Skip to content

fix(proxy): skip bare TCP health probe for SOCKS5 data plane - #13571

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.51from
mdigitalbh81:fix/socks5-remove-bare-tcp-probe
Sep 18, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.51from
mdigitalbh81:fix/socks5-remove-bare-tcp-probe

Conversation

@mdigitalbh81

Copy link
Copy Markdown
Contributor

Summary

Skip the T14 speculative TCP reachability probe for ordinary SOCKS5 data-plane requests, while preserving the existing HTTP/HTTPS fast-fail behavior and the explicit control-plane direct-fallback probe.

Problem

runWithProxyContext() currently starts isProxyReachable() for ordinary proxied requests. That helper performs a raw net.createConnection() and destroys the socket immediately after TCP connect.

For a SOCKS5 listener this produces a separate connection with no SOCKS payload:

SYN -> SYN/ACK -> ACK -> FIN

In production this shows up as unexpected EOF on the SOCKS/GOST listener, while the real request opens a second connection and performs the actual SOCKS5 greeting + CONNECT flow.

Fix

  • skip the speculative T14 probe only for ordinary SOCKS5 data-plane requests
  • keep the real SOCKS5 request as the availability signal
  • preserve HTTP/HTTPS T14 behavior
  • preserve directFallbackOnUnreachable control-plane behavior
  • leave background health, dispatcher, retry/fallback, family handling, and SOCKS connector behavior unchanged
  • do not introduce socks5h support

Validation

  • focused proxy tests: 25/25 passed
  • SOCKS/dispatcher tests: 30/30 passed
  • npm run typecheck:core: passed
  • ESLint: passed
  • git diff --check: passed
  • commit hooks: passed

Regression coverage verifies that SOCKS5 data-plane traffic no longer invokes the bare TCP probe, HTTP retains the existing fast-fail behavior, real SOCKS failures remain owned by the real transport path, and explicit control-plane fallback still performs its blocking reachability check.

@mdigitalbh81
mdigitalbh81 force-pushed the fix/socks5-remove-bare-tcp-probe branch from e940a73 to 53a9180 Compare September 14, 2026 00:29
@diegosouzapw

Copy link
Copy Markdown
Owner

Good root-cause explanation — the speculative bare-TCP probe against a SOCKS5 listener really
would produce exactly that incomplete-handshake EOF pattern. The fix is narrowly scoped and
your test file (9/9 pass here) explicitly covers the three behaviors you promise to preserve
(HTTP/HTTPS fast-fail, control-plane fallback, real-transport ownership of SOCKS5 failures).
One ask before merge: please add a changelog.d/fixes/ fragment.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @mdigitalbh81 — merging via the release merge-train. Validated in local merge-train (merge-train-20260918-120911-suite.log) on the devbox @ train tip 8c305709478b7052fb981a75852bbf88fe3a959d with the sibling PRs of this batch: typecheck:core, file-size, complexity, cognitive-complexity, changelog-integrity green; changed-area node:test 310/311 (the single red, hard-lease inventory, reproduces on the pure release tip) + vitest green (fast parity mode — full suite ran today on the tip via the base-red and 3b trains). Merged --admin per merge-gates §4/§7.

@diegosouzapw
diegosouzapw merged commit f24c366 into diegosouzapw:release/v3.8.51 Sep 18, 2026
11 of 16 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…uzapw#13571)

* fix(proxy): skip bare TCP health probe for SOCKS5 data plane

* docs(changelog): add fragment for SOCKS5 bare TCP probe skip fix

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants