You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A proxy listener captures the acceptor process as its server, so accepted connections do not reach the Session. The old per-connection processes also lack socket ownership and complete lifecycle cleanup. HTTP requests can stall, and stopping the Session does not reliably close its active connections.
Change
Let the Session own accepted TCP sockets and Gun connections. Route acceptor messages to the Session, use finite WebSocket flow and TCP active-once reads, and close all connection resources on stop or owner exit. Retain certificate and hostname verification. Redact the client credential from inspection and crash status.
The public proxy_port, local_addr, and stop APIs stay the same.
Validation
All 83 SDK tests pass with warnings treated as errors, including nine new proxy regressions. Compile and format checks pass. The regressions cover HTTP relay, handshake failures and timeouts, flow control, explicit stop, owner exit, and credential-safe diagnostics. A live private Sprite test returned HTTP 200 with the expected inner bearer; the outer Sprites credential was absent from service headers. The listener closed after Session.stop.
Hi @guarilha! Thanks for the contribution. I found a couple of edge cases that we might want to sort out before merging this:
One slow client could block every connection. Line 191 performs a blocking TCP send inside the shared Session. When a client stops reading, all other tunnels and lifecycle messages stall until the send times out. I think we need to figure out how to isolate the I/O blocking per connection. You can reproduce this by blocking the session in :prim_inet.send/4.
Proxy requests discard the configured base URL path. Line 133 hardcodes /v1/.... A base URL ending in something like /gateway now requests /v1/sprites/test/proxy instead of /gateway/v1/sprites/test/proxy, breaking deployments behind a path prefix. We would want to preserve the base URL's path.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
A proxy listener captures the acceptor process as its server, so accepted connections do not reach the Session. The old per-connection processes also lack socket ownership and complete lifecycle cleanup. HTTP requests can stall, and stopping the Session does not reliably close its active connections.
Change
Let the Session own accepted TCP sockets and Gun connections. Route acceptor messages to the Session, use finite WebSocket flow and TCP active-once reads, and close all connection resources on stop or owner exit. Retain certificate and hostname verification. Redact the client credential from inspection and crash status.
The public proxy_port, local_addr, and stop APIs stay the same.
Validation
All 83 SDK tests pass with warnings treated as errors, including nine new proxy regressions. Compile and format checks pass. The regressions cover HTTP relay, handshake failures and timeouts, flow control, explicit stop, owner exit, and credential-safe diagnostics. A live private Sprite test returned HTTP 200 with the expected inner bearer; the outer Sprites credential was absent from service headers. The listener closed after Session.stop.