| 3 Jun 2025 |
Arian | So I feel like we might have a nix bug that makes some request use HTTP 1.1 for whatever reason or really a lot of people are behind weird corpo proxies | 19:48:11 |
hexa | also Lix from AS8881 is Versatel | 19:49:28 |
hexa | which is an eyeball network | 19:49:31 |
hexa | * also Lix from AS8881 (Versatel 1&1) | 19:49:41 |
Arian | oh the top result is actually no user agent | 19:50:54 |
hexa | so if anything something before nix 2.19 and nothing newer | 19:50:57 |
hexa | Redacted or Malformed Event | 19:51:37 |
hexa | pennaes first suspicion is that h1 would be used if the h2 connection setup failed | 19:52:21 |
hexa | there is no explicit fallback, so either users explicitly configuring it or a curl thing | 19:53:23 |
Arian | so the no-user-agent requests from Amazon are only requesting narinfo files it seems | 19:57:31 |
Arian | so I guess some scraper | 19:59:59 |
Arian | other theory: some Fastly PoPs fail to negotiate HTTP 2.0 for some reason | 20:07:23 |
hexa | uh, we only use the shield pop | 20:07:38 |
hexa | https://github.com/NixOS/infra/issues/212#issuecomment-1187503882 is a great post that explains the setup | 20:08:10 |
hexa | I don't think much has changed since it was potsed | 20:08:18 |
hexa | * I don't think much has changed since it was posted | 20:08:25 |
edef | note that S3 only speaks HTTP/1.1 | 20:14:13 |
edef | are you sure you are measuring client requests to the CDN and not origin requests? | 20:14:36 |
edef | because curling narinfos definitely gives me h2 | 20:15:18 |
edef | and like, we might just be logging this wrong, this data may not exist, i am not sure | 20:19:18 |
Arian | yeh im pretty sure these are client requests to the cdn | 20:19:38 |
edef | the logs are literally some json we sprintf together | 20:19:46 |
edef | * the logs are literally some "json" we sprintf together | 20:19:52 |
Arian | ah | 20:19:54 |
Arian | Okay but Fastly's | 20:21:20 |
Arian | * | 20:21:32 |
Arian | that’s why I started this. Our logs are consistent with that | 20:21:50 |
Arian | enough digging for today :D | 20:23:36 |
Jeremy Fleischman (jfly) | infinisil, i poked around a bit and figured out how to get our mailserver to both store and forward email. so we don't need to do a sudden switch for foundation@, you can keep the mailing list for a bit while you transition to freescout.
could you take a look at https://github.com/NixOS/infra/pull/715 and if it looks good, generate loginAccount for foundation@nixos.org? (nix run .#encrypt-email login -- --help should tell you what to do)
| 20:41:04 |
Jeremy Fleischman (jfly) | https://github.com/NixOS/infra/pull/705 builds upon that PR and adds freescout itself | 20:42:42 |