Decode Linux acct(5) Process Accounting Files

acct(5) describes the binary record Linux writes every time a process exits, and misreading that record as a text log will cost you an afternoon. You will identify the format, inspect a file without changing it, and decode the fields with the right units.

The examples follow the installed acct(5) page from Linux man-pages 6.7. Allow about fifteen minutes for inspection. Enabling accounting is a separate, privileged change and is not required for the read-only checks here.

1. Establish which format you are dealing with

Process accounting writes one binary record when a process terminates. The file is not a configuration file and it does not have a line-oriented format. The kernel can write the original record layout or the optional version 3 layout: version 3 has wider user and group IDs and adds process and parent-process IDs.

The manual page documents the format, but it also warns that process accounting is not standardised and varies between systems. Do not decode an old file by copying a structure from a different operating system. First record the host and header versions:

$ uname -a
$ getconf CLK_TCK
$ dpkg-query -W -f='${Package} ${Version}\n' manpages
manpages 6.7-2

The package line above is an example from the system used to prepare this guide. Your package revision can differ. getconf CLK_TCK matters because the legacy ac_utime, ac_stime and ac_etime fields are measured in clock ticks, not seconds.

Checkpoint: write down the kernel, man-pages version and clock-tick value beside any decoded report. That small record prevents a later reader from mistaking local assumptions for a portable file specification.

2. Locate the file without assuming a path

The acct(5) page uses /var/log/pacct as an example pathname, not as a guaranteed default. A file may be elsewhere, and a host may not have process accounting enabled at all. Check candidate paths as an ordinary user first:

$ for path in /var/log/pacct /var/account/pacct; do
>     if test -e "$path"; then
>         stat --printf='%n %s bytes mode %a\n' "$path"
>     fi
> done

No output means those two candidates do not exist. It does not prove that accounting is disabled. If you have a path supplied by the system administrator, inspect that exact path instead of creating a new file.

Warning: do not use cat on the file and do not open it in an editor. The records contain binary integers and, in version 3, a binary floating-point elapsed-time field. Text tools can display misleading characters and make it easy to overwrite or truncate the evidence.

3. Inspect size, ownership and a small byte sample

Use metadata and a bounded read to establish whether the file is readable and whether it is changing. These commands do not alter the file:

$ PACCT='/var/log/pacct'
$ test -r "$PACCT" && echo readable
$ stat --printf='size=%s bytes owner=%U group=%G mode=%a\n' "$PACCT"
$ od -An -tx1 -N 64 "$PACCT"
$ stat --printf='size=%s bytes\n' "$PACCT"
size=... bytes owner=root group=adm mode=640
 ...

Replace the placeholder path with the file you were given. The first and last size checks are a useful quick test: if they differ, records are arriving while you inspect the file. That is normal on a busy system. Take a copy for repeatable analysis, but ask the owner whether the accounting file contains sensitive command and identity data before moving it to another host.

Security warning: a permission failure is not a reason to make the file world-readable. Ask for temporary read access or have an administrator perform the bounded copy. Process accounting records can expose usernames, command names, process relationships and timing.

4. Decode the fields with the correct units

The legacy layout includes flags, 16-bit user and group IDs, a controlling terminal, process start time, CPU and elapsed times, average memory, page faults, exit status and a command basename. The time fields use the compact comp_t type. It stores a 13-bit mantissa and a 3-bit base-8 exponent, so it is not a normal integer.

For a compact value c, the manual gives this conversion to a tick count:

unsigned long ticks = (c & 0x1fff) << (((c >> 13) & 0x7) * 3);

Convert ticks to seconds using the host's CLK_TCK, not a hard-coded value. The legacy structure also documents the I/O and swap fields as unused. Do not present zero in those fields as proof that a process performed no I/O or swaps.

For version 3, read the version byte and use the version 3 layout only when the file and producer agree on it. Version 3 includes real UID and GID values, PID, PPID and a floating-point elapsed time. Its records are not interchangeable with the legacy structure merely because both contain a command name.

5. Interpret flags and ordering carefully

The accounting flag is a bit field, not a single status code. A record with several bits set must be reported with several meanings:

Records are ordered by process termination time. They are not ordered by start time, PID or parent process. A child can therefore appear before its parent, and a long-running process can appear after many processes that started later. Use the start-time field and, where available, the version 3 PID and PPID fields when reconstructing an event.

Since Linux 2.6.10, threaded programs normally produce one accounting record for the whole process when the last thread terminates. Older Linux versions could produce a record for each NPTL thread. Be explicit about that boundary when comparing historical files.

6. Check low-space policy before changing anything

The kernel setting at /proc/sys/kernel/acct controls what happens when the filesystem containing the accounting file is short of space. Read it without elevated privileges where permitted:

$ cat /proc/sys/kernel/acct
4 2 30

The three values are the percentage of free space at which accounting stops, the percentage at which it resumes, and the frequency in seconds for checking. Exact values are host configuration, so report what your machine returns rather than copying the example into a report.

Warning: do not write to this proc file as part of an inspection. Changing it affects kernel accounting behaviour and can hide a disk-full condition. If you must alter the policy, record the current value first, obtain the normal administrator approval, and keep a tested recovery value. A read-only guide has no undo operation because it makes no state change.

Done means