mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
12 hours ago ee4d71362d092943da3d38bbff5956d785c6b758
[#1144] Widen the ephemeral port range before the benchmark runs (#1145)

BIND opens a new connection per iteration, and docker-proxy relays each one to
the container over a second connection from an ephemeral port. At ~500 binds/s
and 60 s of TIME_WAIT that leg outgrows the default range (32768-60999) within a
minute; the proxy then drops new connections and BIND fails with "LDAP
connection has been closed".

Before the benchmarks of compare-opendj.sh and of the OpenLDAP vs OpenDJ
workflow run, set net.ipv4.ip_local_port_range to 1024-65535 and enable
net.ipv4.tcp_tw_reuse.

Fixes #1144
2 files modified
17 ■■■■■ changed files
.github/benchmark/compare-opendj.sh 8 ●●●●● patch | view | raw | blame | history
.github/workflows/benchmark.yml 9 ●●●●● patch | view | raw | blame | history
.github/benchmark/compare-opendj.sh
@@ -50,6 +50,14 @@
  tar -xzf /tmp/jmeter.tgz -C "$HOME/jmeter"
fi
# ---------------------------------------------------------------- ephemeral ports
# BIND opens a new connection per iteration (~500/s), and docker-proxy relays each one to the
# container over a second connection from an ephemeral port. With the default range
# (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and BIND then
# fails with "LDAP connection has been closed". Widen the range and let connect() reuse
# TIME_WAIT ports.
sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1
# Poll OpenDJ readiness on localhost:1389. An image with a HEALTHCHECK has to report healthy
# first: on a first start the server the bootstrap started answers, then is stopped and
# started again, and a request sent in between fails. An older image's health check
.github/workflows/benchmark.yml
@@ -94,6 +94,15 @@
          fi
          echo "JMETER_BIN=$HOME/jmeter/apache-jmeter-$JMETER/bin/jmeter" >> "$GITHUB_ENV"
      - name: Widen the ephemeral port range
        run: |
          # BIND opens a new connection per iteration, and docker-proxy relays each one to the
          # container over a second connection from an ephemeral port. With the default range
          # (32768-60999) and 60 s of TIME_WAIT that leg runs out of ports within a minute, and
          # BIND then fails with "LDAP connection has been closed". Widen the range and let
          # connect() reuse TIME_WAIT ports.
          sudo sysctl -w net.ipv4.ip_local_port_range="1024 65535" net.ipv4.tcp_tw_reuse=1
      - name: Start OpenLDAP
        run: |
          docker run -d --name openldap -p 2389:389 \