Re: Leak in BOPM
tabris <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sunday 22 August 2004 3:13 pm, Andy Smith wrote: > On Sun, Aug 22, 2004 at 12:02:28PM -0700, Erik Fears wrote: > > > -----BEGIN PGP SIGNED MESSAGE----- > > > Hash: SHA1 > > > > > > I'm running a central BOPM on a medium sized network (approx > > > 1000 users), and it is appear to be leaking memory (i've seen it > > > running at a couple hundred MB). My current workaround is to > > > /kill it every 60 minutes, but that's hardly a fix. > > > > > > I do run multiple DNSBLs (cbl.abuseat njabl, and opm.blitzed), > > > and there's just one BOPM for the entire network (unreal3.2.1 > > > with NICKIP, listening for far-connects). Any other information > > > required, I will provide as soon as I can procure it. > > > > Are you sure this is a leak and not the scan queue filling up. > > There is no max limit on the scan queue, so if your scanner can't > > keep up then it will quickly fill up your memory. Hmmm. is there an easy way to run 2 or 3 'central' BOPMs that each scan a set of servers? I can't put BOPMs on all the leaves, partly b/c I don't operate all of the leaves. > > Yes, tabris, please let us know these stats: Hmm. I'll get back to you with those in a couple hours. I had the bot set with umode d b/c of how noisy the stats channel is. (and i'll stop the periodic KILLs). Any chance we can change the trigger to something like !stat or !bopm stat ? (yes, i'm sure I could hack the code, but I am thinking I might not be the only one to care) > > 20:06:23 <@grifferz> MangoBOPM stat > 20:06:23 <+MangoBOPM> Uptime: 4 weeks, 4 days, 12:32:44 > 20:06:23 <+MangoBOPM> DNSBL: 149 successful lookups from > opm.blitzed.org 20:06:23 <+MangoBOPM> DNSBL: 71 reports sent > 20:06:23 <+MangoBOPM> Found 37 (HTTP) open. > 20:06:23 <+MangoBOPM> Found 27 (HTTPPOST) open. > 20:06:23 <+MangoBOPM> Found 10 (SOCKS4) open. > 20:06:23 <+MangoBOPM> Number of connects: 518654 (11.07/minute) > 20:10:13 <@grifferz> MangoBOPM fdstat > 20:10:13 <+MangoBOPM> Total open FD: 231/11095 > > Incidentally, using NJABL and CBL to protect an IRC network isn't > usually the best idea because they don't expire dynamic IPs very > often. Other people who have tried this have found the need to > whitelist dynamic IPs by using a dynamic IP DNSBL as a DNS whitelist > (with the bopm DNS whitelists patch). They are bit excessive, but also have 'no questions asked' removal policies. Better than say DSBL or SORBS (which I use in a notify only mode (change the KLINE to PRIVMSG #channel), due to the number of hoops to jump through for removal. The alternative is probably to add more ports to scan in the scanner. One idea from a friend is a combined nmap/bopm, that first scans for open ports, filters out a couple of the more obvious non-proxy ports (say 22, 25, 110, 135-139 etc), then scans all of them. I think it might take too long to scan, but it is an idea anyway. - -- tabris - - Why I Can't Go Out With You: I'd LOVE to, but... -- I have to answer all of my "occupant" letters. -- None of my socks match. -- I'm having all my plants neutered. -- I changed the lock on my door and now I can't get out. -- My yucca plant is feeling yucky. -- I'm touring China with a wok band. -- My chocolate-appreciation class meets that night. -- I'm running off to Yugoslavia with a foreign-exchange student named Basil Metabolism. -- There are important world issues that need worrying about. -- I'm going to count the bristles in my toothbrush. -- I prefer to remain an enigma. -- I think you want the OTHER Peggy/Cathy/Mike/whomever. -- I feel a song coming on. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBKPt71U5ZaPMbKQcRAq83AKCDYk6dc0LAcHhhsRgd2X8v8yP7CACeI9OX P1y+MpHTOBiUG1TPw4kdzRE= =PHw+ -----END PGP SIGNATURE-----