fix: preserve active tunnels and bound connection retirement - #17
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
All reviewed changes have approval readiness and no unresolved blocking issues.
Review effort: Lite
Findings: None
What changed in this PR
Fixes tunnel idle-timeout handling, H2 connection retirement, and UDP fallback health tracking.
Changes:
- Shares relay activity across directions while bounding stalled writes.
- Adds explicit H2 ownership and safe session retirement.
- Updates UDP health only after verified CONNECT-UDP responses.
| File | Description |
|---|---|
internal/tunnel/web_udp.go |
Reports verified UDP authentication events. |
internal/tunnel/web_stream.go |
Releases H2 stream ownership on close. |
internal/tunnel/web_h2_lifecycle_test.go |
Adds H2 lifecycle regression coverage. |
internal/tunnel/web_h2_client.go |
Tracks ownership and safely retires sessions. |
internal/tunnel/web_client.go |
Removes health updates from local UDP enqueue. |
internal/tunnel/web_client_udp_health_test.go |
Tests UDP health generations. |
internal/tunnel/web_client_test.go |
Updates health-state tests. |
internal/proxy/relay.go |
Shares activity deadlines and bounds writes. |
internal/proxy/relay_test.go |
Tests relay lifecycle and blocked writes. |
internal/proxy/http.go |
Bounds HTTP CONNECT prefix writes. |
internal/proxy/config.go |
Documents timeout semantics. |
integration/proxy_activity_test.go |
Adds real H2 activity coverage. |
docs/WEB_COVER.md |
Documents UDP recovery behavior. |
docs/DEPLOYMENT.md |
Documents tunnel timeout behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix three reproduced connection-lifecycle problems without changing authentication formats, transport defaults, or fingerprint profiles:
ClientConn.State()cleanup with explicit opening/active ownership. Detach retired sessions under the client mutex, then interrupt the raw wire and close H2 outside that mutex. Full Close/deadline releases ownership once; EOF/half-close preserves the opposite direction.Reproduction and validation
make check,make race,make stealth-tools-checkpassed. Final proxy/integration race rerun passed. Targeted H2 lifecycle race x10, UDP-health/generation race x20 and real H2 proxy integration race repetitions passed.Scope
No old remote test hosts were used; Linux/Docker/netem validation was supplied by GitHub CI for the exact head before merge. No formal PCAP corpus, comparative anti-identification result, version tag or release is included. These changes improve continuity and bounded cleanup; they do not prove traffic indistinguishability.
Exact-head checks
949761b8045714863fdacc6b747b58318f340abd: all jobs passed in CI 35727859407, CodeQL 35727859450, and Linux netem 35727859513. This includes Go 1.25/1.27 Linux tests, macOS tests, race, container integration/build, four-platform builds, and reachable vulnerability scan. No open review threads at the merge audit.Post-merge verification
Merged as
c85f70160cd1ad1d20e3789c40172a80ac3ca74b; its source tree exactly matches the validated PR head. All main-push workflows passed for that SHA: CI 35728213574, CodeQL 35728213651, and Linux netem 35728213729. Main CI confirms container integration, both Go versions, race, macOS tests, four-platform builds and vulnerability scan passed. Local main is synchronized and clean. No release/tag created.