From 90b3c8917e27983e405f6550e92559f6ad665d52 Mon Sep 17 00:00:00 2001 From: Valera V Harseko Date: Thu, 1 Oct 2026 12:47:36 +0300 Subject: [PATCH] [#1144] Widen the ephemeral port range before the benchmark runs BIND opens a new connection per iteration, and docker-proxy relays each one to the container over a second connection from an ephemeral port. At ~500 binds/s and 60 s of TIME_WAIT that leg outgrows the default range (32768-60999) within a minute; the proxy then drops new connections and BIND fails with "LDAP connection has been closed". Before the benchmarks of compare-opendj.sh and of the OpenLDAP vs OpenDJ workflow run, set net.ipv4.ip_local_port_range to 1024-65535 and enable net.ipv4.tcp_tw_reuse. Fixes #1144 --- .github/benchmark/compare-opendj.sh | 8 ++++++++ .github/workflows/benchmark.yml | 9 +++++++++ 2 files changed, 17 insertions(+) diff --git a/.github/benchmark/compare-opendj.sh b/.github/benchmark/compare-opendj.sh index e8321f1d5e..cadb47fb2d 100644 --- a/.github/benchmark/compare-opendj.sh +++ b/.github/benchmark/compare-opendj.sh @@ -50,6 +50,14 @@ if [ ! -x "$JM" ]; then tar -xzf /tmp/jmeter.tgz -C "$HOME/jmeter" fi +# ---------------------------------------------------------------- ephemeral ports +# BIND opens a new connection per iteration (~500/s), and docker-proxy relays each one to the +# container over a second connection from an ephemeral port. With the default range +# (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and BIND then +# fails with "LDAP connection has been closed". Widen the range and let connect() reuse +# TIME_WAIT ports. +sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1 + # Poll OpenDJ readiness on localhost:1389. An image with a HEALTHCHECK has to report healthy # first: on a first start the server the bootstrap started answers, then is stopped and # started again, and a request sent in between fails. An older image's health check diff --git a/.github/workflows/benchmark.yml b/.github/workflows/benchmark.yml index 58efae20e1..85cf736345 100644 --- a/.github/workflows/benchmark.yml +++ b/.github/workflows/benchmark.yml @@ -94,6 +94,15 @@ jobs: fi echo "JMETER_BIN=$HOME/jmeter/apache-jmeter-$JMETER/bin/jmeter" >> "$GITHUB_ENV" + - name: Widen the ephemeral port range + run: | + # BIND opens a new connection per iteration, and docker-proxy relays each one to the + # container over a second connection from an ephemeral port. With the default range + # (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and + # BIND then fails with "LDAP connection has been closed". Widen the range and let + # connect() reuse TIME_WAIT ports. + sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1 + - name: Start OpenLDAP run: | docker run -d --name openldap -p 2389:389 \