|
|
|
@ -290,10 +290,17 @@ const isTlsHandshake = (buffer: Buffer): boolean => {
|
|
|
|
|
return buffer.length > 0 && buffer[0] === 22; // ContentType.handshake
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
// Helper: Ensure timeout values don't exceed Node.js max safe integer
|
|
|
|
|
const ensureSafeTimeout = (timeout: number): number => {
|
|
|
|
|
const MAX_SAFE_TIMEOUT = 2147483647; // Maximum safe value (2^31 - 1)
|
|
|
|
|
return Math.min(Math.floor(timeout), MAX_SAFE_TIMEOUT);
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
// Helper: Generate a slightly randomized timeout to prevent thundering herd
|
|
|
|
|
const randomizeTimeout = (baseTimeout: number, variationPercent: number = 5): number => {
|
|
|
|
|
const variation = baseTimeout * (variationPercent / 100);
|
|
|
|
|
return baseTimeout + Math.floor(Math.random() * variation * 2) - variation;
|
|
|
|
|
const safeBaseTimeout = ensureSafeTimeout(baseTimeout);
|
|
|
|
|
const variation = safeBaseTimeout * (variationPercent / 100);
|
|
|
|
|
return ensureSafeTimeout(safeBaseTimeout + Math.floor(Math.random() * variation * 2) - variation);
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
export class PortProxy {
|
|
|
|
@ -325,12 +332,12 @@ export class PortProxy {
|
|
|
|
|
...settingsArg,
|
|
|
|
|
targetIP: settingsArg.targetIP || 'localhost',
|
|
|
|
|
|
|
|
|
|
// Timeout settings with safe limits for Node.js
|
|
|
|
|
// Timeout settings with safe maximum values
|
|
|
|
|
initialDataTimeout: settingsArg.initialDataTimeout || 60000, // 60 seconds for initial handshake
|
|
|
|
|
socketTimeout: settingsArg.socketTimeout || 2147483647, // Maximum safe value (~24.8 days)
|
|
|
|
|
socketTimeout: ensureSafeTimeout(settingsArg.socketTimeout || 2147483647), // Maximum safe value (~24.8 days)
|
|
|
|
|
inactivityCheckInterval: settingsArg.inactivityCheckInterval || 60000, // 60 seconds interval
|
|
|
|
|
maxConnectionLifetime: settingsArg.maxConnectionLifetime || 2147483647, // Maximum safe value (~24.8 days)
|
|
|
|
|
inactivityTimeout: settingsArg.inactivityTimeout || 14400000, // 4 hours inactivity timeout
|
|
|
|
|
maxConnectionLifetime: ensureSafeTimeout(settingsArg.maxConnectionLifetime || 2147483647), // Maximum safe value (~24.8 days)
|
|
|
|
|
inactivityTimeout: ensureSafeTimeout(settingsArg.inactivityTimeout || 14400000), // 4 hours inactivity timeout
|
|
|
|
|
|
|
|
|
|
gracefulShutdownTimeout: settingsArg.gracefulShutdownTimeout || 30000, // 30 seconds
|
|
|
|
|
|
|
|
|
@ -415,19 +422,19 @@ export class PortProxy {
|
|
|
|
|
* Get connection timeout based on domain config or default settings
|
|
|
|
|
*/
|
|
|
|
|
private getConnectionTimeout(record: IConnectionRecord): number {
|
|
|
|
|
// If the connection has a domain-specific timeout, use that
|
|
|
|
|
// If the connection has a domain-specific timeout, use that with safety check
|
|
|
|
|
if (record.domainConfig?.connectionTimeout) {
|
|
|
|
|
return record.domainConfig.connectionTimeout;
|
|
|
|
|
return ensureSafeTimeout(record.domainConfig.connectionTimeout);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Use default timeout, potentially randomized
|
|
|
|
|
// Use default timeout, potentially randomized with safety check
|
|
|
|
|
const baseTimeout = this.settings.maxConnectionLifetime!;
|
|
|
|
|
|
|
|
|
|
if (this.settings.enableRandomizedTimeouts) {
|
|
|
|
|
return randomizeTimeout(baseTimeout);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return baseTimeout;
|
|
|
|
|
return ensureSafeTimeout(baseTimeout);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
@ -1040,9 +1047,9 @@ export class PortProxy {
|
|
|
|
|
initiateCleanupOnce('timeout_outgoing');
|
|
|
|
|
});
|
|
|
|
|
|
|
|
|
|
// Set appropriate timeouts using the configured value
|
|
|
|
|
socket.setTimeout(this.settings.socketTimeout || 3600000);
|
|
|
|
|
targetSocket.setTimeout(this.settings.socketTimeout || 3600000);
|
|
|
|
|
// Set appropriate timeouts using the configured value with safety
|
|
|
|
|
socket.setTimeout(ensureSafeTimeout(this.settings.socketTimeout || 3600000));
|
|
|
|
|
targetSocket.setTimeout(ensureSafeTimeout(this.settings.socketTimeout || 3600000));
|
|
|
|
|
|
|
|
|
|
// Track outgoing data for bytes counting
|
|
|
|
|
targetSocket.on('data', (chunk: Buffer) => {
|
|
|
|
@ -1169,8 +1176,10 @@ export class PortProxy {
|
|
|
|
|
clearTimeout(connectionRecord.cleanupTimer);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Set timeout based on domain config or default
|
|
|
|
|
// Set timeout based on domain config or default with safety check
|
|
|
|
|
const connectionTimeout = this.getConnectionTimeout(connectionRecord);
|
|
|
|
|
const safeTimeout = ensureSafeTimeout(connectionTimeout); // Ensure timeout is safe
|
|
|
|
|
|
|
|
|
|
connectionRecord.cleanupTimer = setTimeout(() => {
|
|
|
|
|
console.log(
|
|
|
|
|
`[${connectionId}] Connection from ${remoteIP} exceeded max lifetime (${plugins.prettyMs(
|
|
|
|
@ -1178,7 +1187,7 @@ export class PortProxy {
|
|
|
|
|
)}), forcing cleanup.`
|
|
|
|
|
);
|
|
|
|
|
initiateCleanupOnce('connection_timeout');
|
|
|
|
|
}, connectionTimeout);
|
|
|
|
|
}, safeTimeout);
|
|
|
|
|
|
|
|
|
|
// Make sure timeout doesn't keep the process alive
|
|
|
|
|
if (connectionRecord.cleanupTimer.unref) {
|
|
|
|
@ -1574,4 +1583,4 @@ export class PortProxy {
|
|
|
|
|
|
|
|
|
|
console.log('PortProxy shutdown complete.');
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|