Conversation
…probe fails omarchy-network-status measures the internet hop with a single ICMP echo to one hardcoded host. Anything that filters either the host or the protocol -- an ISP that blackholes 1.1.1.1, a university or corporate WLAN with a default-deny egress ACL, a captive-portal appliance, CGNAT -- makes every sample come back empty, so the panel reads Timeout and climbs to 100% packet loss on a link that is working fine. Probe 1.1.1.1 and 8.8.8.8 together and take the first reply in list order, so a blocked host costs no time and nothing changes for a network where 1.1.1.1 answers. Only when no echo returns from either, time a TCP handshake to each in turn and report it as internet_tcp_ms. It crosses the network the same single round trip, so the number is comparable, and the panel labels the row Ping (TCP) rather than passing a handshake off as an echo reply. internet_ping_ms keeps meaning "an echo returned in this long", because that is what the packet loss row counts: a sample the handshake rescued is still a lost echo, and folding the two together would report a link shedding half its packets as healthy. Where no echo returns all window but the handshake keeps landing, loss is not measurable from here, so the row holds at -- instead of claiming 0%. Uses bash's /dev/tcp under a timeout rather than curl, which no script in bin/ currently needs. Fixes omacom#9068 Fixes omacom#9261 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AFuwaBrZB6VbYVHy7oUU64
AronBakes
force-pushed
the
network-icmp-tcp-fallback
branch
from
August 31, 2026 09:05
467179b to
42537de
Compare
Member
|
Automated duplication check: this pull request looks similar to #7932, which covers the same network status second probe. I keep that one open and close this one to consolidate review. If you feel this is the wrong decision, please open the PR again with a note on the difference. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #9068. Fixes #9261.
omarchy-network-statusmeasures the internet hop with a single ICMP echo toone hardcoded host. Anything that filters either the host (an ISP or router
that blackholes 1.1.1.1 — #9261) or the protocol (a university or corporate
WLAN with a default-deny egress ACL, a captive-portal appliance, CGNAT — #9068)
makes every sample come back empty, so the panel reads
Timeoutand climbs to100% packet losson a link that is working fine.Two layers, each only reached when the one before it gets nothing:
in list order wins. Pinging in parallel rather than in sequence means a blocked
host costs no time, and nothing changes on a network where 1.1.1.1 answers.
each host's port 443 is timed and reported as a separate field.
Why the handshake time is comparable
"You substituted a different measurement into the same row" is the fair
objection, so, measured on one machine:
/dev/tcphandshakecurltime_connectpingavg)Both cross the network exactly once — SYN/SYN-ACK is a round trip like
echo/reply — which is why they agree. The row is still labelled
Ping (TCP)rather than passing one off as the other, because a handshake can additionally
carry server-side accept latency.
Why it is a separate field
internet_ping_mskeeps meaning "an echo returned in this long", because thatis what the packet loss row counts. Folding the handshake into it would report a
link shedding half its packets as perfectly healthy — the fallback would quietly
fill the gap left by every lost echo. A sample the handshake rescued is still a
lost echo.
Where no echo returns all window but the handshake keeps landing, loss is not
measurable from here at all, so the row holds at
--rather than claiming aclean link nobody measured.
20 ms0%20 ms0%20 ms50%10 ms(Ping (TCP))--Timeout100%20 msEach is a test in
test/shell.d/network-test.sh. The script-side cases runprint_ping_samplesfor real against a stubbedping, rather than grepping thesource, and were checked to fail when the second host or the per-host handshake
is removed.
Notes
/dev/tcpunder atimeoutrather thancurl, which no script inbin/currently needs. Verified bounded on all four outcomes: reachable,refused, blackholed (returns at 2.001s), unresolvable.
answers echo even where the border filters it, and need not have the port open.
is emitted and no socket opened. The one added cost everywhere is a second ICMP
packet per poll, in parallel with the first.
NetworkManager's existing connectivity state, or simply rendering
--whenevery sample is empty while
rx_bytesis still climbing, would both be smallerthan this. Happy to redo it either way.
🤖 Generated with Claude Code