Informix Connection Errors
Posted in 2008
Colin Dawson (IDS 9.40 on Solaris) found that repeatedly opening and dropping TCP connections to the server's single listener port (via a Perl port-check script) eventually produced "-25571 ... Cannot create an user thread" and blocked further connections — effectively a denial-of-service, also triggered in production when 2000+ apps auto-reconnected at once. Fernando Nunes pointed to the ONCONFIG parameters MAX_INCOMPLETE_CONNECTIONS and LISTEN_TIMEOUT, added in version 10 to control exactly this, noting they aren't available in 9.40 and that DB ports are normally protected inside the network. No fix for the 9.40 instance itself is recorded.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Platform-Specific Issues, Versions, Editions & End-of-Life
OS: Solaris 9/10
IDS 9.40.FC8X3
After having application connection problems we ran a script on a test instance to simulate a connection to the port. If I run the below script in a loop after approximately 5 mins I get the error:-
11:58:42 listener-thread: err = -25571: oserr = 0: errstr = : Cannot create an user thread. On NT check username and IXUSERS
My question is, should Informix do this, NETTYPE is set to:- tlitcp,2,300,NET. Only 1 port is assigned to this instance and there were 200+ other application connections to the database. This seems an easy way to cripple an instance
The errors on the live server seem to be caused by 2000+ connection attempts occurring simultaneuosly. The application does an automatic reconnect so after starting Informix all apps will immediately attempt a reconnection.
#!/usr/bin/perl
# returns 0 if host is listening on specified tcp port
#
use strict;
use Socket;
# set time until connection attempt times out
my $timeout = 1;
if ($#ARGV != 1) {
print "usage: is_tcp_port_listening hostname portnumber\\n";
exit 2;
}
my $hostname = $ARGV[0];
my $portnumber = $ARGV[1];
my $host = shift || $hostname;
my $port = shift || $portnumber;
my $proto = getprotobyname('tcp');
my $iaddr = inet_aton($host);
my $paddr = sockaddr_in($port, $iaddr);
socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die "socket: $!";
eval {
local $SIG{ALRM} = sub { die "timeout" };
alarm($timeout);
connect(SOCKET, $paddr) || error();
alarm(0);
};
if ($@) {
close SOCKET || die "close: $!";
print "$hostname is NOT listening on tcp port $portnumber.\\n";
exit 1;
}
else {
close SOCKET || die "close: $!";
print "$hostname is listening on tcp port $portnumber.\\n";
exit 0;
}
Regards
Colin
There are 10 types of people in the world, those that understand binary and those that don't
_________________________________________________________________
Are you a PC? Upload your PC story and show the world
http://clk.atdmt.com/UKM/go/122465942/direct/01/
Colin Dawson wrote:
> OS: Solaris 9/10
> IDS 9.40.FC8X3
>
> After having application connection problems we ran a script on a test instance to simulate a connection to the port. If I run the below script in a loop after approximately 5 mins I get the error:-
>
> 11:58:42 listener-thread: err = -25571: oserr = 0: errstr = : Cannot create an user thread. On NT check username and IXUSERS>
> My question is, should Informix do this, NETTYPE is set to:- tlitcp,2,300,NET. Only 1 port is assigned to this instance and there were 200+ other application connections to the database. This seems an easy way to cripple an instance
>
> The errors on the live server seem to be caused by 2000+ connection attempts occurring simultaneuosly. The application does an automatic reconnect so after starting Informix all apps will immediately attempt a reconnection.
>
>
> #!/usr/bin/perl
> # returns 0 if host is listening on specified tcp port
> #
> use strict;
> use Socket;
> # set time until connection attempt times out
> my $timeout = 1;
> if ($#ARGV != 1) {
> print "usage: is_tcp_port_listening hostname portnumber\\n";
> exit 2;
> }
> my $hostname = $ARGV[0];
> my $portnumber = $ARGV[1];
> my $host = shift || $hostname;
> my $port = shift || $portnumber;
> my $proto = getprotobyname('tcp');
> my $iaddr = inet_aton($host);
> my $paddr = sockaddr_in($port, $iaddr);
> socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die "socket: $!";
> eval {
> local $SIG{ALRM} = sub { die "timeout" };
> alarm($timeout);
> connect(SOCKET, $paddr) || error();
> alarm(0);
> };
> if ($@) {
> close SOCKET || die "close: $!";
> print "$hostname is NOT listening on tcp port $portnumber.\\n";
> exit 1;
> }
> else {
> close SOCKET || die "close: $!";
> print "$hostname is listening on tcp port $portnumber.\\n";
> exit 0;
> }
>
>
>
>
>
> Regards
>
> Colin
>
>
> There are 10 types of people in the world, those that understand binary and those that don't
> _________________________________________________________________
> Are you a PC? Upload your PC story and show the world
> http://clk.atdmt.com/UKM/go/122465942/direct/01/
Try it against ... a Web Server port, a telnet port, an email port ... and see what happens to those services :-/
Ran script to port 22 (ssh) I could still connect using ssh to the server Regards Colin There are 10 types of people in the world, those that understand binary and those that don't > From: theBP@Usenet-News.Net> Subject: Re: Informix Connection Errors> Date: Wed, 10 Dec 2008 14:03:08 +0000> To: informix-list@iiug.org> > Colin Dawson wrote:> > OS: Solaris 9/10> > IDS 9.40.FC8X3> > > > After having application connection problems we ran a script on a test instance to simulate a connection to the port. If I run the below script in a loop after approximately 5 mins I get the error:-> > > > 11:58:42 listener-thread: err = -25571: oserr = 0: errstr = : Cannot create an user thread. On NT check username and IXUSERS> > > > My question is, should Informix do this, NETTYPE is set to:- tlitcp,2,300,NET. Only 1 port is assigned to this instance and there were 200+ other application connections to the database. This seems an easy way to cripple an instance> > > > The errors on the live server seem to be caused by 2000+ connection attempts occurring simultaneuosly. The application does an automatic reconnect so after starting Informix all apps will immediately attempt a reconnection.> > > > > > #!/usr/bin/perl> > # returns 0 if host is listening on specified tcp port> > #> > use strict;> > use Socket;> > # set time until connection attempt times out> > my $timeout = 1;> > if ($#ARGV != 1) {> > print "usage: is_tcp_port_listening hostname portnumber\\n";> > exit 2;> > }> > my $hostname = $ARGV[0];> > my $portnumber = $ARGV[1];> > my $host = shift || $hostname;> > my $port = shift || $portnumber;> > my $proto = getprotobyname('tcp');> > my $iaddr = inet_aton($host);> > my $paddr = sockaddr_in($port, $iaddr);> > socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die "socket: $!";> > eval {> > local $SIG{ALRM} = sub { die "timeout" };> > alarm($timeout);> > connect(SOCKET, $paddr) || error();> > alarm(0);> > };> > if ($@) {> > close SOCKET || die "close: $!";> > print "$hostname is NOT listening on tcp port $portnumber.\\n";> > exit 1;> > }> > else {> > close SOCKET || die "close: $!";> > print "$hostname is listening on tcp port $portnumber.\\n";> > exit 0;> > }> > > > > > > > > > > > Regards > > > > Colin > > > > > > There are 10 types of people in the world, those that understand binary and those that don't > > _________________________________________________________________> > Are you a PC? Upload your PC story and show the world > > http://clk.atdmt.com/UKM/go/122465942/direct/01/> > Try it against ... a Web Server port, a telnet port, an email port ... and see what happens to those services :-/> _______________________________________________> Informix-list mailing list> Informix-list@iiug.org> http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Get a bird’s eye view of the world with Multimap http://clk.atdmt.com/GBL/go/115454059/direct/01/
Colin Dawson wrote:
> OS: Solaris 9/10
> IDS 9.40.FC8X3
>
> After having application connection problems we ran a script on a test instance to simulate a connection to the port. If I run the below script in a loop after approximately 5 mins I get the error:-
>
> 11:58:42 listener-thread: err = -25571: oserr = 0: errstr = : Cannot create an user thread. On NT check username and IXUSERS>
> My question is, should Informix do this, NETTYPE is set to:- tlitcp,2,300,NET. Only 1 port is assigned to this instance and there were 200+ other application connections to the database. This seems an easy way to cripple an instance
>
> The errors on the live server seem to be caused by 2000+ connection attempts occurring simultaneuosly. The application does an automatic reconnect so after starting Informix all apps will immediately attempt a reconnection.
>
>
> #!/usr/bin/perl
> # returns 0 if host is listening on specified tcp port
> #
> use strict;
> use Socket;
> # set time until connection attempt times out
> my $timeout = 1;
> if ($#ARGV != 1) {
> print "usage: is_tcp_port_listening hostname portnumber\\n";
> exit 2;
> }
> my $hostname = $ARGV[0];
> my $portnumber = $ARGV[1];
> my $host = shift || $hostname;
> my $port = shift || $portnumber;
> my $proto = getprotobyname('tcp');
> my $iaddr = inet_aton($host);
> my $paddr = sockaddr_in($port, $iaddr);
> socket(SOCKET, PF_INET, SOCK_STREAM, $proto) || die "socket: $!";
> eval {
> local $SIG{ALRM} = sub { die "timeout" };
> alarm($timeout);
> connect(SOCKET, $paddr) || error();
> alarm(0);
> };
> if ($@) {
> close SOCKET || die "close: $!";
> print "$hostname is NOT listening on tcp port $portnumber.\\n";
> exit 1;
> }
> else {
> close SOCKET || die "close: $!";
> print "$hostname is listening on tcp port $portnumber.\\n";
> exit 0;
> }
>
>
>
>
>
> Regards
>
> Colin
>
>
> There are 10 types of people in the world, those that understand binary and those that don't
> _________________________________________________________________
> Are you a PC? Upload your PC story and show the world
> http://clk.atdmt.com/UKM/go/122465942/direct/01/
Please check version 10 ONCONFIG parameters:
MAX_INCOMPLETE_CONNECTIONS
LISTEN_TIMEOUT
They were introduced to deal with this AFAIK.
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
> > Please check version 10 ONCONFIG parameters:> MAX_INCOMPLETE_CONNECTIONS> LISTEN_TIMEOUT> > They were introduced to deal with this AFAIK.> Regards.> > -- > Fernando Nunes This is running on IDS 9.40If these parameters have been introduced to deal with this, does this mean IBM accept it is a problem? _________________________________________________________________ Imagine a life without walls. See the possibilities. http://clk.atdmt.com/UKM/go/122465943/direct/01/
Colin Dawson wrote:
> >
> > Please check version 10 ONCONFIG parameters:
> > MAX_INCOMPLETE_CONNECTIONS
> > LISTEN_TIMEOUT> >
> > They were introduced to deal with this AFAIK.
> > Regards.
> >
> > --
> > Fernando Nunes
>
> This is running on IDS 9.40If these parameters have been introduced to
> deal with this, does this mean IBM accept it is a problem?
>
> ------------------------------------------------------------------------
> Win John Lewis vouchers with BigSnapSearch.com Search now
> <http://clk.atdmt.com/UKM/go/117442309/direct/01/>
I may have not understood the situation you showed. I assumed you were talking
about something that could be used for a DoS attack.
The parameters allow you to control this. It's a example of an improvement. But
usually your database ports are inside your network. Possibly protected by
external firewalls. So, deciding if this is a "problem" or not is really above
me. I never had any issue with it... But we can find completely different
situations in different customers.
Regards.
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...