fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(server): survive client resets on WebSocket upgrade sockets - #4570

Closed
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset
Closed

fix(server): survive client resets on WebSocket upgrade sockets#4570
Sipixer wants to merge 1 commit into
pingdotgg:mainfrom
Sipixer:fix/upgrade-socket-econnreset

Conversation

@Sipixer

@SipixerSipixer commented Jul 26, 2026

Copy link
Copy Markdown

What Changed

Attach a no-op 'error' listener to every WebSocket upgrade socket, so a client reset degrades to an ordinary disconnect instead of killing the server process.

Only the Node factory in server.ts is touched. The Bun path goes through Bun.serve and never hands out raw upgrade sockets, so it needs no guard.

Why

A client that sends an upgrade request to /ws and then resets the connection takes the whole server down. Node throws an uncaught exception when a socket emits 'error' with no listener, and @effect/platform-node@4.0.0-beta.78 wires a 'close' listener on the raw upgrade socket in makeUpgradeHandler but never an 'error' one:

socket.on("close",()=>{if(!socket.writableEnded){fiber.interruptUnsafe(parent.id,ClientAbort.annotation)}})

Authentication is not a barrier. The 'upgrade' event fires before the route runs, so a client whose credentials are rejected has already passed through the unguarded socket — a rejected connection that resets kills the server exactly like an accepted one.

node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
errno: -104, code: 'ECONNRESET', syscall: 'read'
systemd: t3code.service: Main process exited, code=exited, status=1/FAILURE

Every in-flight session dies with the process, not just the one whose socket reset.

Trigger conditions. Two have to hold together. Probed against an unpatched 0.0.29-nightly.20260725.899:

client behaviour after upgradeoutcome
reads the response, closes with FINsurvives
reads the response, resetssurvives
leaves the response unread, closes with FINsurvives
leaves the response unread, resetsdies

Unread bytes in the receive buffer make the kernel emit RST instead of FIN, and that RST lands on the unlistened socket. The same probe against a bare connection, partial headers, a completed GET /, a POST /mcp and an SSE GET /mcp leaves the server up — only the upgrade path is affected.

Impact. Unlikely from ordinary traffic: browsers read their response and close cleanly, and a three-week journal on my deployment shows zero occurrences from normal client churn. The crashes I observed were self-inflicted by a scripted client that ignored the response. But it takes about ten lines and no credentials to trigger deliberately and repeatedly, so on any deployment listening beyond loopback it is an availability problem rather than a rare glitch.

Upstream. The gap is in @effect/platform-node and arguably belongs there too. A guard here is still worth having: three lines, holds regardless of what upstream does, and keeps server liveness independent of a transitive dependency's socket handling.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes — n/a, no UI change
  • I included a video for animation/interaction changes — n/a

Tests

apps/server/src/upgradeSocketGuard.test.ts covers that the listener is attached to every upgrade socket, and that ten consecutive resets leave the server answering requests with no uncaughtException.

  • new tests pass; full apps/server suite green (1622 passed, 7 skipped)
  • vp check reports 0 errors (remaining 11 warnings are pre-existing in apps/web)
  • vpr typecheck failures are limited to scripts/lib/resolve-catalog.ts and reproduce on a clean checkout
  • built with vp pack and re-ran the probe against dist/bin.mjs: 20 consecutive resets on the previously fatal case, server alive, nothing fatal logged

Negative control: with the guard removed, the same sequence produces UNCAUGHT: ECONNRESET and exit code 42.

Any client that opens a WebSocket upgrade request to /ws and then resets
the connection takes the whole server process down. Node throws an
uncaught exception when a socket emits 'error' with no listener, and
@effect/platform-node's upgrade handler wires a 'close' listener on the
raw upgrade socket but never an 'error' one.
Authentication does not protect against this. The upgrade event fires
before the route runs, so a client whose credentials are rejected still
reaches the unguarded socket: a rejected connection that resets kills
the server just as effectively as an accepted one. Every in-flight
session dies with the process, and on a deployment exposed beyond
loopback this is remotely reachable without credentials.
node:events:497
throw er; // Unhandled 'error' event
Error: read ECONNRESET
at TCP.onStreamRead (node:internal/stream_base_commons:216:20)
Attach a no-op 'error' listener to every upgrade socket so a reset
degrades to an ordinary disconnect. Only the Node factory needs this;
the Bun path does not expose raw upgrade sockets.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 136a433d-1aec-433c-9901-b3aede7542f5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Jul 26, 2026
@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved

This is a straightforward defensive bug fix that prevents server crashes when clients reset WebSocket connections during handshake. The change follows an existing pattern in the codebase, is minimal in scope, and includes comprehensive tests.

You can customize Macroscope's approvability policy. Learn more.

@t3dotgg

Copy link
Copy Markdown
Member

Note

🤖 GPT-5.6 Sol responding on behalf of Theo

We're closing this PR as we clean up the T3 Code backlog. Thank you for taking the time to put this together.

Closing as already fixed by the shared HTTP error guard. Current main attaches an error listener to each raw upgrade socket and wires that guard into the Node server factory. It also covers response-write errors. The separate upgrade-only wrapper is no longer needed. Related work: #4470.

If you believe we closed this in error, please reopen the PR and leave a comment explaining what we missed. If GitHub does not let you reopen it, leave a comment here and we'll take another look.

@t3dotggt3dotgg closed this Aug 27, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Sipixer@t3dotgg