Conversation
… benchmark runs BIND opens a new connection per iteration, and docker-proxy relays each one to the container over a second connection from an ephemeral port. At ~500 binds/s and 60 s of TIME_WAIT that leg outgrows the default range (32768-60999) within a minute; the proxy then drops new connections and BIND fails with "LDAP connection has been closed". Before the benchmarks of compare-opendj.sh and of the OpenLDAP vs OpenDJ workflow run, set net.ipv4.ip_local_port_range to 1024-65535 and enable net.ipv4.tcp_tw_reuse. Fixes OpenIdentityPlatform#1144
maximthomas
approved these changes
Oct 1, 2026
maximthomas
left a comment
Contributor
There was a problem hiding this comment.
praise: The setting goes in before any server starts, on both benchmark paths.
.github/benchmark/compare-opendj.sh:59sits after the dependency block and before the firstbench_one, so all threebuild.ymlbenchmarks (je vs pdb, Build vs Release inbuild-dockerandbuild-docker-alpine) run with it..github/workflows/benchmark.yml:97-104runs the step before "Start OpenLDAP", so OpenLDAP and OpenDJ are both measured with the same settings. Ports 1389/2389 now fall inside the range, butconnect()does not take them: Linux scans ports of the low bound's parity first and skips ports that are already bound.
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1144
Problem
The
BINDsampler of the LDAP benchmark opens a new connection on every iteration, about 500 per second at the current CI throughput. With-p 1389:1389, docker-proxy relays each connection to the container over a second connection from an ephemeral port. With 60 s of TIME_WAIT, that leg outgrows the default range (32768–60999, 28 232 ports) within about a minute. The proxy then drops new connections, andBINDfails withLDAP connection has been closed: 1911 and 1047 failures in run 36776405938.Change
Before the benchmarks run, set:
net.ipv4.ip_local_port_range="1024 65535", which roughly doubles the number of ephemeral ports;net.ipv4.tcp_tw_reuse=1, which letsconnect()reuse ports held in TIME_WAIT.The settings go in:
.github/benchmark/compare-opendj.sh, used by all three benchmarks inbuild.yml(je vs pdb and Build vs Release inbuild-docker, Build vs Release inbuild-docker-alpine);.github/workflows/benchmark.yml(OpenLDAP vs OpenDJ), as a separate step before the servers start.Verification
bash -non the script and a YAML parse of the workflow both pass.compare-opendj.sh.benchmark.ymlruns only onworkflow_dispatchor after Release.