server: self-test — sysctl audit + egress-MTU self-proof ("server proven good")
A measurement server must prove its own host isn't distorting results:
- sysctl audit (/proc/sys): flags accept_ra on a static host, ICMP
redirects, ICMP rate-limiting of the server's own errors, and disabled
TCP options — each a measurement-fidelity hazard, with the "why".
- egress-MTU self-proof: DF PMTUD probe (IP_MTU_DISCOVER + getsockopt
IP_MTU, no root — Linux-only, stub elsewhere) to external anchors. If the
server's own uplink is below 1500, client MTU tests measure THIS server,
so we say so.
Exposed at GET /admin/selftest (full report) and as server_selftest
{mtu_ok, sysctl_ok} in the profile so clients can trust or skip MTU tests.
Recommended deploy/99-echolot-sysctl.conf + README section.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
c9e0d06ea2
commit
4ae744aae5
@@ -53,6 +53,26 @@ All configurable via `ECHOLOT_*_LISTEN`. Plus:
|
||||
Deliberately out of scope here: an echo listener on 443 (to detect port-based egress filtering)
|
||||
— that genuinely needs 443 and belongs on a dedicated IP, not on a host running a reverse proxy.
|
||||
|
||||
## Host tuning (measurement fidelity)
|
||||
|
||||
A measurement server must not let the kernel distort what clients observe. Apply the
|
||||
recommended sysctls and the daemon will confirm the host is clean:
|
||||
|
||||
```sh
|
||||
sudo cp deploy/99-echolot-sysctl.conf /etc/sysctl.d/ && sudo sysctl --system
|
||||
```
|
||||
|
||||
The daemon **self-tests at startup and via `GET /admin/selftest`** (localhost):
|
||||
- **sysctl audit** — flags settings that would distort results (RA acceptance on a static host,
|
||||
ICMP redirects, ICMP rate-limiting of the server's own errors, disabled TCP options).
|
||||
- **egress-MTU self-proof** — DF-probes external anchors (`ECHOLOT_MTU_PROBE_TARGETS`,
|
||||
default 1.1.1.1 + a v6 anchor) and reads the discovered path MTU. If the server's *own* uplink
|
||||
can't carry 1500, client MTU results would measure this server, not the client — so the profile
|
||||
exposes `server_selftest.mtu_ok` and the log warns loudly.
|
||||
|
||||
Both signals ride in `GET /v1/profile` as `server_selftest` so a client can trust — or skip —
|
||||
MTU testing accordingly.
|
||||
|
||||
## Run in Docker (config via env)
|
||||
|
||||
```sh
|
||||
|
||||
Reference in New Issue
Block a user