Skip to content

fix(proxy): improve DNS handling and CONNECT tunneling - #898

Merged
ithewei merged 2 commits into
masterfrom
async-client-dns-fix
Sep 30, 2026
Merged

ithewei merged 2 commits into
masterfrom
async-client-dns-fix

Conversation

@ithewei

@ithewei ithewei commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • resolve fixed TCP/UDP proxy example targets before starting their event loops
  • resolve HttpHandler hostname targets asynchronously through EventLoop::resolveDns, preserving the numeric-IP fast path and TLS SNI
  • retry dropped DNS queries and keep DNS plus TCP connection setup within one proxy_connect_timeout budget
  • add CONNECT tunneling support to tinyproxyd, including authority parsing and bounds checks
  • fix [bug] use-after-free: hloop_free() on a loop with an in-flight SOCKS5 server DNS query #891 by keeping the DNS resolver alive through IO close callbacks, with a teardown regression test

Scope

The fixed-upstream library functions hloop_create_tcp_proxy_server and hloop_create_udp_proxy_server are unchanged; the example programs resolve their fixed targets before starting the loop. tinyproxyd remains a demo and still uses its existing socket creation path for ordinary dynamic targets.

Verification

  • Debug CMake full build with unit tests, examples, Lua, MQTT, and KCP enabled
  • hdns_test with MallocScribble=1 and MallocErrorAbort=1
  • lua_io_test, lua_http_test, and lua_mqtt_test teardown coverage
  • DNS simulator dropping the first query: proxy succeeds on retry (200 in about 0.54s)
  • non-responsive DNS: proxy returns 504 in about 1.51s while /ping on the same worker remains responsive
  • fixed TCP proxy round trip with a localhost target
  • fixed UDP proxy echo with a localhost target
  • SOCKS5 hostname round trip
  • HttpHandler forward-proxy hostname round trip
  • tinyproxyd CONNECT tunnels with numeric-IP and hostname authorities
  • tinyproxyd ordinary HTTP proxy regression
  • git diff --check

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 04:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 07:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@ithewei ithewei changed the title fix(proxy): avoid blocking DNS in proxy paths fix(proxy): improve DNS handling and CONNECT tunneling Sep 30, 2026
@ithewei
ithewei merged commit ff686fc into master Sep 30, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] use-after-free: hloop_free() on a loop with an in-flight SOCKS5 server DNS query

2 participants