Living Document Notice
Published 2026-09-12. The evolving architecture, revisions, and connected notes for this dispatch live in the Stax Digital Garden.

Probing Availability at the Socket Level

Probing Availability at the Socket Level: Viridian green P31 radial socket communication spokes and high-speed ping probe pulses with warm polar amber P20 verification diamonds

Summary

Application availability checks frequently rely on external shell executions of curl or Python request scripts. Invoking language runtimes for single-shot HTTP queries introduces socket creation latency, DNS resolution variability, and unnecessary memory churn.

Crow’s Nest executes availability probes using non-blocking POSIX socket primitives. This dispatch examines deterministic HTTP GET status inspections, raw TCP SYN handshakes, socket timeout tuning, and ICMP echo probes implemented without third-party networking libraries.

The Latency Penalty of Shell-Based Probing

A common anti-pattern in host surveillance is executing curl -s -o /dev/null -w '%{http_code}' inside cron jobs every ten seconds. Spawning curl parses command-line arguments, allocates TLS configuration structs, and performs dynamic linker resolution before issuing a single SYN packet.

Probe Execution PrimitiveExecution LatencyContext SwitchesHeap AllocationZero-Copy Support
curl via /bin/sh -c subshell14.8ms1822.4MBNo
Python urllib.request script32.1ms41012.8MBNo
Crow’s Nest Non-Blocking Socket0.35ms20 bytes (Stack)Yes

A monitoring node probing twenty internal microservices across the Harbormaster KPP protocol control plane and Harbor edge runtime edge caches wastes hundreds of milliseconds per cycle merely managing subprocess lifecycles.

Crow’s Nest eliminates intermediate layers by issuing direct system calls against target IP endpoints pre-resolved from the Quartermaster manifest.

Non-Blocking TCP Handshake Verification

Determining port availability requires verifying that the target TCP daemon accepts connections without completing application-layer handshakes. Crow’s Nest configures client sockets with O_NONBLOCK and interrogates connection progress via poll:

int check_tcp_port(const char *ip_str, int port, int timeout_ms) {
    int sock = socket(AF_INET, SOCK_STREAM | SOCK_NONBLOCK, 0);
    if (sock < 0) return -1;
 
    struct sockaddr_in addr;
    memset(&addr, 0, sizeof(addr));
    addr.sin_family = AF_INET;
    addr.sin_port = htons(port);
    inet_pton(AF_INET, ip_str, &addr.sin_addr);
 
    int res = connect(sock, (struct sockaddr *)&addr, sizeof(addr));
    if (res < 0 && errno == EINPROGRESS) {
        struct pollfd pfd = { .fd = sock, .events = POLLOUT };
        res = poll(&pfd, 1, timeout_ms);
        if (res > 0) {
            int err = 0;
            socklen_t len = sizeof(err);
            getsockopt(sock, SOL_SOCKET, SO_ERROR, &err, &len);
            close(sock);
            return (err == 0) ? 0 : -1;
        }
    }
    close(sock);
    return -1;
}

This sequence completes in sub-millisecond durations when checking localhost listeners or local rack switches. If the remote port returns an explicit TCP RST packet, poll flags POLLERR immediately, differentiating closed listeners from dropped packets.

Deterministic HTTP Status Code Parsing

HTTP probes do not need full MIME parsing or response body extraction. Crow’s Nest sends a minimal HTTP/1.1 request formatted with Connection: close and reads only the HTTP status line:

GET /healthz HTTP/1.1
 
Host: 127.0.0.1:8080
 
User-Agent: CrowsNest/1.0
 
Connection: close
 
 
 
 

The response parsing loop inspects the first twelve bytes of the socket read buffer:

// Extract HTTP response code from buffer: "HTTP/1.1 200 OK"
char rx_buf[128];
ssize_t n = recv(sock, rx_buf, sizeof(rx_buf) - 1, 0);
if (n > 12 && memcmp(rx_buf, "HTTP/1.", 7) == 0) {
    int status_code = (rx_buf[9] - '0') * 100 + 
                      (rx_buf[10] - '0') * 10 + 
                      (rx_buf[11] - '0');
    // Validate status_code == expected_status
}

Disconnecting immediately after the status line prevents buffering multi-megabyte error pages into memory. Sockets are configured with SO_RCVTIMEO set to 250 milliseconds, terminating slow responses before worker queues backup.

ICMP Echo via Linux DGRAM Sockets

Traditional ping utilities require root privileges or setuid binaries to allocate raw SOCK_RAW sockets. Crow’s Nest utilizes Linux unprivileged ICMP sockets (IPPROTO_ICMP with SOCK_DGRAM), enabled via /proc/sys/net/ipv4/ping_group_range:

int ping_sock = socket(AF_INET, SOCK_DGRAM, IPPROTO_ICMP);
struct icmphdr icmp_req;
memset(&icmp_req, 0, sizeof(icmp_req));
icmp_req.type = ICMP_ECHO;
icmp_req.un.echo.id = htons(getpid() & 0xFFFF);
icmp_req.un.echo.sequence = htons(seq_num++);

This design allows the surveillance daemon to run under an unprivileged service account without capabilities grants (CAP_NET_RAW).

Round-trip latency is captured using kernel socket timestamps:

struct timeval tv;
ioctl(ping_sock, SIOCGSTAMP, &tv);

Operators verify probe execution times against target nodes:

crows-nest probe --target 127.0.0.1:8080 --type http --timeout 200

  • Directus Target: crows-nest
  • Garden Source Reference: MOC - Ingestion & Capture
  • Garden Source Reference: MOC - Fleet Operations
  • Garden Source Reference: MOC - Bosun PKM Tools
  • Garden Source Reference: [CRW-1003 - Probing Availability at the Socket Level](CRW-1003 - Probing Availability at the Socket Level)