UNPKG

@push.rocks/smartproxy

Version:

A powerful proxy package with unified route-based configuration for high traffic management. Features include SSL/TLS support, flexible routing patterns, WebSocket handling, advanced security options, and automatic ACME certificate management.

679 lines 57.9 kB
import * as plugins from '../../plugins.js'; import { logger } from '../../core/utils/logger.js'; import { connectionLogDeduplicator } from '../../core/utils/log-deduplicator.js'; import { LifecycleComponent } from '../../core/utils/lifecycle-component.js'; import { cleanupSocket } from '../../core/utils/socket-utils.js'; import { WrappedSocket } from '../../core/models/wrapped-socket.js'; import { ProtocolDetector } from '../../detection/index.js'; /** * Manages connection lifecycle, tracking, and cleanup with performance optimizations */ export class ConnectionManager extends LifecycleComponent { constructor(smartProxy) { super(); this.smartProxy = smartProxy; this.connectionRecords = new Map(); this.terminationStats = { incoming: {}, outgoing: {} }; // Performance optimization: Track connections needing inactivity check this.nextInactivityCheck = new Map(); this.cleanupBatchSize = 100; // Cleanup queue for batched processing this.cleanupQueue = new Set(); this.cleanupTimer = null; this.isProcessingCleanup = false; // Route-level connection tracking this.connectionsByRoute = new Map(); // Set reasonable defaults for connection limits this.maxConnections = smartProxy.settings.defaults?.security?.maxConnections || 10000; // Start inactivity check timer if not disabled if (!smartProxy.settings.disableInactivityCheck) { this.startInactivityCheckTimer(); } } /** * Generate a unique connection ID */ generateConnectionId() { return Math.random().toString(36).substring(2, 15) + Math.random().toString(36).substring(2, 15); } /** * Create and track a new connection * Accepts either a regular net.Socket or a WrappedSocket for transparent PROXY protocol support */ createConnection(socket) { // Enforce connection limit if (this.connectionRecords.size >= this.maxConnections) { // Use deduplicated logging for connection limit connectionLogDeduplicator.log('connection-rejected', 'warn', 'Global connection limit reached', { reason: 'global-limit', currentConnections: this.connectionRecords.size, maxConnections: this.maxConnections, component: 'connection-manager' }, 'global-limit'); socket.destroy(); return null; } const connectionId = this.generateConnectionId(); const remoteIP = socket.remoteAddress || ''; const remotePort = socket.remotePort || 0; const localPort = socket.localPort || 0; const now = Date.now(); const record = { id: connectionId, incoming: socket, outgoing: null, incomingStartTime: now, lastActivity: now, connectionClosed: false, pendingData: [], pendingDataSize: 0, bytesReceived: 0, bytesSent: 0, remoteIP, remotePort, localPort, isTLS: false, tlsHandshakeComplete: false, hasReceivedInitialData: false, hasKeepAlive: false, incomingTerminationReason: null, outgoingTerminationReason: null, usingNetworkProxy: false, isBrowserConnection: false, domainSwitches: 0 }; this.trackConnection(connectionId, record); return record; } /** * Track an existing connection */ trackConnection(connectionId, record) { this.connectionRecords.set(connectionId, record); this.smartProxy.securityManager.trackConnectionByIP(record.remoteIP, connectionId); // Schedule inactivity check if (!this.smartProxy.settings.disableInactivityCheck) { this.scheduleInactivityCheck(connectionId, record); } } /** * Schedule next inactivity check for a connection */ scheduleInactivityCheck(connectionId, record) { let timeout = this.smartProxy.settings.inactivityTimeout; if (record.hasKeepAlive) { if (this.smartProxy.settings.keepAliveTreatment === 'immortal') { // Don't schedule check for immortal connections return; } else if (this.smartProxy.settings.keepAliveTreatment === 'extended') { const multiplier = this.smartProxy.settings.keepAliveInactivityMultiplier || 6; timeout = timeout * multiplier; } } const checkTime = Date.now() + timeout; this.nextInactivityCheck.set(connectionId, checkTime); } /** * Start the inactivity check timer */ startInactivityCheckTimer() { // Check more frequently (every 10 seconds) to catch zombies and stuck connections faster this.setInterval(() => { this.performOptimizedInactivityCheck(); }, 10000); // Note: LifecycleComponent's setInterval already calls unref() } /** * Get a connection by ID */ getConnection(connectionId) { return this.connectionRecords.get(connectionId); } /** * Get all active connections */ getConnections() { return this.connectionRecords; } /** * Get count of active connections */ getConnectionCount() { return this.connectionRecords.size; } /** * Track connection by route */ trackConnectionByRoute(routeId, connectionId) { if (!this.connectionsByRoute.has(routeId)) { this.connectionsByRoute.set(routeId, new Set()); } this.connectionsByRoute.get(routeId).add(connectionId); } /** * Remove connection tracking for a route */ removeConnectionByRoute(routeId, connectionId) { if (this.connectionsByRoute.has(routeId)) { const connections = this.connectionsByRoute.get(routeId); connections.delete(connectionId); if (connections.size === 0) { this.connectionsByRoute.delete(routeId); } } } /** * Get connection count by route */ getConnectionCountByRoute(routeId) { return this.connectionsByRoute.get(routeId)?.size || 0; } /** * Initiates cleanup once for a connection */ initiateCleanupOnce(record, reason = 'normal') { // Use deduplicated logging for cleanup events connectionLogDeduplicator.log('connection-cleanup', 'info', `Connection cleanup: ${reason}`, { connectionId: record.id, remoteIP: record.remoteIP, reason, component: 'connection-manager' }, reason); if (record.incomingTerminationReason == null) { record.incomingTerminationReason = reason; this.incrementTerminationStat('incoming', reason); } // Add to cleanup queue for batched processing this.queueCleanup(record.id); } /** * Queue a connection for cleanup */ queueCleanup(connectionId) { // Check if connection is already being processed const record = this.connectionRecords.get(connectionId); if (!record || record.connectionClosed) { // Already cleaned up or doesn't exist, skip return; } this.cleanupQueue.add(connectionId); // Process immediately if queue is getting large and not already processing if (this.cleanupQueue.size >= this.cleanupBatchSize && !this.isProcessingCleanup) { this.processCleanupQueue(); } else if (!this.cleanupTimer && !this.isProcessingCleanup) { // Otherwise, schedule batch processing this.cleanupTimer = this.setTimeout(() => { this.processCleanupQueue(); }, 100); } } /** * Process the cleanup queue in batches */ processCleanupQueue() { // Prevent concurrent processing if (this.isProcessingCleanup) { return; } this.isProcessingCleanup = true; if (this.cleanupTimer) { this.clearTimeout(this.cleanupTimer); this.cleanupTimer = null; } try { // Take a snapshot of items to process const toCleanup = Array.from(this.cleanupQueue).slice(0, this.cleanupBatchSize); // Remove only the items we're processing from the queue for (const connectionId of toCleanup) { this.cleanupQueue.delete(connectionId); const record = this.connectionRecords.get(connectionId); if (record) { this.cleanupConnection(record, record.incomingTerminationReason || 'normal'); } } } finally { // Always reset the processing flag this.isProcessingCleanup = false; // Check if more items were added while we were processing if (this.cleanupQueue.size > 0) { this.cleanupTimer = this.setTimeout(() => { this.processCleanupQueue(); }, 10); } } } /** * Clean up a connection record */ cleanupConnection(record, reason = 'normal') { if (!record.connectionClosed) { record.connectionClosed = true; // Remove from inactivity check this.nextInactivityCheck.delete(record.id); // Track connection termination this.smartProxy.securityManager.removeConnectionByIP(record.remoteIP, record.id); // Remove from route tracking if (record.routeId) { this.removeConnectionByRoute(record.routeId, record.id); } // Remove from metrics tracking if (this.smartProxy.metricsCollector) { this.smartProxy.metricsCollector.removeConnection(record.id); } // Clean up protocol detection fragments const context = ProtocolDetector.createConnectionContext({ sourceIp: record.remoteIP, sourcePort: record.incoming?.remotePort || 0, destIp: record.incoming?.localAddress || '', destPort: record.localPort, socketId: record.id }); // Clean up any pending detection fragments for this connection ProtocolDetector.cleanupConnection(context); if (record.cleanupTimer) { clearTimeout(record.cleanupTimer); record.cleanupTimer = undefined; } // Calculate metrics once const duration = Date.now() - record.incomingStartTime; const logData = { connectionId: record.id, remoteIP: record.remoteIP, localPort: record.localPort, reason, duration: plugins.prettyMs(duration), bytes: { in: record.bytesReceived, out: record.bytesSent }, tls: record.isTLS, keepAlive: record.hasKeepAlive, usingNetworkProxy: record.usingNetworkProxy, domainSwitches: record.domainSwitches || 0, component: 'connection-manager' }; // Remove all data handlers to make sure we clean up properly if (record.incoming) { try { record.incoming.removeAllListeners('data'); record.renegotiationHandler = undefined; } catch (err) { logger.log('error', `Error removing data handlers: ${err}`, { connectionId: record.id, error: err, component: 'connection-manager' }); } } // Handle socket cleanup - check if sockets are still active const cleanupPromises = []; if (record.incoming) { // Extract underlying socket if it's a WrappedSocket const incomingSocket = record.incoming instanceof WrappedSocket ? record.incoming.socket : record.incoming; if (!record.incoming.writable || record.incoming.destroyed) { // Socket is not active, clean up immediately cleanupPromises.push(cleanupSocket(incomingSocket, `${record.id}-incoming`, { immediate: true })); } else { // Socket is still active, allow graceful cleanup cleanupPromises.push(cleanupSocket(incomingSocket, `${record.id}-incoming`, { allowDrain: true, gracePeriod: 5000 })); } } if (record.outgoing) { // Extract underlying socket if it's a WrappedSocket const outgoingSocket = record.outgoing instanceof WrappedSocket ? record.outgoing.socket : record.outgoing; if (!record.outgoing.writable || record.outgoing.destroyed) { // Socket is not active, clean up immediately cleanupPromises.push(cleanupSocket(outgoingSocket, `${record.id}-outgoing`, { immediate: true })); } else { // Socket is still active, allow graceful cleanup cleanupPromises.push(cleanupSocket(outgoingSocket, `${record.id}-outgoing`, { allowDrain: true, gracePeriod: 5000 })); } } // Wait for cleanup to complete Promise.all(cleanupPromises).catch(err => { logger.log('error', `Error during socket cleanup: ${err}`, { connectionId: record.id, error: err, component: 'connection-manager' }); }); // Clear pendingData to avoid memory leaks record.pendingData = []; record.pendingDataSize = 0; // Remove the record from the tracking map this.connectionRecords.delete(record.id); // Use deduplicated logging for connection termination if (this.smartProxy.settings.enableDetailedLogging) { // For detailed logging, include more info but still deduplicate by IP+reason connectionLogDeduplicator.log('connection-terminated', 'info', `Connection terminated: ${record.remoteIP}:${record.localPort}`, { ...logData, duration_ms: duration, bytesIn: record.bytesReceived, bytesOut: record.bytesSent }, `${record.remoteIP}-${reason}`); } else { // For normal logging, deduplicate by termination reason connectionLogDeduplicator.log('connection-terminated', 'info', `Connection terminated`, { remoteIP: record.remoteIP, reason, activeConnections: this.connectionRecords.size, component: 'connection-manager' }, reason // Group by termination reason ); } } } /** * Creates a generic error handler for incoming or outgoing sockets */ handleError(side, record) { return (err) => { const code = err.code; let reason = 'error'; const now = Date.now(); const connectionDuration = now - record.incomingStartTime; const lastActivityAge = now - record.lastActivity; // Update activity tracking if (side === 'incoming') { record.lastActivity = now; this.scheduleInactivityCheck(record.id, record); } const errorData = { connectionId: record.id, side, remoteIP: record.remoteIP, error: err.message, duration: plugins.prettyMs(connectionDuration), lastActivity: plugins.prettyMs(lastActivityAge), component: 'connection-manager' }; switch (code) { case 'ECONNRESET': reason = 'econnreset'; logger.log('warn', `ECONNRESET on ${side}: ${record.remoteIP}`, errorData); break; case 'ETIMEDOUT': reason = 'etimedout'; logger.log('warn', `ETIMEDOUT on ${side}: ${record.remoteIP}`, errorData); break; default: logger.log('error', `Error on ${side}: ${record.remoteIP} - ${err.message}`, errorData); } if (side === 'incoming' && record.incomingTerminationReason == null) { record.incomingTerminationReason = reason; this.incrementTerminationStat('incoming', reason); } else if (side === 'outgoing' && record.outgoingTerminationReason == null) { record.outgoingTerminationReason = reason; this.incrementTerminationStat('outgoing', reason); } this.initiateCleanupOnce(record, reason); }; } /** * Creates a generic close handler for incoming or outgoing sockets */ handleClose(side, record) { return () => { if (this.smartProxy.settings.enableDetailedLogging) { logger.log('info', `Connection closed on ${side} side`, { connectionId: record.id, side, remoteIP: record.remoteIP, component: 'connection-manager' }); } if (side === 'incoming' && record.incomingTerminationReason == null) { record.incomingTerminationReason = 'normal'; this.incrementTerminationStat('incoming', 'normal'); } else if (side === 'outgoing' && record.outgoingTerminationReason == null) { record.outgoingTerminationReason = 'normal'; this.incrementTerminationStat('outgoing', 'normal'); record.outgoingClosedTime = Date.now(); } this.initiateCleanupOnce(record, 'closed_' + side); }; } /** * Increment termination statistics */ incrementTerminationStat(side, reason) { this.terminationStats[side][reason] = (this.terminationStats[side][reason] || 0) + 1; } /** * Get termination statistics */ getTerminationStats() { return this.terminationStats; } /** * Optimized inactivity check - only checks connections that are due */ performOptimizedInactivityCheck() { const now = Date.now(); const connectionsToCheck = []; // Find connections that need checking for (const [connectionId, checkTime] of this.nextInactivityCheck) { if (checkTime <= now) { connectionsToCheck.push(connectionId); } } // Also check ALL connections for zombie state (destroyed sockets but not cleaned up) // This is critical for proxy chains where sockets can be destroyed without events for (const [connectionId, record] of this.connectionRecords) { if (!record.connectionClosed) { const incomingDestroyed = record.incoming?.destroyed || false; const outgoingDestroyed = record.outgoing?.destroyed || false; // Check for zombie connections: both sockets destroyed but connection not cleaned up if (incomingDestroyed && outgoingDestroyed) { logger.log('warn', `Zombie connection detected: ${connectionId} - both sockets destroyed but not cleaned up`, { connectionId, remoteIP: record.remoteIP, age: plugins.prettyMs(now - record.incomingStartTime), component: 'connection-manager' }); // Clean up immediately this.cleanupConnection(record, 'zombie_cleanup'); continue; } // Check for half-zombie: one socket destroyed if (incomingDestroyed || outgoingDestroyed) { const age = now - record.incomingStartTime; // Use longer grace period for encrypted connections (5 minutes vs 30 seconds) const gracePeriod = record.isTLS ? 300000 : 30000; // Also ensure connection is old enough to avoid premature cleanup if (age > gracePeriod && age > 10000) { logger.log('warn', `Half-zombie connection detected: ${connectionId} - ${incomingDestroyed ? 'incoming' : 'outgoing'} destroyed`, { connectionId, remoteIP: record.remoteIP, age: plugins.prettyMs(age), incomingDestroyed, outgoingDestroyed, isTLS: record.isTLS, gracePeriod: plugins.prettyMs(gracePeriod), component: 'connection-manager' }); // Clean up this.cleanupConnection(record, 'half_zombie_cleanup'); } } // Check for stuck connections: no data sent back to client if (!record.connectionClosed && record.outgoing && record.bytesReceived > 0 && record.bytesSent === 0) { const age = now - record.incomingStartTime; // Use longer grace period for encrypted connections (5 minutes vs 60 seconds) const stuckThreshold = record.isTLS ? 300000 : 60000; // If connection is older than threshold and no data sent back, likely stuck if (age > stuckThreshold) { logger.log('warn', `Stuck connection detected: ${connectionId} - received ${record.bytesReceived} bytes but sent 0 bytes`, { connectionId, remoteIP: record.remoteIP, age: plugins.prettyMs(age), bytesReceived: record.bytesReceived, targetHost: record.targetHost, targetPort: record.targetPort, isTLS: record.isTLS, threshold: plugins.prettyMs(stuckThreshold), component: 'connection-manager' }); // Set termination reason and increment stats if (record.incomingTerminationReason == null) { record.incomingTerminationReason = 'stuck_no_response'; this.incrementTerminationStat('incoming', 'stuck_no_response'); } // Clean up this.cleanupConnection(record, 'stuck_no_response'); } } } } // Process only connections that need checking for (const connectionId of connectionsToCheck) { const record = this.connectionRecords.get(connectionId); if (!record || record.connectionClosed) { this.nextInactivityCheck.delete(connectionId); continue; } const inactivityTime = now - record.lastActivity; // Use extended timeout for extended-treatment keep-alive connections let effectiveTimeout = this.smartProxy.settings.inactivityTimeout; if (record.hasKeepAlive && this.smartProxy.settings.keepAliveTreatment === 'extended') { const multiplier = this.smartProxy.settings.keepAliveInactivityMultiplier || 6; effectiveTimeout = effectiveTimeout * multiplier; } if (inactivityTime > effectiveTimeout) { // For keep-alive connections, issue a warning first if (record.hasKeepAlive && !record.inactivityWarningIssued) { logger.log('warn', `Keep-alive connection inactive: ${record.remoteIP}`, { connectionId, remoteIP: record.remoteIP, inactiveFor: plugins.prettyMs(inactivityTime), component: 'connection-manager' }); record.inactivityWarningIssued = true; // Reschedule check for 10 minutes later this.nextInactivityCheck.set(connectionId, now + 600000); // Try to stimulate activity with a probe packet if (record.outgoing && !record.outgoing.destroyed) { try { record.outgoing.write(Buffer.alloc(0)); } catch (err) { logger.log('error', `Error sending probe packet: ${err}`, { connectionId, error: err, component: 'connection-manager' }); } } } else { // Close the connection logger.log('warn', `Closing inactive connection: ${record.remoteIP}`, { connectionId, remoteIP: record.remoteIP, inactiveFor: plugins.prettyMs(inactivityTime), hasKeepAlive: record.hasKeepAlive, component: 'connection-manager' }); this.cleanupConnection(record, 'inactivity'); } } else { // Reschedule next check this.scheduleInactivityCheck(connectionId, record); } // Parity check: if outgoing socket closed and incoming remains active // Increased from 2 minutes to 30 minutes for long-lived connections if (record.outgoingClosedTime && !record.incoming.destroyed && !record.connectionClosed && now - record.outgoingClosedTime > 1800000 // 30 minutes ) { // Only close if no data activity for 10 minutes if (now - record.lastActivity > 600000) { logger.log('warn', `Parity check failed after extended timeout: ${record.remoteIP}`, { connectionId, remoteIP: record.remoteIP, timeElapsed: plugins.prettyMs(now - record.outgoingClosedTime), inactiveFor: plugins.prettyMs(now - record.lastActivity), component: 'connection-manager' }); this.cleanupConnection(record, 'parity_check'); } } } } /** * Legacy method for backward compatibility */ performInactivityCheck() { this.performOptimizedInactivityCheck(); } /** * Clear all connections (for shutdown) */ async clearConnections() { // Delegate to LifecycleComponent's cleanup await this.cleanup(); } /** * Override LifecycleComponent's onCleanup method */ async onCleanup() { // Process connections in batches to avoid blocking const connections = Array.from(this.connectionRecords.values()); const batchSize = 100; let index = 0; const processBatch = () => { const batch = connections.slice(index, index + batchSize); for (const record of batch) { try { if (record.cleanupTimer) { clearTimeout(record.cleanupTimer); record.cleanupTimer = undefined; } // Immediate destruction using socket-utils const shutdownPromises = []; if (record.incoming) { const incomingSocket = record.incoming instanceof WrappedSocket ? record.incoming.socket : record.incoming; shutdownPromises.push(cleanupSocket(incomingSocket, `${record.id}-incoming-shutdown`, { immediate: true })); } if (record.outgoing) { const outgoingSocket = record.outgoing instanceof WrappedSocket ? record.outgoing.socket : record.outgoing; shutdownPromises.push(cleanupSocket(outgoingSocket, `${record.id}-outgoing-shutdown`, { immediate: true })); } // Don't wait for shutdown cleanup in this batch processing Promise.all(shutdownPromises).catch(() => { }); } catch (err) { logger.log('error', `Error during connection cleanup: ${err}`, { connectionId: record.id, error: err, component: 'connection-manager' }); } } index += batchSize; // Continue with next batch if needed if (index < connections.length) { setImmediate(processBatch); } else { // Clear all maps this.connectionRecords.clear(); this.nextInactivityCheck.clear(); this.cleanupQueue.clear(); this.terminationStats = { incoming: {}, outgoing: {} }; } }; // Start batch processing setImmediate(processBatch); } } //# sourceMappingURL=data:application/json;base64,