fix(proxy): skip bare TCP health probe for SOCKS5 data plane - #13571
diegosouzapw merged 2 commits into
Conversation
9e8c918 to
e940a73
Compare
e940a73 to
53a9180
Compare
|
Good root-cause explanation — the speculative bare-TCP probe against a SOCKS5 listener really |
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
|
Thanks @mdigitalbh81 — merging via the release merge-train. Validated in local merge-train (merge-train-20260918-120911-suite.log) on the devbox @ train tip 8c305709478b7052fb981a75852bbf88fe3a959d with the sibling PRs of this batch: typecheck:core, file-size, complexity, cognitive-complexity, changelog-integrity green; changed-area node:test 310/311 (the single red, hard-lease inventory, reproduces on the pure release tip) + vitest green (fast parity mode — full suite ran today on the tip via the base-red and 3b trains). Merged --admin per merge-gates §4/§7. |
f24c366
into
diegosouzapw:release/v3.8.51
…uzapw#13571) * fix(proxy): skip bare TCP health probe for SOCKS5 data plane * docs(changelog): add fragment for SOCKS5 bare TCP probe skip fix Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Summary
Skip the T14 speculative TCP reachability probe for ordinary SOCKS5 data-plane requests, while preserving the existing HTTP/HTTPS fast-fail behavior and the explicit control-plane direct-fallback probe.
Problem
runWithProxyContext()currently startsisProxyReachable()for ordinary proxied requests. That helper performs a rawnet.createConnection()and destroys the socket immediately after TCP connect.For a SOCKS5 listener this produces a separate connection with no SOCKS payload:
SYN -> SYN/ACK -> ACK -> FINIn production this shows up as
unexpected EOFon the SOCKS/GOST listener, while the real request opens a second connection and performs the actual SOCKS5 greeting + CONNECT flow.Fix
directFallbackOnUnreachablecontrol-plane behaviorsocks5hsupportValidation
npm run typecheck:core: passedgit diff --check: passedRegression coverage verifies that SOCKS5 data-plane traffic no longer invokes the bare TCP probe, HTTP retains the existing fast-fail behavior, real SOCKS failures remain owned by the real transport path, and explicit control-plane fallback still performs its blocking reachability check.