Audit writer: open a record-less log, share the log-name rule, keep the lock file

M3a review findings 1, 2, 4 and part of 5. One empty log file made brokerd
panic at startup (files[len - 2]); it now opens as an empty log. brokerd's
name check tested one month digit, so a file bxctl ignored could become
brokerd's latest file; both now use proto::is_audit_log_name. Writer no
longer unlinks audit/.lock, which opened a two-writer window. No unwrap in
short_check.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-09-22 21:05:13 -07:00
co-authored by Claude Opus 5.5
parent 22a26aad45
commit eed0a221ca
6 changed files with 182 additions and 70 deletions
+33
View File
@@ -0,0 +1,33 @@
//! Which file names are audit log files. `brokerd` and `bxctl audit verify` both use this one rule,
//! so they always read the same set of files.
use proto::is_audit_log_name;
#[test]
fn a_date_and_jsonl_is_a_log_file() {
for name in ["2026-09-17.jsonl", "0000-00-00.jsonl", "9999-12-31.jsonl"] {
assert!(is_audit_log_name(name), "{name}");
}
}
#[test]
fn every_other_name_is_not() {
for name in [
"",
".lock",
"2026-0x-17.jsonl", // the second month digit
"2026-x9-17.jsonl",
"2026-09-1x.jsonl",
"x026-09-17.jsonl",
"2026_09-17.jsonl",
"2026-09_17.jsonl",
"2026-09-17.json",
"2026-09-17.jsonl.bak",
"2026-9-17.jsonl",
"12026-09-17.jsonl",
"2026-09-17.JSONL",
"026-09-17.jsonl", // a full-width digit is not an ASCII digit
] {
assert!(!is_audit_log_name(name), "{name}");
}
}