Skip to content

[#1144] Widen the ephemeral port range before the benchmark runs - #1145

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue-1144-benchmark-ephemeral-ports
Oct 1, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issue-1144-benchmark-ephemeral-ports

Conversation

@vharseko

@vharseko vharseko commented Oct 1, 2026

Copy link
Copy Markdown
Member

Fixes #1144

Problem

The BIND sampler of the LDAP benchmark opens a new connection on every iteration, about 500 per second at the current CI throughput. With -p 1389:1389, docker-proxy relays each connection to the container over a second connection from an ephemeral port. With 60 s of TIME_WAIT, that leg outgrows the default range (32768–60999, 28 232 ports) within about a minute. The proxy then drops new connections, and BIND fails with LDAP connection has been closed: 1911 and 1047 failures in run 36776405938.

Change

Before the benchmarks run, set:

  • net.ipv4.ip_local_port_range="1024 65535", which roughly doubles the number of ephemeral ports;
  • net.ipv4.tcp_tw_reuse=1, which lets connect() reuse ports held in TIME_WAIT.

The settings go in:

  • .github/benchmark/compare-opendj.sh, used by all three benchmarks in build.yml (je vs pdb and Build vs Release in build-docker, Build vs Release in build-docker-alpine);
  • .github/workflows/benchmark.yml (OpenLDAP vs OpenDJ), as a separate step before the servers start.

Verification

  • bash -n on the script and a YAML parse of the workflow both pass.
  • The benchmarks of this PR's own Build run exercise compare-opendj.sh. benchmark.yml runs only on workflow_dispatch or after Release.
  • One green run does not prove the fix: below ~3600 tests/s the failures did not appear before either. The port-exhaustion explanation is inferred from the throughput numbers; the TIME_WAIT count was not measured.

… benchmark runs

BIND opens a new connection per iteration, and docker-proxy relays each one to
the container over a second connection from an ephemeral port. At ~500 binds/s
and 60 s of TIME_WAIT that leg outgrows the default range (32768-60999) within a
minute; the proxy then drops new connections and BIND fails with "LDAP
connection has been closed".

Before the benchmarks of compare-opendj.sh and of the OpenLDAP vs OpenDJ
workflow run, set net.ipv4.ip_local_port_range to 1024-65535 and enable
net.ipv4.tcp_tw_reuse.

Fixes OpenIdentityPlatform#1144

@maximthomas maximthomas left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

praise: The setting goes in before any server starts, on both benchmark paths.

  • .github/benchmark/compare-opendj.sh:59 sits after the dependency block and before the first bench_one, so all three build.yml benchmarks (je vs pdb, Build vs Release in build-docker and build-docker-alpine) run with it.
  • .github/workflows/benchmark.yml:97-104 runs the step before "Start OpenLDAP", so OpenLDAP and OpenDJ are both measured with the same settings. Ports 1389/2389 now fall inside the range, but connect() does not take them: Linux scans ports of the low bound's parity first and skips ports that are already bound.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Benchmark BIND fails with "LDAP connection has been closed" once docker-proxy runs out of ephemeral ports

2 participants