Skip to content

Benchmark BIND fails with "LDAP connection has been closed" once docker-proxy runs out of ephemeral ports #1144

Description

@vharseko

In run 36776405938 (PR #1125) the Build-alpine vs Release-alpine benchmark recorded 1911 and 1047 failed BIND samples: 800 javax.naming.NamingException: LDAP connection has been closed. The two images failed the same way, and every other operation had 0 errors. The connection was established (Connect = 0) and then dropped. The failures start 70–80 s into the run and come in bursts. In the PR runs for #1131, #1133 and #1135 the count was 0, but their throughput was 2950–3190 tests/s against 3590–3650 here.

BIND (test=sbind) opens a new connection on every iteration, about 1/7 of all samples, so roughly 515 new connections per second. With -p 1389:1389, every connection to localhost goes through docker-proxy, which opens a second connection to the container from an ephemeral port. Over 60 s of TIME_WAIT that adds up to ~31k sockets, above the default Linux range of 32768–60999 (28 232 ports). The proxy then cannot reach the container and closes the client connection. This explanation is inferred from the numbers; the TIME_WAIT count was not measured.

Proposed fix: before the benchmark runs, widen net.ipv4.ip_local_port_range to 1024–65535 and enable net.ipv4.tcp_tw_reuse.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions