04 — Conflux · Troubleshooting

Read what conflux says, then do what it names

Conflux names the cause of almost every refusal, and the way out of most. This page is the reading guide: what conflux status reports, what each message means, and where to look when a machine is up and still reaches nothing.

On this page

Reading conflux status

Start here. sudo conflux status prints conflux's own state and anchorctl status beneath it. Conflux decides the mode, the taints it asked for, the IPv4, the subnets, the proxies, the exits, the medium, where the files live and when to renew. The anchor underneath decides everything else: every packet, every route, every credential check.

a machine whose renewals are failing
$ sudo conflux status
conflux 1.0.0-pre (f47de0fac83d24489664ca15fc6a317ac9c9f683) linux/amd64

  service      active (systemd: conflux.service, enabled at boot)
  mode         tun — interface anchor0
  taint        brhk-2mq9-tzva-6pjs-k4xe-nw7d-qf
  ipv4         10.128.0.1/24
  anchor       anchor6btpa3gn6w4stipba4hekzho7caw6srfyy5puvbz7mfanaiept5a
  credential   valid until 2026-10-06T06:35:43Z (8d 4h)
  renewal      failing since 2026-09-26T08:10:00Z: dial tcp: no route to host
  api          https://api.veilnet.com.au
  telemetry    none — nothing is exported until an endpoint is set
Lines that appear only when they matter
LineWhat it says
taintThe set in conflux.json, which mirrors what the credential grants, or none: the realm's default compartment for an issued credential granting none. A member's Taints order may have moved the running anchor since, and that does not show here: anchor reports no live set locally.
refusedThe machine is configured for taints its credential does not grant, which every start refuses for good. It names the set granted and the set configured, and the way out.
credentialvalid until …, EXPIRED …, or none — nothing enrolled yet on a machine that has never reached the API.
renewalfailing since … and the last error. While the credential is valid this is a warning, retried every minute.
clockHow far the clock was from the API's at the last call, when more than a second. Past ten minutes it says to fix the clock. See Clock skew.
forwardingThe networks this machine forwards for the realm. When a member's Subnets order replaced conflux.json's list, one line says whose order it was, with set by an order from anchor… at …, and that --subnet or --no-subnet sets it again.
exitPresent only when this machine is an exit one way or the other.
uplinkOn a machine on a link, the reopen tally. See Uplink.
binariesstale after an upgrade, until sudo conflux start restarts onto the new build.

The DATA column

sudo conflux peers lists each peer the anchor knows, and its DATA column says whether the two may exchange data. It is the first thing to check when two machines are up and cannot see each other, after giving them a minute: peers find each other by gossip, in fifteen to sixty seconds.

$ sudo conflux peers
ANCHOR      OVERLAY                                  IPV4        HARDWARE           STATE      CONN     DATA  REACH     RTT
i46dpakhug  fd80:c4b9:99ae:df9b:5261:d178:18f1:783c  10.128.0.2  ae:70:60:82:85:68  connected  out*,in  yes   nat-cone  990µs
s5g3oefl2s  fd80:c4b9:99ae:a015:58f1:5b6e:b140:5e8e  -           5a:f0:a9:da:4e:32  connected  out      no    unknown   1.2ms
  • DATA no on a peer that should be reachable is taint separation, working as designed. Two anchors exchange data only if one carries every taint the other does, so {office,laptop} and {office,desktop} cannot talk. Compare both machines' taint lines character for character. A credential's taints never change, so a machine enrolled in the wrong one needs a new identity: sudo conflux uninstall --yes, then sudo conflux up --taint with the right one. A member's Taints order may also have moved one of them, which status does not show.
  • DATA no on every peer can also mean this machine is blocked. A block leaves the anchor running, outside its realm, and every member treats it as an outsider. sudo conflux blocks on another member lists the blocks in force, and nothing on this machine needs doing once it is lifted.
  • A peer that is not listed at all has not been seen yet. If one machine has no peers, it has not reached the bootstrap node, which is a network problem rather than a conflux one.
  • A peer that is connected, shows DATA yes and an RTT, while every ping times out, is the host's routing table: nothing sends overlay addresses to the overlay interface. Check with ip route on Linux, netstat -rn on macOS or route print on Windows. anchor installs those routes itself, so one routed elsewhere is worth reporting to anchor with that output.

EXPIRED

credential EXPIRED means renewal has been failing for longer than the credential had left, and the renewal line beneath it names the last error. A running anchor stays up with every handshake refused. A restarted one does not start at all, since anchor will not build an anchor on an expired credential, so the supervisor keeps retrying with a backoff up to thirty seconds, renewing first each time.

It recovers on its own once a renewal gets through. The renewal route works after expiry, so a machine that was off for a month renews on its next start and keeps its AnchorID and its address. Conflux never re-enrols to work around a failed renewal, because that would draw a new identity and orphan every peer. The exception is a fixed-term credential, which names nowhere to renew: once it has expired it has to be replaced, and the unit shows as failed until it is.

Errors and what they mean

The messages below are quoted as conflux prints them, with … where it names the value at fault. Most go on to say what to type next.

Typing a command
MessageCauseWhat to do
nothing is running hereNo daemon on the socket.sudo conflux start if a configuration exists, otherwise conflux up or conflux proxy.
… needs rootEvery command that changes the machine needs it. On Windows it says … needs Administrator.Run the command it names, flags and all, with sudo or from an elevated PowerShell.
status exits 78The machine was never configured.conflux up or conflux proxy.
has not been given an IPv4 yet and there is no terminal to ask atup or proxy in a script, on a machine never asked.Pass --ipv4 ADDRESS or --no-ipv4.
no port specs given, and nothing else to serveconflux proxy with no spec, no --subnet and no --serve-exit.Give it something to offer: a spec such as 8080=127.0.0.1:3000, or a network or an exit to route.
"-add" is not one of conflux proxy's flagsanchorctl's proxy was meant.sudo conflux anchorctl proxy -add …
"-identity" is anchorctl's startanchorctl's flags given to conflux start, which takes none.sudo conflux anchorctl start …
the service started but no anchor came up within 90sThe supervisor is running and the anchor is not.The message names the log to read. Then see Service and logs.
Settings conflux refuses
MessageCauseWhat to do
is not a unicast address a host sends fromA loopback, link-local, multicast or broadcast IPv4.Any address a host could send from is accepted.
is inside 198.18.0.0/15anchor answers the IPv4 peers it translates for from that range, and will not send from it.Pick an address outside it.
a reverse proxy needs userspace modeA proxy spec in a configuration whose mode is tun.The modes are exclusive: run conflux proxy, or bind the service on the overlay address.
taint … contains a commaA comma-separated list passed to --taint.Use --taint once per label.
taint … has '@'Or '+'. Those bind a forwarded network to compartments, as SUBNET@a+b, so no taint may hold them. Nor may a space or a character that does not print.Pick a name without them.
this machine's credential grants …--taint or conflux.json names a set the credential does not grant.Keep the taints it grants, or draw a new identity as the message says: conflux uninstall --yes, then conflux up --taint.
subnet … is not a private networkA public prefix.anchor forwards private networks only; reaching the internet is what an exit is for.
subnet … has host bits set192.168.1.7/24, say.Write the network, 192.168.1.0/24, which the message suggests.
subnet … is bound to …, which this machine is not inA SPEC@taint binding names a taint this machine's credential does not grant.Bind only to the machine's own taints. A machine with none can bind nothing.
the control socket path is N bytesCONFLUX_DIR is too deep for a Unix socket.Use a shorter one; the kernel's limit is 104 to 108 bytes.
fd:3 adopts a descriptor …--uplink fd:N. conflux's supervisor starts anchord with no descriptor to adopt.Name the device, or drive anchor yourself with conflux anchorctl start -uplink fd:3.
anchor has no way to open a link on Windows--uplink on Windows.An uplink is Unix only.
Starting the anchor
MessageCauseWhat to do
the anchor binaries were extracted to … but will not run from thereThe filesystem is mounted noexec, SELinux refuses a binary labelled var_lib_t, or on Windows endpoint protection has quarantined it.The message says which. For noexec, set CONFLUX_DIR to a filesystem that allows execution; for SELinux, run the semanage and restorecon commands it prints. On macOS, killed: 9 instead means the signature was rejected.
… does not grant this anchor's taintsFrom anchord: the manifest names taints its chain does not commit to. The issuer's mistake, which no retry changes, so the supervisor gives up.Ask the issuer for a new credential.
this host will not give this process a TUN deviceFrom anchord: no capability or device, the interface name held by another, or a host booted without IPv6, which every overlay address needs.Grant the capability, pick another --interface, or run conflux proxy, which needs no interface and no IPv6 on the host.
this host could not be set up to forward for the realmFrom anchord, on Linux with an interface and --subnet or --serve-exit: no nft and no iptables with ipset, or a /proc/sys it cannot write.Install one of them, or start the container with forwarding already on. A userspace router needs neither.
this machine's clock is … away from the server'sThe clock is more than ten minutes from the API's.Fix NTP first; nothing connects until then. See Clock skew.
the credential expired …, and anchor will not start on an expired oneconflux enrol given a credential past its expiry.Get a fresh one from its issuer.
the manifest says renewalAuth … and carries no renewalUrlA document that says how to authenticate a renewal and not where to send one.The issuer has to set it.
Bootstrap failed: 5: Input/output errormacOS, on up or install after an uninstall. launchd reports most refusals as error 5, which names nothing.Conflux enables the label before every bootstrap, so the cause is one of the others the message lists: the plist is not root-owned or is group- or world-writable, the job is already loaded (sudo launchctl bootout system/org.veilnet.conflux), or the executable it names is gone or on a volume not mounted yet.

Windows

  • Every command that changes the machine needs an elevated PowerShell, and says … needs Administrator without one.
  • conflux up needs wintun.dll, which conflux fetches the first time a TUN machine needs it and again at any start that finds it missing, after an upgrade say. Offline, it says what to do by hand, and names the way round it.
conflux: a network interface on Windows needs wintun.dll, and it could not be fetched: …

  Download wintun-0.14.1.zip from https://www.wintun.net and put
  bin\amd64\wintun.dll at:
    C:\ProgramData\conflux\bin\998ece52739a7c74\wintun.dll

  Or run "conflux proxy PORT=BACKEND", which needs no interface at all
  • The archive is checked against a pinned SHA-256, and a mismatch aborts, printing both digests. Userspace mode needs no driver, so on a machine where Wintun cannot be installed, conflux proxy is a complete way to use the overlay.
  • When the extracted binaries will not run, conflux names endpoint protection as the likely cause. Compare the digests conflux version prints with the release notes, and if an exclusion is needed, the directory is %ProgramData%\conflux\bin.
  • Conflux gives %ProgramData%\conflux to SYSTEM and Administrators, and refuses a directory another account made there first, saying which. Remove it and run the command again as Administrator.
  • --uplink is refused: anchor has no way to open a link on Windows.
  • The service is conflux, displayed as VeilNet Conflux, and has no console, so it writes what it and anchord say to %ProgramData%\conflux\logs\conflux.log.

Service and logs

Where the logs are
PlatformRead the last fifty lines
Linuxjournalctl -u conflux -n 50
macOS, FreeBSDtail -n 50 /var/log/conflux.log
OpenBSDgrep conflux /var/log/daemon | tail -n 50
WindowsGet-Content -Tail 50 "C:\ProgramData\conflux\logs\conflux.log"

A start that times out names the right one for the machine. When the service starts and the anchor does not, stop the service and run the supervisor in the foreground. anchord's own lines are prefixed anchord:, so its reason for a refusal is printed in its own words.

$ sudo systemctl stop conflux
$ sudo conflux serve --foreground

How the supervisor restarts

  • A failed start is retried with a backoff up to thirty seconds, which is what lets a --subnet whose interface is not up yet come right at boot.
  • What no retry changes stops the supervisor after three attempts, with exit 70: a configuration or manifest conflux refuses, taints the credential does not grant among them, a credential expired with nowhere to renew it, one for a realm tree other than the one these binaries are pinned to, a TUN the host will not give, a host that will not be set up to forward, and an argument anchorctl refuses. Nothing to start at all is exit 78. systemd and Windows leave the service down on either, and launchd starts it again after its throttle interval.
  • Anything else it stops on, such as an extraction onto a full disk, exits 1, which a service manager restarts.
  • While it runs, it asks the daemon every thirty seconds whether it still holds an anchor, every ten through the link watcher on an uplink, and rebuilds it if not. A rebuild refused for good three times in a row, as after a conflux.json edited into one that will not build, makes the watcher give up and say so in the log. The service stays up holding no anchor until sudo conflux start or a reboot.
  • A blocked anchor is not rebuilt. A block leaves it running, outside its realm, and rebuilding it would change nothing.

Clock skew

Three separate things break on a bad clock, and only one of them says so.

  • A credential starts at the moment its issuer signs it, and anchor refuses one that starts more than ten minutes after its own clock says now. A machine ten minutes slow cannot start on a credential it has just been issued or renewed, and the refusal names the credential rather than the clock.
  • anchor's handshake tag rotates hourly and a peer accepts one epoch either side, so two machines two hours apart cannot connect at all. The symptom is a TLS alert that looks exactly like a wrong realm.
  • A clock weeks fast makes a current credential look expired, and one a year slow makes an expired one look fine.

So conflux compares the API's Date header with the local clock on every call, records the skew, and refuses to bring a machine up when it exceeds ten minutes, anchor's own allowance and the tightest of the three, naming NTP. The measurement is taken on the calls that reach the API, enrolling and renewing. A start whose credential is current makes none, unless the last measurement was over the limit, in which case it renews to measure again rather than trust a figure from before the clock was fixed. conflux status prints the last skew when it is more than a second.

$ sudo timedatectl set-ntp true
$ sudo conflux start