Skip to content

Release 3.0.1: fix HTTPS in the macOS app - #29

Merged
DavidVoitenko merged 10 commits into
mainfrom
release/3.0.1
Sep 27, 2026
Merged

DavidVoitenko merged 10 commits into
mainfrom
release/3.0.1

Conversation

@DavidVoitenko

Copy link
Copy Markdown
Owner

Proxy Workbench 3.0.1

Fixes the macOS app of 3.0.0, which could not collect any proxies. The frozen build looked for trusted certificates in a folder of the build machine, so every HTTPS source failed with a connection error.

  • One shared TLS context (proxy_workbench/tls.py) for source downloads, HTTPS checks and the gateway's HTTPS upstreams: the system store plus the certifi bundle that ships inside the app. Verification is never turned off.
  • Regression test that simulates a build with no system certificates.
  • CI now makes the built macOS app and the built Windows CLI collect the quick source set from the internet, so a build that cannot verify HTTPS fails before release.

Verified locally on a rebuilt arm64 app: 8/8 quick sources downloaded (26,996 candidates), 12 working proxies found for example.com in 20 s, one used successfully with curl; the full GUI flow (Quick preset, stop after 5, Find and check, Results) finished with 5 rows.

Anonymous added 10 commits September 27, 2026 12:08
Frozen macOS builds pointed OpenSSL at a folder of the build machine, so
every HTTPS source failed with a connection error. One shared context now
loads the system store and the certifi bundle.
A check started from the desktop app failed with "data folder is already
used" whenever the background job runner or scheduler held the lock for
its one-second poll. A run now waits up to ten seconds for such a hold.

The interface server answered refused POST requests without reading their
body, which Windows turned into a reset connection.
The body memory budget was a fixed 64 MiB, which with the default 1 MiB
body cap held every scan at 64 checks in flight. It now grows with the
worker count up to 1 GiB. Candidates are read in address order, so the
thousands of ports some lists publish for one IP queued every worker
behind that host; the first port of each host now goes first and further
ports follow round by round. 663k collected addresses: 25 -> ~390 checks/s.
A connect attempt that has not answered within 2 s now has the next proxy
dialled alongside it and the first tunnel wins (4 attempts), instead of
waiting out each connect timeout in turn. When every matching proxy rests
after failures, the one due back first is used instead of answering 502
for the whole cooldown.
@DavidVoitenko
DavidVoitenko merged commit d29e6da into main Sep 27, 2026
22 checks passed
@DavidVoitenko
DavidVoitenko deleted the release/3.0.1 branch September 27, 2026 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant