Skip to content

Fix proxy connection ownership and cleanup - #37

Open
guarilha wants to merge 1 commit into
superfly:mainfrom
awafinance:fix/proxy-lifecycle
Open

guarilha wants to merge 1 commit into
superfly:mainfrom
awafinance:fix/proxy-lifecycle

Conversation

@guarilha

@guarilha guarilha commented Sep 10, 2026 •

Copy link
Copy Markdown

Problem

A proxy listener captures the acceptor process as its server, so accepted connections do not reach the Session. The old per-connection processes also lack socket ownership and complete lifecycle cleanup. HTTP requests can stall, and stopping the Session does not reliably close its active connections.

Change

Let the Session own accepted TCP sockets and Gun connections. Route acceptor messages to the Session, use finite WebSocket flow and TCP active-once reads, and close all connection resources on stop or owner exit. Retain certificate and hostname verification. Redact the client credential from inspection and crash status.

The public proxy_port, local_addr, and stop APIs stay the same.

Validation

All 83 SDK tests pass with warnings treated as errors, including nine new proxy regressions. Compile and format checks pass. The regressions cover HTTP relay, handshake failures and timeouts, flow control, explicit stop, owner exit, and credential-safe diagnostics. A live private Sprite test returned HTTP 200 with the expected inner bearer; the outer Sprites credential was absent from service headers. The listener closed after Session.stop.

@aezell

aezell commented Sep 14, 2026

Copy link
Copy Markdown
Collaborator

Hi @guarilha! Thanks for the contribution. I found a couple of edge cases that we might want to sort out before merging this:

One slow client could block every connection. Line 191 performs a blocking TCP send inside the shared Session. When a client stops reading, all other tunnels and lifecycle messages stall until the send times out. I think we need to figure out how to isolate the I/O blocking per connection. You can reproduce this by blocking the session in :prim_inet.send/4.

Proxy requests discard the configured base URL path. Line 133 hardcodes /v1/.... A base URL ending in something like /gateway now requests /v1/sprites/test/proxy instead of /gateway/v1/sprites/test/proxy, breaking deployments behind a path prefix. We would want to preserve the base URL's path.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants