Files
openchamber/packages/web/server/lib/opencode/proxy-agent-wiring.test.js
T
Aaron Hogue 7611076436 fix(proxy): reuse upstream connections for OpenCode API requests (#2916)
* fix(proxy): reuse upstream connections for OpenCode API requests

`createProxyMiddleware` was constructed without an `agent`, so `http-proxy`
fell back to `agent: false`. That disables connection pooling and forces
`Connection: close` on every proxied request, consuming one ephemeral port
per request.

Measured against a real `opencode serve` instance, 200 sequential requests
through the proxy created 201 TIME_WAIT entries (1.005 ports/request). With
a keep-alive agent the same load creates 0.

On macOS the ephemeral range is 16,384 ports and TIME_WAIT lasts 30s, so
sustained traffic around 546 req/sec exhausts the pool — after which every
process on the host fails to open outbound connections with EADDRNOTAVAIL.

`maxSockets: Infinity` preserves the unbounded concurrency of `agent: false`,
so this changes connection reuse only, not request throughput.

Partially addresses #2915.

* fix(proxy): derive proxy agent class from the target scheme

Addresses review feedback on #2916. The first commit created an
unconditional `http.Agent`, which regresses external OpenCode servers
configured over https via `OPENCODE_HOST` (accepted by env-config.js).

http-proxy dispatches through `https.request` when the target protocol is
`https:` (http-proxy/lib/http-proxy/passes/web-incoming.js:126), and
`http.Agent#createConnection` is plain `net.createConnection` — so an
http.Agent would open a plaintext socket to a TLS port and fail every
proxied request. `agent: false` previously worked for both schemes.

`createOpenCodeProxyAgent(target)` now returns an `https.Agent` for https
targets and an `http.Agent` otherwise, derived once from
`resolveProxyTarget()` at registration so the single shared instance is
preserved across `apiProxy` and `interactiveOAuthProxy`.

Guarded in both test layers, verified to fail when the selection is
reverted to an unconditional http.Agent. `https.Agent` extends
`http.Agent`, so the http cases assert `not.toBeInstanceOf(https.Agent)`.

* Round 2: fix: resolve the proxy agent lazily so cold starts honor https

Addresses the round-2 blocker on #2916. Deriving the agent class at
registration is too early: startup-pipeline-runtime.js calls setupProxy()
(line 104) before bootstrapOpenCodeAtStartup() (line 141), so on a fresh
process state.openCodePort is null, buildOpenCodeUrl() throws
(network-runtime.js:86-88), and resolveProxyTarget() returns the http
loopback fallback. An external server configured via OPENCODE_HOST=https://
only appears on state.openCodeBaseUrl after bootstrap, so it was still
getting a plain http.Agent — the regression the previous commit intended
to fix.

`agent` is now a getter backed by a per-scheme memoizing resolver.
http-proxy-middleware rebuilds per-request options with
`Object.assign({}, this.proxyOptions)` in prepareProxyRequest, which invokes
getters, so resolution happens at request time while still yielding one
shared pool per scheme.

Tests now model the production ordering — registration while the port is
null and buildOpenCodeUrl throws, then an https base URL appearing after
bootstrap — and fail against the eager implementation. A behavioral test
pins the http-proxy-middleware option re-read the fix depends on, so a
library change that froze options would fail loudly instead of silently
regressing https targets.

The resolver is module-private; `bun run dead-code` flagged it as an
unused export when it was exported.

* Round 3: docs(changelog): note upstream connection reuse under [Unreleased]

Repo precedent adds [Unreleased] bullets for comparable proxy/stability
fixes (1.18.4 Stability, 1.9.3 Reliability/Proxy). Non-blocker raised in
review on #2916.

* Round 3: docs(changelog): use repo-standard 'behavior' spelling

* Round 4: docs(changelog): don't imply a restart is the only recovery

The ephemeral port pool drains on its own once the exhausting traffic
stops (TIME_WAIT expiry), so a restart is sufficient but not necessary.
Optional nit raised in review on #2916.

* Round 5: fix: construct the proxy agent through one factory; widen the pool

Review found the https branch was mutation-uncovered: the resolver
re-implemented agent construction inline instead of calling the exported
`createOpenCodeProxyAgent(target)`, so replacing its https branch with
`new https.Agent()` — dropping OPENCODE_AGENT_OPTIONS, and with it
keep-alive — left the entire suite green. Since `createOpenCodeProxyAgent`
also had no production callers, its four tests were pinning dead code.
Delegating collapses both: the factory is now the single construction
path, and the mutation fails 2 tests including the live resolver path.

Also from review:

- maxFreeSockets 32 -> 256 (Node's own default). The lower cap evicted
  pooled sockets under concurrency, reintroducing the churn this agent
  exists to prevent: at 64 concurrent requests it left 303 sockets in
  TIME_WAIT versus 0 at 256.
- Added `timeout` to OPENCODE_AGENT_OPTIONS. Free-socket eviction is
  governed by agent.options.timeout, which was unset, so idle sockets
  persisted until the peer closed them. `keepAliveMsecs` is the TCP probe
  delay, not the idle lifetime.
- resolveProxyTarget() now checks openCodePort before calling
  buildOpenCodeUrl instead of relying on it throwing. The port is nulled
  on several runtime paths (health-check failure, failed restart), so a
  degraded OpenCode made every proxied request pay for a thrown-and-caught
  exception — and the getter added a second call per request.
- Test fixtures use :4096 rather than :443; WHATWG URL elides the default
  port, so parseInt('') is NaN and env-config rejects that host. The
  fixtures modeled a state that cannot reach production.
- The getter-read assertion is now exact (0 at construction, 1, then 2)
  rather than >= 2, which would have passed if the getter were read twice
  at construction and never per-request.
- listen() rejects on 'error' and servers start inside try/finally, so a
  bind failure fails the test instead of hanging to timeout.
2026-08-17 23:44:38 +03:00

153 lines
5.1 KiB
JavaScript

import http from 'node:http';
import https from 'node:https';
import { beforeEach, describe, expect, it, vi } from 'vitest';
const { createProxyMiddlewareMock } = vi.hoisted(() => ({
createProxyMiddlewareMock: vi.fn(),
}));
vi.mock('http-proxy-middleware', () => ({
createProxyMiddleware: createProxyMiddlewareMock,
}));
const { registerOpenCodeProxy } = await import('./proxy.js');
const createStubApp = () => {
const settings = new Map();
const noop = () => {};
return {
get: (...args) => (args.length === 1 ? settings.get(args[0]) : undefined),
set: (key, value) => {
settings.set(key, value);
},
use: noop,
post: noop,
put: noop,
patch: noop,
delete: noop,
all: noop,
};
};
/**
* `state` is intentionally mutable so a test can model the production ordering:
* the proxy is registered before OpenCode bootstraps, so the port/base URL only
* become resolvable afterwards.
*/
const createStubDeps = (state) => ({
fs: { promises: { realpath: async (value) => value } },
os: {},
path: {},
OPEN_CODE_READY_GRACE_MS: 0,
LONG_REQUEST_TIMEOUT_MS: 1_000,
getRuntime: () => ({ openCodePort: state.port, openCodeBaseUrl: state.baseUrl }),
getOpenCodeAuthHeaders: () => ({}),
// Mirrors network-runtime.js: throws until the port is known.
buildOpenCodeUrl: (pathname) => {
if (!state.port) {
throw new Error('OpenCode port is not available');
}
return `${state.baseUrl}${pathname}`;
},
ensureOpenCodeApiPrefix: (pathname) => pathname,
});
const managedState = () => ({ port: 49303, baseUrl: 'http://127.0.0.1:49303' });
const coldState = () => ({ port: null, baseUrl: null });
const agentsFromCalls = () => createProxyMiddlewareMock.mock.calls.map(([options]) => options.agent);
describe('OpenCode API proxy agent wiring', () => {
beforeEach(() => {
createProxyMiddlewareMock.mockReset();
createProxyMiddlewareMock.mockImplementation(() => (_req, _res, next) => next?.());
});
it('constructs every proxy with a keep-alive agent', () => {
registerOpenCodeProxy(createStubApp(), createStubDeps(managedState()));
expect(createProxyMiddlewareMock).toHaveBeenCalled();
for (const agent of agentsFromCalls()) {
// Without an explicit agent, http-proxy falls back to `agent: false`,
// which forces `Connection: close` and burns one ephemeral port per
// request. See createOpenCodeProxyAgent in ./proxy.js.
expect(agent).toBeTruthy();
expect(agent.options?.keepAlive).toBe(true);
}
});
it('shares one agent instance across the API and OAuth proxies', () => {
registerOpenCodeProxy(createStubApp(), createStubDeps(managedState()));
const agents = agentsFromCalls();
expect(agents.length).toBeGreaterThan(1);
expect(agents.every(Boolean)).toBe(true);
expect(new Set(agents).size).toBe(1);
});
it('memoizes the agent per scheme rather than allocating one per resolution', () => {
registerOpenCodeProxy(createStubApp(), createStubDeps(managedState()));
const [options] = createProxyMiddlewareMock.mock.calls[0];
expect(options.agent).toBe(options.agent);
});
// Production ordering: startup-pipeline-runtime.js calls setupProxy() before
// bootstrapOpenCodeAtStartup(), so at registration the port is null,
// buildOpenCodeUrl throws, and resolveProxyTarget() falls back to the http
// loopback default. An external https server configured via OPENCODE_HOST is
// only visible after bootstrap, so the agent must be resolved lazily.
it('resolves an https agent after bootstrap even though registration ran cold', () => {
const state = coldState();
registerOpenCodeProxy(createStubApp(), createStubDeps(state));
// Cold: nothing resolvable yet, so the http fallback target applies.
for (const agent of agentsFromCalls()) {
expect(agent).not.toBeInstanceOf(https.Agent);
}
// Bootstrap completes against an external https server.
state.baseUrl = 'https://opencode.example.com:4096';
for (const agent of agentsFromCalls()) {
expect(agent).toBeInstanceOf(https.Agent);
// Asserted on the live resolver path, not just the exported factory:
// the https branch is the one a mutation could silently strip.
expect(agent.options?.keepAlive).toBe(true);
expect(agent.options?.maxFreeSockets).toBe(256);
}
});
it('keeps a plain http agent when bootstrap resolves an http target', () => {
const state = coldState();
registerOpenCodeProxy(createStubApp(), createStubDeps(state));
Object.assign(state, managedState());
for (const agent of agentsFromCalls()) {
// https.Agent extends http.Agent, so the negative assertion is load-bearing.
expect(agent).toBeInstanceOf(http.Agent);
expect(agent).not.toBeInstanceOf(https.Agent);
}
});
it('derives an https agent when the target is already https at registration', () => {
registerOpenCodeProxy(
createStubApp(),
createStubDeps({ port: 4096, baseUrl: 'https://opencode.example.com:4096' }),
);
const agents = agentsFromCalls();
expect(agents.length).toBeGreaterThan(0);
for (const agent of agents) {
expect(agent).toBeInstanceOf(https.Agent);
}
});
});