You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

添加用户的UID为何会导致/var/log/lastlog文件大幅膨胀?

Why does /var/log/lastlog size explode with large UIDs on Ubuntu?

Let me break down exactly why this happens—this is a classic gotcha with how Ubuntu (and most Debian-based distros) handle the lastlog and faillog files, and it has nothing to do with Docker itself.

How lastlog works under the hood

The /var/log/lastlog file isn't a plain text log you can read with cat—it's a fixed-size binary database. Each entry in this database corresponds to a specific UID (user ID), and every entry takes up the same amount of space (usually around 128 bytes, depending on your system architecture).

Here's the critical detail: the file doesn't only store entries for existing users. It allocates space for every UID from 0 up to the highest UID present on your system. So if you create a user with a massive UID (say, 20,000,000), the system will instantly reserve space for all UIDs between 0 and that number—even if 99.9% of those UIDs don't map to real users. That's exactly why your lastlog jumped from 288KB to 2.8GB: your operation must have created a user with a drastically higher UID than before.

The same logic applies to faillog

/var/log/faillog uses the exact same binary database structure. Any large UID added to the system will force this file to expand to accommodate all UIDs up to that maximum value too.

How to verify this

To confirm the connection between your highest UID and the file size, run this command to get the largest UID on your system:

awk -F: '{print $3}' /etc/passwd | sort -n | tail -1

Multiply that number by the entry size (you can check the entry size with getconf LASTLOG_ENTRY_SIZE), and you'll see it matches roughly the size of your lastlog file.

Fixes and prevention

  • Stick to low, contiguous UIDs: Ubuntu defaults to assigning UIDs starting at 1000 for regular users. Creating users within this range keeps lastlog and faillog small and manageable.
  • If you already have the problem:
    1. If the large UID user isn't needed, delete them with sudo userdel <username>.
    2. Truncate the log files (this will erase all historical login/failure data):
      sudo truncate -s 0 /var/log/lastlog
      sudo truncate -s 0 /var/log/faillog
      
    3. Restore the correct permissions (the files should be owned by root:utmp with mode 664):
      sudo chown root:utmp /var/log/lastlog /var/log/faillog
      sudo chmod 664 /var/log/lastlog /var/log/faillog
      

内容的提问来源于stack exchange,提问作者daroo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:21:42