You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When running any container from https://github.com/jessfraz/dockerfiles (which uses X11 on the host system by sharing DISPLAY), vpnkit closes the connection after some idle timeout.
Example log message on macOS: com.docker.vpnkit[505]: TCP 192.168.65.3:39220 > 192.168.0.59:6000 closing flow due to idle port disconnection
However, this is not what is expected. In this specific example, the container sends TCP Keep Alive messages to the host (on port 6000 for X11 traffic). I would expect vpnkit to consider this a non-idle port and leave the connection intact.
Steps to reproduce (with Docker for Mac 18.06.1-ce-mac74 (26766)):
Add "vpnKitPortMaxIdleTime" : 5 to ~/Library/Group\ Containers/group.com.docker/settings.json. This isn't strictly necessary but makes it faster to test
Start XQuartz and enable "Allow connections from network clients" in its Preferences
Run a Docker container that uses X11: docker run -it -e DISPLAY=$YOUR_IP_HERE:0 jess/atom:latest
Run tcpdump, Wireshark or similar to observe TCP Keep Alives being sent to port 6000
Observe the X11 is closed after ~5s. Docker/vpnkit log will show this was caused due to an idle port
When running any container from https://github.com/jessfraz/dockerfiles (which uses X11 on the host system by sharing DISPLAY), vpnkit closes the connection after some idle timeout.
Example log message on macOS:
com.docker.vpnkit[505]: TCP 192.168.65.3:39220 > 192.168.0.59:6000 closing flow due to idle port disconnection
However, this is not what is expected. In this specific example, the container sends TCP Keep Alive messages to the host (on port 6000 for X11 traffic). I would expect vpnkit to consider this a non-idle port and leave the connection intact.
Steps to reproduce (with Docker for Mac 18.06.1-ce-mac74 (26766)):
"vpnKitPortMaxIdleTime" : 5
to~/Library/Group\ Containers/group.com.docker/settings.json
. This isn't strictly necessary but makes it faster to testdocker run -it -e DISPLAY=$YOUR_IP_HERE:0 jess/atom:latest
Possibly related: docker/for-mac#2406, mirage/mirage-tcpip#338 (reverted by #389)
The text was updated successfully, but these errors were encountered: