-
heston76
Alrighty, everything is now update to 15.1-STABLE
-
elivoncoder
nice
-
elivoncoder
im still rc3 going to reinstall later just because
-
elivoncoder
well not rc
-
skered
Well that wasn't dramatic. pkgbasify was quick and just worked.
-
rtprio
yep
-
hc
rtprio: Welcome to the world of scientific research. I've been using nixos since 2016 on various systems, including nixos unstable on my work laptop. Though I'm conservative when it comes to running production servers and still prefer a more proven system there
-
hc
There's a lot of interest in systems like nix in the functional programming research community, too
-
Aedil
I did it. My VM is on 15.1-RELEASE.
-
MelanieUrsidino
scientific research‽
-
hc
-
MelanieUrsidino
o_O
-
Macer
i've never seen a p0 release
-
Macer
is that from the bug that was sent out in the mailing list a couple days ago?
-
voy4g3r2
hc: have you looked at the software bill of material (SBOM)? The concept of being able to "track" software and its dependencies have always been a "fun" avenue as inconsistencies are that constant variable to balance.. back to reading it a little more
-
hc
voy4g3r2: Haven't looked into it beyond briefly trying out syft, but it seems to have limited support for .cabal files
-
hc
I like the idea of sbom. It is an attempt to make an important aspect of software security (transitive dependency versions) more visible
-
td123
just upgraded a vm from 15.0 to 15.1 using freebsd-update and it went smoothly, thanks for making this process so easy
-
DarkUranium
Q. I'm debugging something, and I need to be sure --- does `fetch` do keep-alive / reuse connection if I call it multiple times on the same site in a short timespan?
-
DarkUranium
Or is each run of `fetch` a new connection, always?
-
hc
You mean the command fetch as in /usr/bin/fetch? The shell should fork,exec on each invocation, how can it preserve state and reuse a connection?
-
DarkUranium
hc: Correct. And you never know, there could (in principle) be a `fetchd` to preserve it over short timespans, or the process forks a background process that stays around for a minute or so with some per-site socket.
-
DarkUranium
Just doing a sanity check because I'm dealing with a heisenbug of networking ......
-
DarkUranium
(TL;DR most fetches work, occasionally I get a "connection reset by peer" ...... to an internal [to bhyve/VM] network)
-
DarkUranium
(my reverse proxy is even weirder, it's pretty consistently every 2nd request that fails)
-
hc
DarkUranium: true. I don't know fetch enough to be able to say with certainty, though I'd be really surprised
-
DarkUranium
Same, but at this point, I felt like I needed the sanity check.
-
DarkUranium
The issue's driving me crazy >_<
-
hc
Yeah, I know you need a sanity check; you need absolute certainty and I can't help you with that
-
DarkUranium
Fair, thanks anyway ^^
-
DarkUranium
Okay, this is weeeeeeeeeird.
-
DarkUranium
The jail has a 3.8-12% packet loss (too small sample size to tell for sure) to a *container in VM on the same machine*.
-
DarkUranium
The host (of the jail) has 0.0%.
-
scoobybejesus
Maybe too early to start asking this, but intel or Realtek nic?
-
DarkUranium
scoobybejesus: It doesn't go via the NIC, it's jail -> host -> bhyve VM -> container
-
DarkUranium
But I can check if it matters.
-
hc
DarkUranium: Have you run fetch with -v yet? It should give you some clues as to whether it uses connection keep alice
-
hc
I just ran it with two URLs and it looks like even when specifying two URLs in one go to the same host it will establish two connections in sequence
-
hc
(-vv might be more helpful even)
-
DarkUranium
Apparently, I was being DoS'd yesterday. But that was yesterday.
-
DarkUranium
Okay, I *think* I managed to get a bit further.
-
DarkUranium
`ping` form the jail has a packet loss. `ping` from host does not.
-
DarkUranium
(seems to be kinda random, 0-12%)
-
DarkUranium
traceroute is different, from the jail, it goes via 10.88.0.1, a bridge
-
sig`
DarkUranium: and your virtual network path issue?
-
DarkUranium
sig`: Hm? Er, which path issue?
-
sig`
DarkUranium: your host will be good because the jail has loss because only the jail path crosses epair and bridge
-
sig`
vnet jails use their own isolated net stack and epair/bridge
-
sig`
just learned this too
-
DarkUranium
Sure, but I'd expect 0% loss since it's not an *actual* cable. But maybe.
-
DarkUranium
Either way, the packet loss is no longer showing up *at all*, *ever* (as of a re-test a minute ago) ...... but nginx is still getting reset connections.
-
DarkUranium
hc: FWIW, not only does it *not* use Keep-Alive, it actually sends `Connection: close` explicitly.
-
DarkUranium
So it's safe to say there's no reuse, at least.
-
sig`
hmm, tcp connections being reset?
-
DarkUranium
Yeah, to summarize (to put it all in 1 place again):
-
DarkUranium
My setup is `jail (nginx reverse proxy) -> bhyve VM -> Linux -> container`, in terms of what connects to what.
-
DarkUranium
All but 1 container have this problem. 1 works, in the same Linux system. No idea why.
-
DarkUranium
(out of 5 or so)
-
DarkUranium
Every 2nd request (or so, so far it seems like it's *actually* every 2nd request, but that's hard to confirm), nginx gets me a "502 Bad Gateway" in the browser, and logs it as: kevent() reported about an closed connection (54: Connection reset by peer) while reading response header from upstream,
-
DarkUranium
Upstream IP is correct in the log, so it's not some weird round-robining going on in nginx.
-
sig`
probably not nginx....
-
sig`
nginx shows the coorect upstream ip?
-
DarkUranium
Exactly. I'm thinking either keepalive (between nginx/proxy & backend, not user & proxy) or a firewall misconfiguration or an IP conflict.
-
sig`
any old upstream connections?
-
DarkUranium
No, because I also tried restarting nginx and such.
-
sig`
-
DarkUranium
In fact, *reloading* (not even restarting) nginx's config on the proxy seems to pretty reliably make the next request fail.
-
sig`
DarkUranium: ok
-
DarkUranium
(but not 100% reliably, nothing's 100% here, sadly ... which is why I'm struggling with diagnosing it)
-
sig`
you have 1 jail working well out of the 5?
-
DarkUranium
1 Linux (podman) container, but yes.
-
DarkUranium
The only difference, AFAICT, is that the one that works well uses a non-wildcard certificate. But I don't see how that could *possibly* affect the connection in this way.
-
sig`
compare the working one app runtime with the broke ones?
-
nimaje
hm, can you share more of your networking setup (ifconfig and routing tables)?
-
sig`
have you tried disabling upstream keepalive to see if that fixes it
-
DarkUranium
Good point, I've not done it at upstream yet.
-
DarkUranium
... so, disabling keepalive makes it not work at all. Which makes sense as to why reloading would break things (presumably, it drops keepalive connections due to [potential] config changes)
-
sig`
ah yeah
-
DarkUranium
Every 2nd request is how 504 Gateway Time-out. So it goes 502 -> 504 -> 502 -> 504, instead of 502 -> ok -> 502 -> ok
-
mosaid
HI
-
voy4g3r2
DarkUranium: a few thoughts 1.) is your network topology setup 2.) what type of firewall setup? 3.) what network card
-
voy4g3r2
for example.. host firewall and then have a firewall that is on the individual vnet jails itself.. unwinding what you can on the network and what is the number of interfaces and bridges that you are using..
-
DarkUranium
voy4g3r2: It's an Intel i210, but note that none of the traffic passes through it.
-
DarkUranium
None that's relevant to the problem at hand, anyway. The issue is between the reverse proxy and the contain behind it.
-
mosaid
I want to ask a question.. could I but every part of my system in separate partition like usr, var, tmp.. and get a fresh 14 version on usb
-
mosaid
then upgrade through it
-
DarkUranium
s/contain/container/
-
mosaid
or will go into problem for?
-
DarkUranium
voy4g3r2: it's pf on FreeBSD end, iptables on Linux/VM.
-
DarkUranium
Podman in Linux as well.
-
DarkUranium
So, turns out it *does* reach the backend after all. It was misconfigured and hiding error_log.
-
DarkUranium
> [info] 345#345: *783 epoll_wait() reported that client prematurely closed connection, so upstream connection is closed too (104: Connection reset by peer) while connecting to upstream
-
DarkUranium
(this is backend's own frontend)
-
DarkUranium
In other words: proxy thinks the backend closed the connection prematurely, and the backend thinks the proxy did it.
-
ridcully
does anyone know how to completely remove a previously `fetch`ed release with AppJail? i used `appjail fetch destroy -v $v default` and it's not longer in the list, but there are still three datasets mounted with $v in the name
-
rwp
Is the tool expecting you to destroy the datasets manually?
-
ridcully
it removes other dataset(s) correlating to $v. so my options are to just remove the other residue myself, create a ticket/minimal example or investigate the source. my hope was, that i am not the only one using AppJail around here