf-user mailing list: [email protected]
https://lists.sourceforge.net/lists/listinfo/leaf-user
Support Request -- http://leaf-project.org/