On Mon, Jul 13, 2015 at 10:52:46PM +0930, Jack Burton wrote: > > > > I don't pretend to know httpd (at all), but I'm wondering, what should > > fstat(1) say, over time, for the httpd processes? > > Thanks Tor -- that was exactly the clue I needed to isolate the > problem. > > [snip] > > admin talks to a custom FastCGI daemon, which is most likely the culprit > -- I'll debug it tomorrow. > > "portal" (the other HTTPS server) also talks to a (different) custom > FastCGI daemon, but carries orders of magnitude more traffic and didn't > have any stale sockets -- so clearly our problem is at the other end of > admin's FastCGI socket (not with httpd itself). Sorry for the noise. > > Ted -- similarly, you may want to look into whatever is at the other end > of your "server1"'s FastCGI socket. If your issue is the same as ours, > that's likely where you'll find the cause. >
I am not sure you should conclude yet. I don't use FastCGI. ;-} Now, as I write, I have 218 open fd's, compared to the 206 or whatever I had in my previous post. I've got a few "dangling" :443 streams (the :80 ones seem to disappear like they should), and then a bunch of these: www httpd 17244 213* internet stream tcp 0x0 *:0 While I have been writing this, the recent (since this morning) fd's have looked like this ('$' denotes end of list): www httpd 17244 206* internet stream tcp 0x0 193.214.208.180:443 <-- 193.214.208.185:57311 www httpd 17244 207* internet stream tcp 0x0 *:0 www httpd 17244 208* internet stream tcp 0x0 *:0 www httpd 17244 209* internet stream tcp 0x0 *:0 www httpd 17244 210* internet stream tcp 0x0 *:0 www httpd 17244 211* internet stream tcp 0x0 *:0 www httpd 17244 212* internet stream tcp 0x0 *:0 www httpd 17244 213* internet stream tcp 0x0 *:0 www httpd 17244 214* internet stream tcp 0x0 193.214.208.180:80 <-- 66.249.78.231:59307 $ www httpd 17244 206* internet stream tcp 0x0 193.214.208.180:443 <-- 193.214.208.185:57311 www httpd 17244 207* internet stream tcp 0x0 *:0 www httpd 17244 208* internet stream tcp 0x0 *:0 www httpd 17244 209* internet stream tcp 0x0 *:0 www httpd 17244 210* internet stream tcp 0x0 *:0 www httpd 17244 211* internet stream tcp 0x0 *:0 www httpd 17244 212* internet stream tcp 0x0 *:0 www httpd 17244 213* internet stream tcp 0x0 *:0 $ Notice how 214 (:80) closed and went away. A few minutes later, I have these: www httpd 17244 206* internet stream tcp 0x0 193.214.208.180:443 <-- 193.214.208.185:57311 www httpd 17244 207* internet stream tcp 0x0 *:0 www httpd 17244 208* internet stream tcp 0x0 *:0 www httpd 17244 209* internet stream tcp 0x0 *:0 www httpd 17244 210* internet stream tcp 0x0 *:0 www httpd 17244 211* internet stream tcp 0x0 *:0 www httpd 17244 212* internet stream tcp 0x0 *:0 www httpd 17244 213* internet stream tcp 0x0 *:0 www httpd 17244 214* internet stream tcp 0x0 193.214.208.180:443 <-- 86.129.139.178:60804 $ www httpd 17244 206* internet stream tcp 0x0 193.214.208.180:443 <-- 193.214.208.185:57311 www httpd 17244 207* internet stream tcp 0x0 *:0 www httpd 17244 208* internet stream tcp 0x0 *:0 www httpd 17244 209* internet stream tcp 0x0 *:0 www httpd 17244 210* internet stream tcp 0x0 *:0 www httpd 17244 211* internet stream tcp 0x0 *:0 www httpd 17244 212* internet stream tcp 0x0 *:0 www httpd 17244 213* internet stream tcp 0x0 *:0 www httpd 17244 214* internet stream tcp 0x0 *:0 www httpd 17244 215* internet stream tcp 0x0 *:0 www httpd 17244 216* internet stream tcp 0x0 193.214.208.180:443 <-- 86.129.139.178:61345 $ FWIW, the following is a dump from some earlier connections from the same client (they look too short): 07:23:48.292311 193.214.208.180.443 > 86.129.139.178.51968: S 4293888040:4293888040(0) ack 147006770 win 16384 <mss 1460,nop,nop,sackOK,nop,wscale 3> (DF) 0000: 4500 0034 2113 4000 4006 a4f2 c1d6 d0b4 E..4!.@.@....... 0010: 5681 8bb2 01bb cb00 ffef 8828 08c3 2532 V..........(..%2 0020: 8012 4000 377d 0000 0204 05b4 0101 0402 ..@.7}.......... 0030: 0103 0303 .... 07:23:48.345674 86.129.139.178.51968 > 193.214.208.180.443: . ack 1 win 16698 (DF) 0000: 4500 0028 5a8a 4000 7206 3987 5681 8bb2 E..(Z.@.r.9.V... 0010: c1d6 d0b4 cb00 01bb 08c3 2532 ffef 8829 ..........%2...) 0020: 5010 413a 7711 0000 dd2d 0000 0000 P.A:w....-.... 07:23:48.346721 86.129.139.178.51968 > 193.214.208.180.443: P 1:116(115) ack 1 win 16698 (DF) 0000: 4500 009b 5a8b 4000 7206 3913 5681 8bb2 E...Z.@.r.9.V... 0010: c1d6 d0b4 cb00 01bb 08c3 2532 ffef 8829 ..........%2...) 0020: 5018 413a 0813 0000 1603 0100 6e01 0000 P.A:........n... 0030: 6a03 0155 9e05 48fa 033a 70a9 351e 8015 j..U..H..:p.5... 0040: 97b8 4deb ad29 538c effc 13be 7c2d eea5 ..M..)S.....|-.. 0050: c00a d400 0018 002f 0035 0005 000a c009 ......./.5...... 0060: c00a c013 c014 0032 0038 0013 0004 0100 .......2.8...... 0070: 0029 0000 000e 000c 0000 0962 6f67 7573 .).........bogus 0080: 2e6e 6574 000a 0008 0006 0017 0018 0019 .net............ 0090: 000b 0002 0100 ff01 0001 00 ........... 07:23:48.350817 193.214.208.180.443 > 86.129.139.178.51968: P 1:8(7) ack 116 win 2178 (DF) 0000: 4500 002f 368b 4000 4006 8f7f c1d6 d0b4 E../6.@.@....... 0010: 5681 8bb2 01bb cb00 ffef 8829 08c3 25a5 V..........)..%. 0020: 5018 0882 74e0 0000 1503 0100 0202 28 P...t.........( 07:23:48.403677 86.129.139.178.51969 > 193.214.208.180.443: S 3771038199:3771038199(0) win 8192 <mss 1452,nop,wscale 2,nop,nop,sackOK> (DF) 0000: 4500 0034 5a8d 4000 7206 3978 5681 8bb2 E..4Z.@.r.9xV... 0010: c1d6 d0b4 cb01 01bb e0c5 79f7 0000 0000 ..........y..... 0020: 8002 2000 b2e5 0000 0204 05ac 0103 0302 .. ............. 0030: 0101 0402 .... 07:23:48.403881 193.214.208.180.443 > 86.129.139.178.51969: S 3568087258:3568087258(0) ack 3771038200 win 16384 <mss 1460,nop,nop,sackOK,nop,wscale 3> (DF) 0000: 4500 0034 fd68 4000 4006 c89c c1d6 d0b4 E..4.h@.@....... 0010: 5681 8bb2 01bb cb01 d4ac b0da e0c5 79f8 V.............y. 0020: 8012 4000 0d44 0000 0204 05b4 0101 0402 ..@..D.......... 0030: 0103 0303 .... 07:23:48.405379 86.129.139.178.51968 > 193.214.208.180.443: F 116:116(0) ack 8 win 16696 (DF) 0000: 4500 0028 5a8c 4000 7206 3985 5681 8bb2 E..(Z.@.r.9.V... 0010: c1d6 d0b4 cb00 01bb 08c3 25a5 ffef 8830 ..........%....0 0020: 5011 4138 7698 0000 e78b 0000 0000 P.A8v......... 07:23:48.405496 193.214.208.180.443 > 86.129.139.178.51968: . ack 117 win 2178 (DF) 0000: 4500 0028 3f45 4000 4006 86cc c1d6 d0b4 E..(?E@.@....... 0010: 5681 8bb2 01bb cb00 ffef 8830 08c3 25a6 V..........0..%. 0020: 5010 0882 74d9 0000 P...t... 07:23:48.455731 86.129.139.178.51969 > 193.214.208.180.443: . ack 1 win 16698 (DF) 0000: 4500 0028 5a8e 4000 7206 3983 5681 8bb2 E..(Z.@.r.9.V... 0010: c1d6 d0b4 cb01 01bb e0c5 79f8 d4ac b0db ..........y..... 0020: 5010 413a 4cd8 0000 b5c4 0000 0000 P.A:L......... 07:23:48.456175 86.129.139.178.51969 > 193.214.208.180.443: F 1:1(0) ack 1 win 16698 (DF) 0000: 4500 0028 5a8f 4000 7206 3982 5681 8bb2 E..(Z.@.r.9.V... 0010: c1d6 d0b4 cb01 01bb e0c5 79f8 d4ac b0db ..........y..... 0020: 5011 413a 4cd7 0000 d046 0000 0000 P.A:L....F.... 07:23:48.456402 193.214.208.180.443 > 86.129.139.178.51969: . ack 2 win 2178 (DF) 0000: 4500 0028 92e2 4000 4006 332f c1d6 d0b4 E..(..@.@.3/.... 0010: 5681 8bb2 01bb cb01 d4ac b0db e0c5 79f9 V.............y. 0020: 5010 0882 74d9 0000 P...t... 07:25:48.453812 86.129.139.178.51968 > 193.214.208.180.443: R 117:117(0) ack 8 win 0 (DF) 0000: 4500 0028 5b05 4000 7206 390c 5681 8bb2 E..([.@.r.9.V... 0010: c1d6 d0b4 cb00 01bb 08c3 25a6 ffef 8830 ..........%....0 0020: 5014 0000 b7cc 0000 e4c6 0000 0000 P............. 07:25:48.502315 86.129.139.178.51969 > 193.214.208.180.443: R 2:2(0) ack 1 win 0 (DF) 0000: 4500 0028 5b06 4000 7206 390b 5681 8bb2 E..([.@.r.9.V... 0010: c1d6 d0b4 cb01 01bb e0c5 79f9 d4ac b0db ..........y..... 0020: 5014 0000 8e0d 0000 9c74 0000 0000 P........t.... Kind regards, Tor