arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.01564cs.DCcs.OScs.SE

基于Docker的Logs API的源受限精确恢复

Source-Bounded Exact Recovery over Docker's Logs API

Kelvin Amoaba

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对Docker的Logs API提出源受限精确恢复方法,通过LogDeck实验验证其修复了竞态条件等问题,在120次测试中精确性达60/60,优于Grafana Alloy 1.18.0。

中文摘要 AI 辅助

Docker会保留收集器在附加前或停机期间错过的记录,而持久化的读取位置本身并不能确保在生命周期变更后实现恢复。我们研究通过Docker支持的Logs API可实现何种精确恢复契约,并定义源受限精确性:每一条保留的、可区分的源记录最终都会在持久化的收集器输出中精确出现一次。我们的方法采用感知代际的多重集预言机,将源截断与收集器遗漏分离,同时暴露丢失和重放情况。将该方法应用于LogDeck后,我们发现了从启动到附加的竞态条件、一条记录的附加重叠、有限的Docker API协调机制,以及通过精确插入闭合了测试边界。我们将修复后的版本与未修改的Grafana Alloy 1.18.0进行比较,二者使用相同API且持久化读取位置;在120次收集器运行中,LogDeck的精确性为60/60,Alloy为20/60。Alloy在受保护启动和进程暂停时可成功,但当恢复需要发现已退出或重启的源时,会遗漏保留的历史记录。在因果对照实验中,5000条记录的源在收集前退出:原始发现机制在20次试验中精确性为0/20且未获取任何记录,而同一读取器在提供容器ID后,20次试验均精确恢复了所有记录。该结果在OrbStack和独立Ubuntu主机(Docker 29.4.0和24.0.9)上复现:两个收集器均可恢复守护进程重启情况,但均无法在源移除后恢复记录。精确性的前提是物理代际、时间戳、流和字节的元组可区分;两个驱动程序中20万条字节完全相同的记录未观察到冲突。我们的结果表明,生命周期重新获取而非仅持久化位置,决定了保留源范围内的精确恢复,这是一个受限接口声明,而非通用收集器排名或无冲突证明。

英文摘要

Docker can retain records that a collector misses before attachment or during downtime. A persisted read position does not by itself ensure recovery after lifecycle changes. We study what exact recovery contract is achievable through Docker's supported Logs API. We define source-bounded exactness: every retained, distinguishable source record eventually appears exactly once in durable collector output. Our method uses a generation-aware multiset oracle that separates source truncation from collector omission and exposes simultaneous loss and replay. Applied to LogDeck, it uncovered a start-to-attachment race; a one-record attachment overlap, finite Docker-API reconciliation, and exact insertion closed the tested boundary. We compare the fixed revision with unmodified Grafana Alloy 1.18.0, which uses the same API and persists read positions; across 120 collector-runs, LogDeck was exact in 60/60 and Alloy in 20/60. Alloy succeeded at guarded startup and process pause but omitted retained history when recovery required discovering an exited or restarted source. In a causal control, a 5,000-record source exited before collection: stock discovery was exact in 0/20 trials and acquired nothing, while the same reader given the container ID recovered all records exactly in 20/20. This reproduced on OrbStack and independent Ubuntu hosts with Docker 29.4.0 and 24.0.9; both collectors recovered daemon restart, while neither recovered records after source removal. Exactness assumes distinct tuples of physical generation, timestamp, stream, and bytes; 200,000 byte-identical records across two drivers produced no observed collisions. Our results show that lifecycle reacquisition, not a persisted position alone, determines exact recovery within the retained-source horizon. This is a bounded interface claim, not a universal collector ranking or proof of collision freedom.

补充信息

↑