Skip to content

Fix connection leaks and UDP session races - #223

Merged
windtf merged 3 commits into
windtf:masterfrom
NikoCat233:fix/memory-leak
Sep 2, 2026
Merged

windtf merged 3 commits into
windtf:masterfrom
NikoCat233:fix/memory-leak

Conversation

@NikoCat233

Copy link
Copy Markdown
Contributor

Fix multiple memory leaks in the project

  • Close TCP, HTTP, ICMP, and WireGuard resources on failure paths.
  • Make UDP session cleanup idempotent and close remote connections immediately.
  • Synchronize UDP activity timestamps and PingRecord access.
  • Validate positive CheckAliveInterval and non-negative InactivityTimeout.
  • Add regression tests for configuration validation and UDP session cleanup.

@windtf
windtf merged commit 812c2fb into windtf:master Sep 2, 2026
10 checks passed
@NikoCat233
NikoCat233 deleted the fix/memory-leak branch September 3, 2026 06:39
tomaskir added a commit to tomaskir/vllm-wg-dockerized that referenced this pull request Sep 24, 2026
…leak fixes

No wireproxy release exists past v1.1.3 (2026-07-16), but master carries two
fixes on the TCPServerTunnel path we rely on:

- windtf/wireproxy#222: every closed tunnel connection logged
  "ERROR: Cannot forward traffic: ... use of closed network connection".
  It goes through wireproxy's own logger, so `-s` never silenced it.
- windtf/wireproxy#223: when the loopback target refused (e.g. vLLM still
  loading), the WG-side connection was never closed and the peer hung until
  its own timeout.

Reproduced both with two userspace peers over loopback running the
entrypoint's config shape under -s. v1.1.3 logged 30 "use of closed network
connection" lines for 10 aborted SSE streams, and requests to a port with no
listener timed out. The a4c5269 build logged 0 such lines and the refused
connections closed immediately (curl: empty reply). `wireproxy -n` and `-s`
behave the same, and upstream `go test` passes.

The fetch stage becomes a Go build stage. It stays pinned end to end: the
golang image by digest, the source by full commit SHA (checked after
checkout), and the modules by go.sum (`go mod verify`). CLAUDE.md now
describes this pinning and says to return to the release tarball + SHA256
once a release containing both fixes ships.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants