Compare commits
12 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 2cc0ff0030 | |||
| 72935e7ee0 | |||
| 61db285e04 | |||
| d165829022 | |||
| 5e6cf391ab | |||
| 2b1a21c599 | |||
| b8e1c9f3cf | |||
| c65369540c | |||
| 59e108edbd | |||
| 1e2ca68fc7 | |||
| 4c76a9f9f3 | |||
| 8e76c42cea |
37
changelog.md
37
changelog.md
@@ -1,5 +1,42 @@
|
|||||||
# Changelog
|
# Changelog
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.15 - fix(rustproxy-http)
|
||||||
|
implement vectored write support for backend streams
|
||||||
|
|
||||||
|
- Add poll_write_vectored forwarding for both plain and TLS backend stream variants
|
||||||
|
- Expose is_write_vectored so the proxy can correctly report vectored write capability
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.14 - fix(rustproxy-http)
|
||||||
|
forward vectored write support in ShutdownOnDrop AsyncWrite wrapper
|
||||||
|
|
||||||
|
- Implements poll_write_vectored by delegating to the wrapped writer
|
||||||
|
- Exposes is_write_vectored so the wrapper preserves underlying AsyncWrite capabilities
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.13 - fix(rustproxy-http)
|
||||||
|
remove hot-path debug logging from HTTP/1 connection pool hits
|
||||||
|
|
||||||
|
- Stops emitting debug logs when reusing HTTP/1 idle connections in the connection pool.
|
||||||
|
- Keeps pool hit behavior unchanged while reducing overhead on a frequently executed path.
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.12 - fix(rustproxy-http)
|
||||||
|
remove connection pool hit logging and keep logging limited to actual failures
|
||||||
|
|
||||||
|
- Removes debug and warning logs for HTTP/2 connection pool hits and age checks.
|
||||||
|
- Keeps pool behavior unchanged while reducing noisy per-request logging in the Rust HTTP proxy layer.
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.11 - fix(rustproxy-http)
|
||||||
|
improve HTTP/2 proxy error logging with warning-level connection failures and debug error details
|
||||||
|
|
||||||
|
- Adds debug-formatted error fields to HTTP/2 handshake, retry, fallback, and request failure logs
|
||||||
|
- Promotes upstream HTTP/2 connection error logs from debug to warn to improve operational visibility
|
||||||
|
|
||||||
|
## 2026-03-16 - 25.11.10 - fix(rustproxy-http)
|
||||||
|
validate pooled HTTP/2 connections asynchronously before reuse and evict stale senders
|
||||||
|
|
||||||
|
- Add an async ready() check with a 500ms timeout before reusing pooled HTTP/2 senders to catch GOAWAY/RST states before forwarding requests
|
||||||
|
- Return connection age from the HTTP/2 pool checkout path and log warnings for older pooled connections
|
||||||
|
- Evict pooled HTTP/2 senders when they are closed, exceed max age, fail readiness validation, or time out during readiness checks
|
||||||
|
|
||||||
## 2026-03-16 - 25.11.9 - fix(rustproxy-routing)
|
## 2026-03-16 - 25.11.9 - fix(rustproxy-routing)
|
||||||
reduce hot-path allocations in routing, metrics, and proxy protocol handling
|
reduce hot-path allocations in routing, metrics, and proxy protocol handling
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@push.rocks/smartproxy",
|
"name": "@push.rocks/smartproxy",
|
||||||
"version": "25.11.9",
|
"version": "25.11.15",
|
||||||
"private": false,
|
"private": false,
|
||||||
"description": "A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.",
|
"description": "A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.",
|
||||||
"main": "dist_ts/index.js",
|
"main": "dist_ts/index.js",
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ use bytes::Bytes;
|
|||||||
use dashmap::DashMap;
|
use dashmap::DashMap;
|
||||||
use http_body_util::combinators::BoxBody;
|
use http_body_util::combinators::BoxBody;
|
||||||
use hyper::client::conn::{http1, http2};
|
use hyper::client::conn::{http1, http2};
|
||||||
use tracing::debug;
|
// No per-request logging in the pool — only log on actual failures (in proxy_service.rs)
|
||||||
|
|
||||||
/// Maximum idle connections per backend key.
|
/// Maximum idle connections per backend key.
|
||||||
const MAX_IDLE_PER_KEY: usize = 16;
|
const MAX_IDLE_PER_KEY: usize = 16;
|
||||||
@@ -82,7 +82,7 @@ impl ConnectionPool {
|
|||||||
while let Some(idle) = idles.pop() {
|
while let Some(idle) = idles.pop() {
|
||||||
// Check if the connection is still alive and ready
|
// Check if the connection is still alive and ready
|
||||||
if idle.idle_since.elapsed() < IDLE_TIMEOUT && idle.sender.is_ready() && !idle.sender.is_closed() {
|
if idle.idle_since.elapsed() < IDLE_TIMEOUT && idle.sender.is_ready() && !idle.sender.is_closed() {
|
||||||
debug!("Pool hit (h1): {}:{}", key.host, key.port);
|
// H1 pool hit — no logging on hot path
|
||||||
return Some(idle.sender);
|
return Some(idle.sender);
|
||||||
}
|
}
|
||||||
// Stale or closed — drop it
|
// Stale or closed — drop it
|
||||||
@@ -115,20 +115,19 @@ impl ConnectionPool {
|
|||||||
|
|
||||||
/// Try to get a cloned HTTP/2 sender for the given key.
|
/// Try to get a cloned HTTP/2 sender for the given key.
|
||||||
/// HTTP/2 senders are Clone-able (multiplexed), so we clone rather than remove.
|
/// HTTP/2 senders are Clone-able (multiplexed), so we clone rather than remove.
|
||||||
pub fn checkout_h2(&self, key: &PoolKey) -> Option<http2::SendRequest<BoxBody<Bytes, hyper::Error>>> {
|
pub fn checkout_h2(&self, key: &PoolKey) -> Option<(http2::SendRequest<BoxBody<Bytes, hyper::Error>>, Duration)> {
|
||||||
let entry = self.h2_pool.get(key)?;
|
let entry = self.h2_pool.get(key)?;
|
||||||
let pooled = entry.value();
|
let pooled = entry.value();
|
||||||
|
let age = pooled.created_at.elapsed();
|
||||||
|
|
||||||
// Check if the h2 connection is still alive and not too old
|
if pooled.sender.is_closed() || age >= MAX_H2_AGE {
|
||||||
if pooled.sender.is_closed() || pooled.created_at.elapsed() >= MAX_H2_AGE {
|
|
||||||
drop(entry);
|
drop(entry);
|
||||||
self.h2_pool.remove(key);
|
self.h2_pool.remove(key);
|
||||||
return None;
|
return None;
|
||||||
}
|
}
|
||||||
|
|
||||||
if pooled.sender.is_ready() {
|
if pooled.sender.is_ready() {
|
||||||
debug!("Pool hit (h2): {}:{}", key.host, key.port);
|
return Some((pooled.sender.clone(), age));
|
||||||
return Some(pooled.sender.clone());
|
|
||||||
}
|
}
|
||||||
None
|
None
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -109,6 +109,24 @@ impl tokio::io::AsyncWrite for BackendStream {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn poll_write_vectored(
|
||||||
|
self: Pin<&mut Self>,
|
||||||
|
cx: &mut Context<'_>,
|
||||||
|
bufs: &[std::io::IoSlice<'_>],
|
||||||
|
) -> Poll<std::io::Result<usize>> {
|
||||||
|
match self.get_mut() {
|
||||||
|
BackendStream::Plain(s) => Pin::new(s).poll_write_vectored(cx, bufs),
|
||||||
|
BackendStream::Tls(s) => Pin::new(s).poll_write_vectored(cx, bufs),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn is_write_vectored(&self) -> bool {
|
||||||
|
match self {
|
||||||
|
BackendStream::Plain(s) => s.is_write_vectored(),
|
||||||
|
BackendStream::Tls(s) => s.is_write_vectored(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
fn poll_flush(self: Pin<&mut Self>, cx: &mut Context<'_>) -> Poll<std::io::Result<()>> {
|
fn poll_flush(self: Pin<&mut Self>, cx: &mut Context<'_>) -> Poll<std::io::Result<()>> {
|
||||||
match self.get_mut() {
|
match self.get_mut() {
|
||||||
BackendStream::Plain(s) => Pin::new(s).poll_flush(cx),
|
BackendStream::Plain(s) => Pin::new(s).poll_flush(cx),
|
||||||
@@ -659,17 +677,40 @@ impl HttpProxyService {
|
|||||||
h2: use_h2,
|
h2: use_h2,
|
||||||
};
|
};
|
||||||
|
|
||||||
// H2 pool checkout (H2 senders are Clone and multiplexed)
|
// H2 pool checkout with async readiness validation.
|
||||||
|
// checkout_h2 does synchronous is_closed()/is_ready() checks, but these
|
||||||
|
// reflect cached state — the H2 connection driver (a separate tokio task)
|
||||||
|
// may not have processed a pending GOAWAY/RST yet. The ready().await
|
||||||
|
// forces the runtime to yield, giving the driver a chance to detect failures.
|
||||||
if use_h2 {
|
if use_h2 {
|
||||||
if let Some(sender) = self.connection_pool.checkout_h2(&pool_key) {
|
if let Some((mut sender, age)) = self.connection_pool.checkout_h2(&pool_key) {
|
||||||
self.metrics.backend_pool_hit(&upstream_key);
|
match tokio::time::timeout(
|
||||||
self.metrics.set_backend_protocol(&upstream_key, "h2");
|
std::time::Duration::from_millis(500),
|
||||||
let result = self.forward_h2_pooled(
|
sender.ready(),
|
||||||
sender, parts, body, upstream_headers, &upstream_path,
|
).await {
|
||||||
route_match.route, route_id, &ip_str, &pool_key, domain_str, &conn_activity,
|
Ok(Ok(())) => {
|
||||||
).await;
|
self.metrics.backend_pool_hit(&upstream_key);
|
||||||
self.upstream_selector.connection_ended(&upstream_key);
|
self.metrics.set_backend_protocol(&upstream_key, "h2");
|
||||||
return result;
|
let result = self.forward_h2_pooled(
|
||||||
|
sender, parts, body, upstream_headers, &upstream_path,
|
||||||
|
route_match.route, route_id, &ip_str, &pool_key, domain_str, &conn_activity,
|
||||||
|
).await;
|
||||||
|
self.upstream_selector.connection_ended(&upstream_key);
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
Ok(Err(e)) => {
|
||||||
|
warn!(backend = %upstream_key, age_secs = age.as_secs(),
|
||||||
|
"Pooled H2 sender failed ready check (GOAWAY/RST): {}, evicting", e);
|
||||||
|
self.connection_pool.remove_h2(&pool_key);
|
||||||
|
// Fall through to fresh connection
|
||||||
|
}
|
||||||
|
Err(_) => {
|
||||||
|
warn!(backend = %upstream_key, age_secs = age.as_secs(),
|
||||||
|
"Pooled H2 sender ready check timed out (500ms), evicting");
|
||||||
|
self.connection_pool.remove_h2(&pool_key);
|
||||||
|
// Fall through to fresh connection
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -967,7 +1008,7 @@ impl HttpProxyService {
|
|||||||
) = match tokio::time::timeout(self.connect_timeout, h2_builder.handshake(io)).await {
|
) = match tokio::time::timeout(self.connect_timeout, h2_builder.handshake(io)).await {
|
||||||
Ok(Ok(h)) => h,
|
Ok(Ok(h)) => h,
|
||||||
Ok(Err(e)) => {
|
Ok(Err(e)) => {
|
||||||
error!(backend = %backend_key, domain = %domain, error = %e, "Backend H2 handshake failed");
|
error!(backend = %backend_key, domain = %domain, error = %e, error_debug = ?e, "Backend H2 handshake failed");
|
||||||
self.metrics.backend_handshake_error(&backend_key);
|
self.metrics.backend_handshake_error(&backend_key);
|
||||||
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 handshake failed"));
|
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 handshake failed"));
|
||||||
}
|
}
|
||||||
@@ -985,7 +1026,7 @@ impl HttpProxyService {
|
|||||||
let key = pool_key.clone();
|
let key = pool_key.clone();
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
if let Err(e) = conn.await {
|
if let Err(e) = conn.await {
|
||||||
debug!("HTTP/2 upstream connection error: {}", e);
|
warn!("HTTP/2 upstream connection error: {} ({:?})", e, e);
|
||||||
}
|
}
|
||||||
pool.remove_h2(&key);
|
pool.remove_h2(&key);
|
||||||
});
|
});
|
||||||
@@ -1117,7 +1158,7 @@ impl HttpProxyService {
|
|||||||
) = match tokio::time::timeout(self.connect_timeout, h2_builder.handshake(io)).await {
|
) = match tokio::time::timeout(self.connect_timeout, h2_builder.handshake(io)).await {
|
||||||
Ok(Ok(h)) => h,
|
Ok(Ok(h)) => h,
|
||||||
Ok(Err(e)) => {
|
Ok(Err(e)) => {
|
||||||
error!(backend = %backend_key, domain = %domain, error = %e, "H2 retry: handshake failed");
|
error!(backend = %backend_key, domain = %domain, error = %e, error_debug = ?e, "H2 retry: handshake failed");
|
||||||
self.metrics.backend_handshake_error(&backend_key);
|
self.metrics.backend_handshake_error(&backend_key);
|
||||||
self.metrics.backend_connection_closed(&backend_key);
|
self.metrics.backend_connection_closed(&backend_key);
|
||||||
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 retry handshake failed"));
|
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 retry handshake failed"));
|
||||||
@@ -1136,7 +1177,7 @@ impl HttpProxyService {
|
|||||||
let key = pool_key.clone();
|
let key = pool_key.clone();
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
if let Err(e) = conn.await {
|
if let Err(e) = conn.await {
|
||||||
debug!("H2 retry: upstream connection error: {}", e);
|
warn!("H2 retry: upstream connection error: {} ({:?})", e, e);
|
||||||
}
|
}
|
||||||
pool.remove_h2(&key);
|
pool.remove_h2(&key);
|
||||||
});
|
});
|
||||||
@@ -1265,7 +1306,7 @@ impl HttpProxyService {
|
|||||||
let key = pool_key.clone();
|
let key = pool_key.clone();
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
if let Err(e) = conn.await {
|
if let Err(e) = conn.await {
|
||||||
debug!("HTTP/2 upstream connection error: {}", e);
|
warn!("HTTP/2 upstream connection error: {} ({:?})", e, e);
|
||||||
}
|
}
|
||||||
pool.remove_h2(&key);
|
pool.remove_h2(&key);
|
||||||
});
|
});
|
||||||
@@ -1320,6 +1361,7 @@ impl HttpProxyService {
|
|||||||
backend = %bk,
|
backend = %bk,
|
||||||
domain = %domain,
|
domain = %domain,
|
||||||
error = %e,
|
error = %e,
|
||||||
|
error_debug = ?e,
|
||||||
"Auto-detect: H2 request failed, falling back to H1"
|
"Auto-detect: H2 request failed, falling back to H1"
|
||||||
);
|
);
|
||||||
self.metrics.backend_h2_failure(&bk);
|
self.metrics.backend_h2_failure(&bk);
|
||||||
@@ -1577,11 +1619,11 @@ impl HttpProxyService {
|
|||||||
// Evict the dead sender so subsequent requests get fresh connections
|
// Evict the dead sender so subsequent requests get fresh connections
|
||||||
if let Some(key) = pool_key {
|
if let Some(key) = pool_key {
|
||||||
let bk = format!("{}:{}", key.host, key.port);
|
let bk = format!("{}:{}", key.host, key.port);
|
||||||
error!(backend = %bk, domain = %domain, error = %e, "Backend H2 request failed");
|
error!(backend = %bk, domain = %domain, error = %e, error_debug = ?e, "Backend H2 request failed");
|
||||||
self.metrics.backend_request_error(&bk);
|
self.metrics.backend_request_error(&bk);
|
||||||
self.connection_pool.remove_h2(key);
|
self.connection_pool.remove_h2(key);
|
||||||
} else {
|
} else {
|
||||||
error!(domain = %domain, error = %e, "Backend H2 request failed");
|
error!(domain = %domain, error = %e, error_debug = ?e, "Backend H2 request failed");
|
||||||
}
|
}
|
||||||
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 request failed"));
|
return Ok(error_response(StatusCode::BAD_GATEWAY, "Backend H2 request failed"));
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -50,6 +50,18 @@ impl<S: AsyncRead + AsyncWrite + Unpin + Send + 'static> AsyncWrite for Shutdown
|
|||||||
Pin::new(self.get_mut().inner.as_mut().unwrap()).poll_write(cx, buf)
|
Pin::new(self.get_mut().inner.as_mut().unwrap()).poll_write(cx, buf)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn poll_write_vectored(
|
||||||
|
self: Pin<&mut Self>,
|
||||||
|
cx: &mut Context<'_>,
|
||||||
|
bufs: &[io::IoSlice<'_>],
|
||||||
|
) -> Poll<io::Result<usize>> {
|
||||||
|
Pin::new(self.get_mut().inner.as_mut().unwrap()).poll_write_vectored(cx, bufs)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn is_write_vectored(&self) -> bool {
|
||||||
|
self.inner.as_ref().unwrap().is_write_vectored()
|
||||||
|
}
|
||||||
|
|
||||||
fn poll_flush(
|
fn poll_flush(
|
||||||
self: Pin<&mut Self>,
|
self: Pin<&mut Self>,
|
||||||
cx: &mut Context<'_>,
|
cx: &mut Context<'_>,
|
||||||
|
|||||||
@@ -3,6 +3,6 @@
|
|||||||
*/
|
*/
|
||||||
export const commitinfo = {
|
export const commitinfo = {
|
||||||
name: '@push.rocks/smartproxy',
|
name: '@push.rocks/smartproxy',
|
||||||
version: '25.11.9',
|
version: '25.11.15',
|
||||||
description: 'A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.'
|
description: 'A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.'
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user