Prior to placing the issue, please check following: (fill out each checkbox with an X once done)
Description of the bug:
I have just installed the changes from today (11.07.2020) on three systems, now on all three systems the CPU is 100%.
I installed the last changes yesterday on the systems, so it must have something to do with today's changes.
Responsible is the python3 process in netfilter-mailcow.
top - 23:08:08 up 12:21, 1 user, load average: 5.99, 4.54, 3.65
Tasks: 433 total, 2 running, 431 sleeping, 0 stopped, 0 zombie
%Cpu(s): 72.6 us, 18.5 sy, 0.0 ni, 7.8 id, 0.0 wa, 0.0 hi, 0.8 si, 0.3 st
MiB Mem : 7962.1 total, 250.8 free, 3678.9 used, 4032.4 buff/cache
MiB Swap: 10240.0 total, 10195.0 free, 45.0 used. 4071.1 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
692458 root 20 0 18668 15588 5728 R 96.7 0.2 31:43.34 python3
# docker top mailcowdockerized_netfilter-mailcow_1
UID PID PPID C STIME TTY TIME CMD
root 692458 692380 96 22:35 ? 00:32:01 python3 -u /server.py
md5-c3f6e836c2fe144420ff13490c5daddc
# docker images
REPOSITORY TAG IMAGE ID CREATED SIZE
mailcow/netfilter 1.36 ce8f47161dbe 10 hours ago 79.3MB
md5-2f2a1fbbc575401ce9bb7c48c7c7217b
dc logs netfilter-mailcow
Attaching to mailcowdockerized_netfilter-mailcow_1
netfilter-mailcow_1 | Clearing all bans
Reproduction of said bug:
Install updates from today
System information:
| Question | Answer |
| --- | --- |
| My operating system | Ubuntu 20.04 LTS, Linux lan0 5.4.0-40-generic #44-Ubuntu SMP Tue Jun 23 00:01:04 UTC 2020 x86_64 x86_64 x86_64 GNU/Linux |
| Is Apparmor, SELinux or similar active? | no|
| Virtualization technlogy (KVM, VMware, Xen, etc - LXC and OpenVZ are not supported | KVM/VMWARE |
| Server/VM specifications (Memory, CPU Cores) | Different on all three systems |
| Docker Version (docker version) | 19.03.12 |
| Docker-Compose Version (docker-compose version) | 1.26.2, build eefe0d31 |
| Reverse proxy (custom solution) | yes |
git diff origin/master, any other changes to the code? If so, please post them.iptables -L -vn, ip6tables -L -vn, iptables -L -vn -t nat and ip6tables -L -vn -t nat.docker exec -it $(docker ps -qf name=acme-mailcow) dig +short stackoverflow.com @172.22.1.254 (set the IP accordingly, if you changed the internal mailcow network) and post the output.Thanks, fixed it. Can you test?
https://github.com/mailcow/mailcow-dockerized/commit/816c779ac2511b1c36084b81b39167e1b89befb0 resolves the issue :-)
How did you find out so quickly that iptables version 1.6.2-r1 caused the problem?
It was a hacky workaround at that time.
I did not remove it anymore. :/ That's what I got.