diff --git a/.github/benchmark/compare-opendj.sh b/.github/benchmark/compare-opendj.sh index e8321f1d5e..cadb47fb2d 100644 --- a/.github/benchmark/compare-opendj.sh +++ b/.github/benchmark/compare-opendj.sh @@ -50,6 +50,14 @@ if [ ! -x "$JM" ]; then tar -xzf /tmp/jmeter.tgz -C "$HOME/jmeter" fi +# ---------------------------------------------------------------- ephemeral ports +# BIND opens a new connection per iteration (~500/s), and docker-proxy relays each one to the +# container over a second connection from an ephemeral port. With the default range +# (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and BIND then +# fails with "LDAP connection has been closed". Widen the range and let connect() reuse +# TIME_WAIT ports. +sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1 + # Poll OpenDJ readiness on localhost:1389. An image with a HEALTHCHECK has to report healthy # first: on a first start the server the bootstrap started answers, then is stopped and # started again, and a request sent in between fails. An older image's health check diff --git a/.github/workflows/benchmark.yml b/.github/workflows/benchmark.yml index 58efae20e1..85cf736345 100644 --- a/.github/workflows/benchmark.yml +++ b/.github/workflows/benchmark.yml @@ -94,6 +94,15 @@ jobs: fi echo "JMETER_BIN=$HOME/jmeter/apache-jmeter-$JMETER/bin/jmeter" >> "$GITHUB_ENV" + - name: Widen the ephemeral port range + run: | + # BIND opens a new connection per iteration, and docker-proxy relays each one to the + # container over a second connection from an ephemeral port. With the default range + # (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and + # BIND then fails with "LDAP connection has been closed". Widen the range and let + # connect() reuse TIME_WAIT ports. + sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1 + - name: Start OpenLDAP run: | docker run -d --name openldap -p 2389:389 \