Compare commits

...

6 Commits

Author SHA1 Message Date
Vladimir Dubrovin
c31fe8367f Minor FilePlugin cleanup
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled
2026-08-08 23:06:36 +03:00
Vladimir Dubrovin
f480c9dfe8 Do not try non-SOCKSv5 proxies for UDPASSOC 2026-08-08 22:58:41 +03:00
Vladimir Dubrovin
8de2be3b3b fix socket leak on failed UDPASSOC parent 2026-08-08 22:11:25 +03:00
Vladimir Dubrovin
aea9ff8c94 Fix warnings 2026-08-08 21:58:53 +03:00
Vladimir Dubrovin
e7bc76da73 Restore half-close support by default (accidentally switched off in previous fixes) 2026-08-08 21:34:15 +03:00
Vladimir Dubrovin
207ddb7f02 Fix: descriptors leak in proxy.c 2026-08-08 21:31:54 +03:00
8 changed files with 44 additions and 24 deletions

View File

@ -201,11 +201,14 @@ for most traffic. Rebuild with -DWITHSPLICE to make -s available, -s0 disables i
explicitly.
.br
.B -C
(for TCP services) keep the session until both sides close the connection
(TCP half-close). By default a connection closed by any of the sides terminates
the session, buffered data is delivered before the sockets are closed. Half-close
is required for the protocols where one of the sides closes its sending side and
expects the answer, it may cause the sockets to be kept in CLOSE_WAIT state.
(for TCP services) a connection closed by any of the sides terminates the
session, buffered data is delivered before the sockets are closed. By default
the session is kept until both sides close the connection (TCP half-close).
Half-close is required for the protocols where one of the sides closes its
sending side and expects the answer, but it keeps the socket of the side which
has already closed the connection in CLOSE_WAIT state. Use -C to close both
sockets as soon as any of the sides closes the connection, -C1 to request
the default behaviour explicitly.
.br
(for dnspr) simple, do not use resolver and 3proxy cache, always use external DNS server.
.br

View File

@ -298,7 +298,7 @@ void cyclestep(void){
default:
break;
}
dologname (tmpbuf, conf.logname, (conf.archiver)?conf.archiver[1]:NULL, conf.logtype, (conf.logtime - t * conf.rotate));
dologname (tmpbuf, conf.logname, (conf.archiver)?conf.archiver[1]:NULL, conf.logtype, (conf.logtime - (time_t)t * conf.rotate));
remove ((char *) tmpbuf);
if(conf.archiver) {
int i;

View File

@ -159,6 +159,10 @@ int checkACL(struct clientparam * param){
if(!res) break;
if(param->remsock != INVALID_SOCKET) param->srv->so._closesocket(param->sostate, param->remsock);
param->remsock = INVALID_SOCKET;
if(param->ctrlsocksrv != INVALID_SOCKET) {
param->srv->so._closesocket(param->sostate, param->ctrlsocksrv);
param->ctrlsocksrv = INVALID_SOCKET;
}
}
return res;
}

View File

@ -70,9 +70,9 @@ int inithashtable(struct hashtable *ht, unsigned tablesize, unsigned poolsize, u
_3proxy_mutex_init(&ht->hash_mutex);
_3proxy_mutex_lock(&ht->hash_mutex);
}
if(!(ht->ihashtable = malloc(tablesize * sizeof(uint32_t)))
|| !(ht->hashvalues = malloc(poolsize * (sizeof(struct hashentry) + ht->recsize - 4)))
|| !(ht->hashhashvalues = malloc(poolsize * ht->hash_size))
if(!(ht->ihashtable = malloc((size_t)tablesize * sizeof(uint32_t)))
|| !(ht->hashvalues = malloc((size_t)poolsize * (sizeof(struct hashentry) + ht->recsize - 4)))
|| !(ht->hashhashvalues = malloc((size_t)poolsize * ht->hash_size))
){
free(ht->ihashtable);
ht->ihashtable = NULL;
@ -126,13 +126,13 @@ static void hashgrow(struct hashtable *ht){
if(ht->ihashempty) return;
if(ht->poolsize >= ht->growlimit) return;
if(newsize > ht->growlimit) newsize = ht->growlimit;
newvalues = realloc(ht->hashvalues, newsize * (sizeof(struct hashentry) + ht->recsize - 4));
newvalues = realloc(ht->hashvalues, (size_t)newsize * (sizeof(struct hashentry) + ht->recsize - 4));
if(!newvalues) return;
ht->hashvalues = newvalues;
newvalues = realloc(ht->hashhashvalues, newsize * ht->hash_size);
newvalues = realloc(ht->hashhashvalues, (size_t)newsize * ht->hash_size);
if(!newvalues) return;
ht->hashhashvalues = newvalues;
memset(ht->hashvalues + (ht->poolsize * (sizeof(struct hashentry) + ht->recsize - 4)), 0, (newsize - ht->poolsize) * (sizeof(struct hashentry) + ht->recsize - 4));
memset(ht->hashvalues + ((size_t)ht->poolsize * (sizeof(struct hashentry) + ht->recsize - 4)), 0, (size_t)(newsize - ht->poolsize) * (sizeof(struct hashentry) + ht->recsize - 4));
for(i = ht->poolsize + 1; i < newsize; i++) {
hvalue(ht,i)->inext = i+1;
}

View File

@ -109,15 +109,17 @@ struct sockfuncs sso;
static void genpaths(struct fp_stream *fps){
size_t len = strlen(path) + 32;
if(fps->what & (FP_CLIDATA|FP_CLIHEADER)){
if(fps->fpd.path_cli) free(fps->fpd.path_cli);
fps->fpd.path_cli = malloc(strlen(path) + 10);
sprintf(fps->fpd.path_cli, path, counter++);
fps->fpd.path_cli = malloc(len);
if(fps->fpd.path_cli) sprintf(fps->fpd.path_cli, "%s%07d.tmp", path, counter++);
}
if(fps->what & (FP_SRVDATA|FP_SRVHEADER)){
if(fps->fpd.path_srv) free(fps->fpd.path_srv);
fps->fpd.path_srv = malloc(strlen(path) + 10);
sprintf(fps->fpd.path_srv, path, counter++);
fps->fpd.path_srv = malloc(len);
if(fps->fpd.path_srv) sprintf(fps->fpd.path_srv, "%s%07d.tmp", path, counter++);
}
}
@ -139,6 +141,7 @@ static
return fps->fpd.h_cli;
#else
if(fps->fpd.fd_cli != -1) close(fps->fpd.fd_cli);
if(!fps->fpd.path_cli) return (fps->fpd.fd_cli = -1);
fps->fpd.fd_cli = open(fps->fpd.path_cli, O_BINARY|O_RDWR|O_CREAT|O_TRUNC, 0600);
return fps->fpd.fd_cli;
#endif
@ -160,6 +163,7 @@ static
return fps->fpd.h_srv;
#else
if(fps->fpd.fd_srv != -1) close(fps->fpd.fd_srv);
if(!fps->fpd.path_srv) return (fps->fpd.fd_srv = -1);
fps->fpd.fd_srv = open(fps->fpd.path_srv, O_BINARY|O_RDWR|O_CREAT|O_TRUNC, 0600);
return fps->fpd.fd_srv;
#endif
@ -871,17 +875,17 @@ static int h_cachedir(int argc, unsigned char **argv){
size_t len;
dirp = (argc > 1)? (char *)argv[1] : getenv("TEMP");
len = strlen(dirp);
len = dirp? strlen(dirp) : 0;
if(!dirp || !len || len > 200 || strchr(dirp, '%')) {
fprintf(stderr, "FilePlugin: invalid directory path: %s\n", dirp);
return (1);
}
#ifdef _WIN32
if(dirp[len-1] == '\\') dirp[len-1] = 0;
sprintf(path, "%.256s\\%%07d.tmp", dirp);
sprintf(path, "%.256s\\", dirp);
#else
if(dirp[len-1] == '/') dirp[len-1] = 0;
sprintf(path, "%.256s/%%07d.tmp", dirp);
sprintf(path, "%.256s/", dirp);
#endif
return 0;
}

View File

@ -831,12 +831,20 @@ for(;;){
send_st(param, 9);
}
if((unsigned)socksend(param, param->clisock, buf, inbuf, conf.timeouts[STRING_S]) != inbuf){
param->srv->so._closesocket(param->sostate, ftps);
ftps = INVALID_SOCKET;
param->remsock = s;
RETURN(781);
}
inbuf = 0;
}
else {
if(!(newbuf = realloc(buf, bufsize + BUFSIZE))){RETURN (21);}
if(!(newbuf = realloc(buf, bufsize + BUFSIZE))){
param->srv->so._closesocket(param->sostate, ftps);
ftps = INVALID_SOCKET;
param->remsock = s;
RETURN (21);
}
buf = newbuf;
bufsize += BUFSIZE;
}

View File

@ -329,8 +329,8 @@ int MODULEMAINFUNC (int argc, char** argv){
#endif
#ifdef WITHSPLICE
" -s Use splice() - no filtering for data, off by default\n"
" -C keep the session until both sides close the connection (TCP half-close),\n"
" by default connection closed by any of the sides terminates the session\n"
" -C connection closed by any of the sides terminates the session, by default\n"
" the session is kept until both sides close it (TCP half-close)\n"
#endif
"-g(GRACE_TRAFF,GRACE_NUM,GRACE_DELAY) - delay GRACE_DELAY milliseconds before polling if average polling size below GRACE_TRAFF bytes and GRACE_NUM read operations in single directions are detected within 1 second to minimize polling\n"
" -fFORMAT logging format (see documentation)\n"
@ -599,7 +599,7 @@ int MODULEMAINFUNC (int argc, char** argv){
sscanf(argv[i]+2, "%d,%d,%d", &srv.gracetraf, &srv.gracenum, &srv.gracedelay);
break;
case 'C':
srv.halfclose = *(argv[i]+2)? atoi(argv[i]+2) : 1;
srv.halfclose = *(argv[i]+2)? atoi(argv[i]+2) : 0;
break;
case 's':
#ifdef WITHSPLICE
@ -1252,7 +1252,7 @@ void srvinit(struct srvparam * srv, struct clientparam *param){
#ifdef WITHSPLICE
srv->usesplice = 0;
#endif
srv->halfclose = 0;
srv->halfclose = 1;
memset(param, 0, sizeof(struct clientparam));
param->srv = srv;
param->version = srv->version;

View File

@ -352,6 +352,7 @@ int handleredirect(struct clientparam * param, struct ace * acentry){
}
if(param->operation == UDPASSOC){
SOCKET s;
if(cur->type != R_SOCKS5 && cur->type != R_SOCKS5P) return 70;
s = param->remsock;
param->remsock = INVALID_SOCKET;
param->ctrlsocksrv = s;