The log says everything is fine INC-2412

Open2 versionsLinux · Medium · Investigate · about 25 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Mara Okafor opened INC-2412 at 08:15SEV-3

Scanners at depot-8 keep dropping their connection. Waybill's restart counter climbs, and its log file looks spotless.

var/log/waybill/app.log only shows the latest start, because Waybill recreates it every time it starts. Each start looks healthy. The restarts are the problem.

"Do not just revert last night's change. It turned on the hazmat-v2 labels for depot-8, the regulator wants those from Monday." (Mara)

The reboot split the evidence across two boots. The journal keeps both; the app log does not.

Your task

Find the earliest failure, with its time and the file that caused it, and write both into var/incident/findings.txt. Then fix the setting that causes the exits while keeping the hazmat-v2 change.

On the machine

  • bin/hostlog --list-boots, bin/hostlog -u waybill -b -1
  • var/log/waybill/app.log (current run only)
  • etc/waybill/waybill.conf and etc/waybill/overrides.d/

Timeline

06:58First Waybill exit with status 78 after a config change.
07:00–07:40Waybill restarts every few minutes; scanners reconnect each time.
LaterTomas reboots depot-8 "to clear it". It does not.
08:15INC-2412 opened.

Done when

  1. var/incident/findings.txt names the earliest failure: its time and the file that caused it.
  2. Waybill survives two restarts and several config reloads.
  3. The hazmat-v2 override stays in place.

Hints

Hint 1

Look beyond the current log file: it starts fresh with every run.

Hint 2

Query the journal across boots: `bin/hostlog --list-boots`, then `-b -1`.

Hint 3

The first failure is before the visible log. Find the first exit with code 78 and the line above it.

Hint 4

The config message names the override file and the bad value. Fix that value, and keep what else the file sets.

Show the solution

`bin/hostlog --list-boots`, then `bin/hostlog -u waybill -b -1`: before the 10:12 reboot, Waybill first exited with code 78 on a config error. The message names the override file in `etc/waybill/overrides.d/` and the value it rejected, a `cache_ttl` without a valid unit. Write that time and file into `var/incident/findings.txt`. Fix the value in that file (for example `5m` or `300s`) without dropping the hazmat-v2 template override, then restart Waybill twice and reload it a few times while watching the journal.