Skip to content

Fix log pattern end anchoring - #1338

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:fix-log-pattern-anchoring
Aug 28, 2026
Merged

Fix log pattern end anchoring#1338
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:fix-log-pattern-anchoring

Conversation

@hakman

@hakman hakman commented Aug 23, 2026

Copy link
Copy Markdown
Member

CompilePattern previously appended \z directly to each configured expression. Because | has lower precedence, oom-kill|Out of memory\z anchored only the second branch. The first branch could match a retained line again after every subsequent push until that line was overwritten, repeating temporary events and log-counter results.

Group the expression before adding the end anchor:

  • Before: oom-kill|Out of memory\z
  • After: (?:oom-kill|Out of memory)\z

This makes every branch honor the end-of-buffer contract and removes the extra parse-tree comparison. Shipped configurations are unaffected because they already group their alternatives. Custom patterns with an unparenthesized top-level | intentionally change behavior; use (?:oom-kill|Out of memory).* when either phrase should match anywhere before the end of the newest line.

/cc @DigitalVeer

@kubernetes-prow
kubernetes-prow Bot requested a review from DigitalVeer August 23, 2026 05:17
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. approved Indicates a PR has been approved by an approver from all required OWNERS files. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Aug 23, 2026
@hakman

hakman commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/cc @ameukam

@kubernetes-prow
kubernetes-prow Bot requested a review from ameukam August 25, 2026 16:49
@ameukam

ameukam commented Aug 25, 2026

Copy link
Copy Markdown
Member

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 25, 2026
@hakman

hakman commented Aug 25, 2026

Copy link
Copy Markdown
Member Author

/hold for a second pass

@kubernetes-prow kubernetes-prow Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Aug 25, 2026
anchored := `(?:` + expr + `)\z`
reg, err := regexp.Compile(anchored)
if err != nil {
return nil, err

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Everything LGTM. Only one comment - I think with this change we should wrap the error:

fmt.Errorf("invalid pattern %q: %w", expr, err)

This is based on running a before/after with a string with \Q in it:

old  regexp.Compile(`error\Q` + `\z`)     → no err
new  regexp.Compile(`(?:error\Q)` + `\z`) → missing closing ): `(?:error\Q)\z`

The error message shows our internal (?:...)\z pattern which the user did not write.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good point, will update. thanks for checking this.

@hakman
hakman force-pushed the fix-log-pattern-anchoring branch from b02cca9 to 0558b3d Compare August 26, 2026 16:21
@kubernetes-prow kubernetes-prow Bot removed the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 26, 2026
@hakman
hakman force-pushed the fix-log-pattern-anchoring branch from 0558b3d to b02cca9 Compare August 26, 2026 16:24
`CompilePattern` previously appended `\z` directly to each configured expression. With a top-level alternative such as `oom-kill|Out of memory`, the first branch could match an older line that was still in the buffer.

Wrap the expression in a non-capturing group before adding the end anchor:

- **Before:** `oom-kill|Out of memory\z`
- **After:** `(?:oom-kill|Out of memory)\z`

This makes every branch honor the documented end-of-buffer contract, lets last-line classification inspect a single parse tree, and adds regression coverage for stale matches.
@hakman
hakman force-pushed the fix-log-pattern-anchoring branch from b02cca9 to 0b0ff3e Compare August 26, 2026 16:25
@hakman

hakman commented Aug 26, 2026

Copy link
Copy Markdown
Member Author

/unhold

@kubernetes-prow kubernetes-prow Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Aug 26, 2026
@hakman

hakman commented Aug 27, 2026

Copy link
Copy Markdown
Member Author

CC @ameukam @DigitalVeer - one more LGTM, please

@DigitalVeer

Copy link
Copy Markdown
Member

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 28, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ameukam, DigitalVeer, hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow
kubernetes-prow Bot merged commit 7a25332 into kubernetes:master Aug 28, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants