Skip to content

relay: a socket refused at the upgrade cannot take the process with it - #388

Merged
mishan merged 1 commit into
masterfrom
upgrade-reset
Oct 6, 2026
Merged

mishan merged 1 commit into
masterfrom
upgrade-reset

Conversation

@mishan

@mishan mishan commented Oct 6, 2026

Copy link
Copy Markdown
Owner

Any client can crash the relay on master, ending every room on it.

The bug

  • Node's HTTP server stops listening for a socket's errors once the socket is handed to 'upgrade', and ws attaches its own listener only to the sockets it takes over.
  • A socket the relay refuses itself, such as a document socket with no ticket (403), therefore has no error listener.
  • If its client then resets the connection, the ECONNRESET is emitted unhandled and the process exits.

The fix
Every upgrading socket gets an error listener that destroys it.

Test
relaytest refuses a document upgrade, then resets it from the client, and checks the relay still answers. Without the fix, relaytest's in-process relay dies with ECONNRESET partway through the run. With it, all 126 checks pass.

The commit message also mentions a room socket's 429. That refusal comes with #377; on master the 403 is the path.

Node's server stops listening for a socket's errors once it is handed to
'upgrade', and ws listens again only for the sockets it takes. One the
relay refuses itself -- a document socket's 403, a room socket's 429 --
and its client then resets had its ECONNRESET emitted with no listener,
which ends the process: jamtest's page rejoining after a cut did it.
Every upgrading socket now has a listener that destroys it.
@mishan
mishan merged commit 70081eb into master Oct 6, 2026
8 checks passed
@mishan
mishan deleted the upgrade-reset branch October 6, 2026 23:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant