Skip to content

fix: Detect appends to files kept open by their writer on Windows - #8

Open
StephKll3c wants to merge 1 commit into
mainfrom
sc-polling-stat-by-handle
Open

fix: Detect appends to files kept open by their writer on Windows#8
StephKll3c wants to merge 1 commit into
mainfrom
sc-polling-stat-by-handle

Conversation

@StephKll3c

Copy link
Copy Markdown
Collaborator

On Windows, the polling watcher relied on os.Stat, which reads the directory entry. NTFS does not refresh that entry while another process keeps the file open for writing, which is exactly what SQL Server does with its ERRORLOG. The watcher never saw the file grow, so the tail silently stopped after the initial read (see SekoiaLab/platform#89869, and most likely SekoiaLab/platform#83229 as well, since the fsnotify bump never touched the polling path). The polling loop now stats the file through a handle on Windows, which always returns fresh metadata.

While in there, the polling loop no longer calls util.Fatal on an unexpected stat error, which was killing the whole agent process with os.Exit(1) from a background goroutine. Transient stat errors are now tolerated for a few seconds, then the file is reported as deleted so the tail reopens it instead of dying.

@StephKll3c
StephKll3c force-pushed the sc-polling-stat-by-handle branch from 18b33f6 to ca377ca Compare July 31, 2026 16:38
@StephKll3c
StephKll3c requested a review from Darkheir July 31, 2026 16:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant