Relationships
↔ sibling #3039#3052 Serve audit: delivered WAL segments are only deleted at shutdown, so a long-running serve fills the WAL
Opened by stack72 · 10/5/2026· Shipped 10/6/2026
WalSink (src/serve/audit_sinks/wal_sink.ts) records each segment delivered to the store in a delivered set, but only deletes those segments in WalSink.flush. In a running serve nothing calls it: AuditEmitter.flush, the only path to WalSink.flush, is called from serve.ts only during shutdown, and AuditWal.deleteSegment is otherwise only called by startup replay and the size-limit eviction in AuditWal.enforceLimit. So every delivered segment stays on disk until shutdown. Once the WAL reaches its max size (default 100MB), AuditWal.isFull is true, which makes fail-secure mode (fail-open false) reject every request with audit_unavailable. With fail-open true, enforceLimit evicts the oldest segments, which are already delivered, and sets hasDroppedEvents, which also trips the fail-secure check and logs that undelivered events may be lost. Expected: a delivered segment is deleted soon after delivery (for example after the downstream batch it went into is flushed to the store), so WAL size tracks undelivered events only. Found while working on swamp-club#3039, which does not change this.
Shipped
Click a lifecycle step above to view its details.
Sign in to post a ripple.