From c854b2cc6d347aa9e883f51ed1b0e657e1c87fba Mon Sep 17 00:00:00 2001 From: oqyude Date: Sun, 4 Oct 2026 21:37:14 +0300 Subject: [PATCH] 3x-ui: drop dead -p 127.0.0.1:15380:443/tcp (double-bind blocks start) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The systemd unit on the otreca VDS carried two -p flags that bind the same host port 127.0.0.1:15380: -p 127.0.0.1:15380:8443/tcp # from basePorts -p 127.0.0.1:15380:443/tcp # from realityPorts (when reality443Forwarding=true) podman 5.x tries to bind 127.05 in each -p flag and the second fails with EADDRINUSE, even though no process is visible in ss — the bind happens at the proxy level before the container starts: Error: cannot listen on the TCP port: listen tcp4 127.0.0.1:15380: bind: address already in use Symptom on otreca: podman-3xui_app.service hits start-limit-hit after 5 rapid retries. The 15380:443 mapping is dead code: the container's only Reality inbound listens on 8443, and nginx stream already routes host:443 to 127.0.0.1:15380 via SNI (modules/server/nginx.nix streamConfig). reality443Forwarding remains a host option for configurations to declare intent; the broken port-mapping generation is replaced with an empty list. --- modules/containers/3x-ui.nix | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/modules/containers/3x-ui.nix b/modules/containers/3x-ui.nix index 2324836..18e3388 100644 --- a/modules/containers/3x-ui.nix +++ b/modules/containers/3x-ui.nix @@ -34,9 +34,20 @@ let # port-forward mangles it and clients see the fallback cert. "127.0.0.1:15380:8443/tcp" ]; - # VDS-only: nginx stream forwards host:443 → 127.0.0.1:15380 → - # container:443, so Xray sees its REALITY inbound on port 443. - realityPorts = lib.optional config.host."3x-ui".reality443Forwarding "127.0.0.1:15380:443/tcp"; + # VDS-only: nginx stream forwards host:443 → 127.0.0.1:15380 via SNI + # (see modules/server/nginx.nix). The container's only Reality inbound + # listens on 8443, so nginx's SNI-routed connection to host:15380 + # lands on the correct inbound. A `-p ...:15380:443/tcp` mapping is + # therefore unnecessary and was removed: podman 5.x refuses two + # `-p` flags that bind the same host port (the second `-p + # 127.0.0.1:15380:443/tcp` produced + # `Error: cannot listen on the TCP port: listen tcp4 127.0.0.1:15380: + # bind: address already in use` and a start-limit-hit loop). + # + # Removed 2026-10-04. The reality443Forwarding host option is kept + # so configurations can continue to declare the intent; only the + # broken port-mapping generation is gone. + realityPorts = [ ]; # Workaround for a 3x-ui panel bug (both 3.8.5 and 3.9.0 reproduce it): when # generating bin/config.json from the inbounds DB rows, the panel drops the # inner `realitySettings.settings.{publicKey,fingerprint,serverName,spiderX,