Skip to content

chronyc-sources

Captured 2026-08-03 from one CE of this deployment.

Terminal window
{"command":["chronyc-sources"]}
MS Name/IP address Stratum Poll Reach LastRx Last sample
===============================================================================
^+ 169.254.0.10 4 9 377 211 -758us[ -705us] +/- 47ms
^* 169.254.0.11 3 9 77 200 +324us[ +377us] +/- 27ms
^- time4.google.com 1 10 377 97 -4210us[-4210us] +/- 5284us

The MS column is two characters, not one. The first is the mode — ^ for a server — and the second is the state: * is the source currently selected, + an acceptable alternative, - one excluded by the selection algorithm, and ? one that is unreachable. So ^* is the selected server and ^? is an unreachable one; reading only the first character tells you nothing, because it is ^ on every line here.

Exactly one * is the healthy case, and that holds even when other sources show ?.

Reach is an octal register of the last eight polls, so 377 means all eight succeeded. Anything lower means at least one of the last eight did not — but that includes a source that has only recently started answering, whose register is still filling. A run taken while writing this showed 3 and 37 alongside a 377 on a node that had one source selected (^*) and whose login banner reported NTP: Synced. Read Reach together with LastRx, which shows how long ago the source last answered, rather than treating any value below 377 as a fault.

Worth checking early when authentication or TLS is failing for no visible reason: a node whose clock has drifted far enough will reject valid certificates and have its tokens rejected, and the resulting errors rarely mention time.